URLhaus Database

You are currently viewing the URLhaus database entry for http://contatopericia.com.br/chat/statement/9uvxrzxgo2x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445169
URL: http://contatopericia.com.br/chat/statement/9uvxrzxgo2x/
URL Status:Offline
Host: contatopericia.com.br
Date added:2020-08-27 11:42:08 UTC
Last online:2020-08-27 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-27 11:44:02 UTC to abuse{at}hospedagem[dot]net)
Takedown time:1 hour, 37 minutes Good (down since 2020-08-27 13:21:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27FILE_368045410.docdoc 952538ff917ab5d3ee99b631731526300164f3b607818d2cd99d019ca5add14dn/aHeodo
2020-08-27WBXY_PO_08272020EX.docdoc bf913198774af473c451fa304746ed1434412a8f1c7706b2e5f12c6cf1827249Virustotal results 28.81%Heodo
2020-08-27REP_23634697.docdoc 23745a515c547cd80f85106940b7feb4f83e248a7cf96b2a45c2ad63214e161fn/aHeodo
2020-08-278Z55JZB3JZV0.docdoc 991d1c5d354ae5640d55186accbd371791d03c05853b380edcd80ba40e515861n/aHeodo
2020-08-27INV_GWP_080120_EQG_082720.docdoc 38923432e3f3c288a95ad269e276d83fc311457e325def95858c499997a5e00en/aHeodo
2020-08-27BAL_96595213.docdoc 14c1d57c66c10bba2bc25fade1eda3827106db6c716dfe521ab21d2fa39e5de3Virustotal results 28.81%Heodo