URLhaus Database

You are currently viewing the URLhaus database entry for https://www.revvcorpus.com.br/wp-includes/http://Documentation/3xqf9LFZtaixb4L98/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452685
URL: https://www.revvcorpus.com.br/wp-includes/http://Documentation/3xqf9LFZtaixb4L98/
URL Status:Offline
Host: www.revvcorpus.com.br
Date added:2020-09-03 18:44:11 UTC
Last online:2020-09-04 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 18:46:04 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:9 hours, 11 minutes Good (down since 2020-09-04 03:57:30 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04Dat 103124.docdoc 8d774a00099efb6bf180d96ed66c4cc234169be46bd45261c06dd8500e0a8481Virustotal results 40.00%Heodo
2020-09-04list-40810.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-04rep_1121.docdoc cbf75dba4c6b4f8cbcfb647112f9a0a4f8efb293526aea73ffebcd800379e08fVirustotal results 40.00%Heodo
2020-09-04Untitled 7652.docdoc 3b921395ead4db8129425113780d7d7391058b9a70f1bfadaa36d56c48de30edn/aHeodo
2020-09-04Inf_2020_09_04.docdoc 595e8a24f2e5e51e56138296f7c6cd58e709e8f532dbacc38ae66f462e0e071dVirustotal results 40.00%Heodo
2020-09-04file-20200904.docdoc 9cf29b7fcce905e807fd1e4493af36f7f0e8618912601f1a85cf52af6d38d6b8Virustotal results 40.00%Heodo
2020-09-04dat-2020_09_04-LXV669920.docdoc eaab7e71c3da44a79d28d2bef0582eeadb430df7d20febba2eed46323d6dd3eeVirustotal results 40.00%Heodo
2020-09-04arc 2020_09_04 K175.docdoc 6300e903bf3720bb91e4db31ad186d98f0b8307f0abd3b785145f72f0a89edefVirustotal results 40.00%Heodo
2020-09-044789524_6485.docdoc daa812c082d4d470cfad19c540bfc6ea7adbcd3859273af885dda81d2722e1e1Virustotal results 40.00%Heodo
2020-09-04652766_E311.docdoc 69e91274a22bb98b54013be9509ad757c17fd9ab44d80c5a8585ec639ea6f04bVirustotal results 40.68%Heodo
2020-09-04Arc-633.docdoc 945f9c6c84eff86e098fcb02268e716fb80f5c6fa8a5e64e08175a306d3c0a2bVirustotal results 41.38%Heodo
2020-09-04LIST-41804.docdoc 39f12f314a1431044af9b7061ac6b7b2d68e29927ba8650ecfd4a5a41337922cVirustotal results 36.67%Heodo
2020-09-03Rep-2020_09_04-50171.docdoc 62f2e2f1e282bf930eaf8a31d9904112fa33e4c5bcb2d14f0efc91df5351ae54Virustotal results 35.00%Heodo
2020-09-03arc_IXG407.docdoc d313ce8483aa86f33b4fb8f8eaf32cc9162fea1ecd980baf5fb9ae5ba1e2024cVirustotal results 33.33%Heodo
2020-09-03Rep-2020_09_04-131.docdoc 5870705910f4290f13346efd3c9113483974723cc840cd330844efa6f5b3be19Virustotal results 34.48%Heodo
2020-09-03file-8512.docdoc 9e3d362ff8dc1daec89813f11f73bac91ac2ee3f97f803fd413522874432ebb4Virustotal results 32.79%Heodo
2020-09-03DAT 2020_09_04.docdoc 198716bbb4d8d22a81603b2d905312ceae4b0f8df0a17ccda349c44ae024011bVirustotal results 33.33%Heodo
2020-09-03arc-2020_09_04.docdoc 93b78de73040a3429d67f551e6a789cd2a141185e4bdba2cb74d575346b169f8Virustotal results 32.20%Heodo
2020-09-03mes 20200904 LH60832.docdoc 2f9910b3fffce2373726bb19cee907def1ad66df1c9210d955647c7a638ef9edVirustotal results 30.00%Heodo
2020-09-03Inf-2020_09_04-0051619.docdoc c9915f741ce8d4cf9ca8c30d7711a0152562b3b68514486b5b49442ea9fc3b06Virustotal results 31.58%Heodo
2020-09-03Doc-KO754892.docdoc 184ba331ed727480fd65743bfe0cf1489eca3b4d49b68a31b970ee96288c9484Virustotal results 30.00%Heodo
2020-09-0313158J_2020_09_04_187.docdoc d0b12e270e83660cf1af25738d605f6c9a9edbd56f777bf405d01602fd42a201Virustotal results 30.51%Heodo
2020-09-03File-2020_09_04-PYL44635.docdoc 3c9f9e08bf1785b8c6c1fed306eb5e322fb63ea73a8d01a9fc83af4006d64008Virustotal results 31.03%Heodo
2020-09-03LIST-2020_09_04.docdoc eff6ba195fc7d083d41cc3c5d0bf90588ba4de22599bc9adeb053e04f0f4d55cVirustotal results 30.51%Heodo
2020-09-03INF-20200904.docdoc 57db4c9dcd57a6d59d1b728b6ada57bf429b28d3b3a3adf0416ed0dc9cf7dd5en/aHeodo
2020-09-0373290 2020_09_04.docdoc 8cf9bff9f058b2a79f8e84597c708b0d15b2235c89fd2b63d50c0e25db6090adVirustotal results 28.81%Heodo
2020-09-03doc 20200903 S791.docdoc a0c7d7125079c31ddaf2b7b1955bf7992183d25c6c03b5d81ce1a17ff8ad612dn/aHeodo
2020-09-0374811R_2020_09_03_Y67370.docdoc e5115c3e86dd21ece011508d8b1b576b6b5b38eefde8dea14cdaac4a6a06f4e0Virustotal results 28.81%Heodo
2020-09-03Arc_20200903_ZI692044.docdoc 349cb26e54b95d8b8902d5adcb96d1901780dc4b79c294e28b4c6cba21776a8cVirustotal results 27.59%Heodo
2020-09-03Inf-2020_09_03.docdoc 3898915681d8baa76a674cb8386bd9a88f2b8b3883e5db87f3c43e6eda4c08d6Virustotal results 28.81% Heodo
2020-09-03MES IP584.docdoc 83a608a684d531170d1d962a923ec80ff882ad17ac5a24ce4477d634e575c74eVirustotal results 27.12%Heodo
2020-09-03Doc-20200903-5189.docdoc 509ecb6a2610738956ebdf8a885bdb413fe84bd8143e1012a1fb4a4e14333d19Virustotal results 22.03%Heodo
2020-09-03arc_2020_09_03_4933301.docdoc 87c33ae0a712785fde7c483d86dbb964ab1db6cb7a0050ea07e5da240dba44b7Virustotal results 23.73%Heodo
2020-09-03LIST 20200903 OTX387081.docdoc bc4ee7e49e05ab462e199c1a2635de8de23b9ca32d8c7634cc4902f425967e22Virustotal results 23.33%Heodo
2020-09-03Mes.docdoc af81984de14d081c2a5d015a4266dd625fd7eb4153810cb71c2ba3e9dbf382ddVirustotal results 23.73%Heodo
2020-09-03File-20200903-EPF082.docdoc 87dc054eccdd1cd6182d372f5fad56aae34971c4a0ab10e92fd242ee82e9c785n/aHeodo
2020-09-03LIST_2020_09_03_27515.docdoc b577e4ea45a40a29dcfff06e9bf6917dc3d3475dad04807b10bfb0c565d014bdVirustotal results 23.73%Heodo