URLhaus Database

You are currently viewing the URLhaus database entry for http://metalurgicanunes.com.br/wp-admin/http://lm/fFGbFQE531X/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452561
URL: http://metalurgicanunes.com.br/wp-admin/http://lm/fFGbFQE531X/
URL Status:Offline
Host: metalurgicanunes.com.br
Date added:2020-09-03 16:09:05 UTC
Last online:2020-09-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 16:10:03 UTC to abuse{at}hospedagem[dot]net)
Takedown time:2 hours, 59 minutes Good (down since 2020-09-03 19:09:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03File_2020_09_03_SVJ441.docdoc 039593442d9e6207131ebcf1a580c3e5bec865876db4457c1f8caa6947159cbdVirustotal results 25.00%Heodo
2020-09-03Mes NIR49788.docdoc 98494fc713c44d8a04dfd9843ece379a625dc73ea24fa88cf65b60733b206390Virustotal results 25.00%Heodo
2020-09-03505-20200903.docdoc dbc13cd5e6ecadf32014b392f23502deefc834c7eb890da0946c1a50d059aebbVirustotal results 25.00%Heodo
2020-09-03INF-762296.docdoc aaded0705ecee562ec8d51ac4daf7fb1b011e3794d75c0dc394e25d67baeead9Virustotal results 24.59%Heodo
2020-09-03doc-20200903-6975.docdoc 5fd0bf16f99dcc3a2daa90cb5c60a390dc2f606e53f7456676d02fdce15bd282n/aHeodo
2020-09-03Mes 2020_09_03 6089.docdoc 71ffbf141f5aebe290a6af65bb7c1f043e16b70bca63e9d098d5102caed37d96n/aHeodo
2020-09-03Attachments-20200903.docdoc 431ec558729a17c71ef7827a20d49d5577d19b03f8ccaa3e0615a8db09ed3c54n/aHeodo