URLhaus Database

You are currently viewing the URLhaus database entry for http://www.closmaq.com.br/wp-admin/INC/gzj7zw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452692
URL: http://www.closmaq.com.br/wp-admin/INC/gzj7zw/
URL Status:Offline
Host: www.closmaq.com.br
Date added:2020-09-03 19:02:05 UTC
Last online:2020-09-03 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 19:04:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 58 minutes Good (down since 2020-09-03 21:02:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03SR_25234050578612875503233.docdoc e56820ed5e83d51aa84705e88d0ece136340abd67783ea2c9b47b055cd7d87e8Virustotal results 31.67%Heodo
2020-09-03EMY_090120_DGI_090320.docdoc ed9238b54842d3b371847f10b062cd40c9ae9cd4f92a3d0de6cf997cc31999e9n/a Heodo
2020-09-03H_UY9743901477UL.docdoc 14f41bc73e28d88290af87558aa3a0f6ce0b3eb17dd48f401aca614cf7da06dfVirustotal results 31.67% Heodo
2020-09-03Y_PO_09032020EX.docdoc f50133085cf408fa42e3568d8466e35d6ae2ceffb26ec78fc25041eb5e5d7c93Virustotal results 27.12%Heodo
2020-09-03REP_21084581.docdoc d7dccaf606ccac241264d06440a58415ea545b955e3e2538954c3ab166c541c3Virustotal results 26.23%Heodo
2020-09-03REP_PO_09032020EX.docdoc 0286addf31e211364a924ab469282f0f4f544eddc3bd553d31a8b98a3b11704dVirustotal results 26.67%Heodo