URLhaus Database

You are currently viewing the URLhaus database entry for http://engeclimabrasil.com.br/erros/Reporting/nu1mfupl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452335
URL: http://engeclimabrasil.com.br/erros/Reporting/nu1mfupl/
URL Status:Offline
Host: engeclimabrasil.com.br
Date added:2020-09-03 11:35:06 UTC
Last online:2020-09-03 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 11:36:04 UTC to abuse{at}hospedagem[dot]net)
Takedown time:2 hours, 14 minutes Good (down since 2020-09-03 13:50:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03PO_09032020EX.docdoc feb68022d4541ffd2ac8ac987ced84820eff930b11904e21bd930ad75115981cVirustotal results 38.33%Heodo
2020-09-0332468246.docdoc d88bb1c72d637f689aabcfb3f96db6b0c7d80d51d84089583eb01c16aff56e8en/aHeodo
2020-09-03E3OM2WL9BVCWQGN.docdoc 6c9fc30d18facaf2b4c12ece2295a651e742612c768cb2ea841fdd78dbf64eb7Virustotal results 42.37%Heodo
2020-09-03PO_09032020EX.docdoc 3f96777138c8e15f787574fe25b5d504343325ac2bce0a4a8fe612142eef9bb6Virustotal results 36.67%Heodo
2020-09-03A_05825947.docdoc 5b608686af208a20dd45c69ca03d172add7e054c5b6ca17d04d617103e1c4713Virustotal results 38.33%Heodo
2020-09-03M_FYK_090120_VCN_090320.docdoc 887550b3f998c098e70f648e0b6c0357286d513fe42e649612ee103633379f9cn/aHeodo