URLhaus Database

You are currently viewing the URLhaus database entry for http://www.weblabor.com.br/avisos/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:491337
URL: http://www.weblabor.com.br/avisos/invoice/
URL Status:Offline
Host: www.weblabor.com.br
Date added:2020-09-14 07:15:07 UTC
Last online:2020-09-14 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 07:16:22 UTC to abuse{at}hospedagem[dot]net)
Takedown time:10 hours, 56 minutes Good (down since 2020-09-14 18:12:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14INV_UZ3F28S9X1UWTZ.docdoc 18a08bfde32fec48dd39f4ba41cd7449d4169cd9252a6dcc077cd7fdca819191n/aHeodo
2020-09-14FILE_969275658.docdoc 28af08585e9a6ba58d36d8e18f06e00def8d27ad158b4ceef0a99e6ad2200e9an/aHeodo
2020-09-14REP_HOK_090120_ZLL_091420.docdoc 3e64b6ff86edb967541e4c0b1dc3667ccbd807e99af91d16f9682597b1352ee1Virustotal results 28.81%Heodo
2020-09-14AIMK_HKN_090120_HJY_091420.docdoc 875aadb39437a5366487bf9232ad64eb3d635fae59449e241d84be3133ed2a44Virustotal results 27.12%Heodo
2020-09-14FILE_07619276609.docdoc 5d29d4ae2581a27221609c7e3877aa9139dd44042bcde1fb62d7e901d285e4f4Virustotal results 27.59%Heodo
2020-09-14SGO_090120_TFZ_091420.docdoc 0844edff9f032df69f33be680af0947ca6c06895530397bf028ae47482b5b711Virustotal results 28.07%Heodo
2020-09-14NA7709568160PH.docdoc 65af960efb522275c12cbbc2902476854043df45ed96b435103aedcef02eecben/aHeodo
2020-09-14FILE_KG2JJM5WTN7QXGJ9.docdoc 979b409188d97c556d5d9bea690f767ad8b8c4a6158913070cbf7005058b209eVirustotal results 25.00%Heodo
2020-09-14FS7813232581AD.docdoc 2ff4b7d7b02e82dce1df902e65b025fe06a6a66e3e4605ada4206d0eb2e33cd5Virustotal results 21.43%Heodo
2020-09-14INV_163399827803048.docdoc bf5e604c3ef6c684bb10f3877f5aaad357943c8b08c0ef560972419d1d80f43aVirustotal results 23.73%Heodo
2020-09-14A_PO_09142020EX.docdoc e080d3e47109955d920cea3412153304a44c6675154bdb704180405f9f36b099Virustotal results 21.67%Heodo
2020-09-144WYS5R2RHR.docdoc 12820384810ee90b5f51be5c13e6c2a8ca47e4266660b1e3100722e4c2baa33bn/aHeodo
2020-09-14BAL_RE9AQIOH3I6IM.docdoc bc08b7a8310a6206226dd767a9c4cc26dd5d5316ad80e399359db8c090294b43Virustotal results 21.67%Heodo
2020-09-14DOC_CEXHILK5Y.docdoc 29727ccfff36705a0638c4b0127fc5ec22be60f05d542fd9e9f0f49f6827ef54n/aHeodo
2020-09-14YO9092792299VO.docdoc 358777fc6c34cc75ebc7d92ee6c2bd0b29eaf38c4a215fc317e920ab0f60476fVirustotal results 20.34%Heodo
2020-09-14BAL_54913225.docdoc 089bf49461e57f29762b5c1f0b89fd5db567a615c5fde7cc529369f7472f8f3dVirustotal results 20.34%Heodo
2020-09-14X_04823230.docdoc a3ec8d007a38ecb5e5367c769af1c4ba2131bd44505bb8eb76c695c4e7a8da9aVirustotal results 23.33%Heodo
2020-09-14REP_84045131.docdoc fbb786eb4a0f0a9ecf9da92977d330921554d0c4cbdc1218de3641c9a9a16933Virustotal results 23.33%Heodo
2020-09-14M_67697506.docdoc 3ca9d3e5ceccd9464ea63ceb8d70613a4110caa1a40eaafea1215d0ef0bcef23Virustotal results 26.67%Heodo
2020-09-14N_PO_09142020EX.docdoc 11cc4036d50f7e705e15ad8d6b14813b0f328d9e14d31aa6ca51ba7e13fd4f4en/aHeodo
2020-09-14FILE_QX9970388594EC.docdoc fdd3d83dc6ff712204b45d9dd5b04ccecce3d2dad4f20e24867c2737c3379081Virustotal results 24.56%Heodo
2020-09-14FILE_BUN_090120_CZM_091420.docdoc 33fdd2105c6792ea0096f87c5be02c0a4077e059d550eae962c72be773a41bacVirustotal results 26.67%Heodo
2020-09-14DOC_8718567901152568246.docdoc 80d8e37e856ada6bc31bdd15d3ef46e47cf2163c6394c78aba7ee026b55a6b2bVirustotal results 22.95%Heodo
2020-09-14GZ5354891160WA.docdoc 813835e555a57244f759ea1f03dd32d05bc472af33d6ed3c4ff22fc850798fe3Virustotal results 24.14%Heodo
2020-09-14PO_09142020EX.docdoc 3b211810dcd8176df286ff6d29407b15b8977014c8a22899ef51874995c40462Virustotal results 23.73%Heodo
2020-09-14ZQ_09579427.docdoc 4248b1beb0bf8d0caa595316529c99e3a8511af5fc8c72cda777b837ff22c8d6Virustotal results 22.95%Heodo
2020-09-1480431773.docdoc d27caae7e1449d09d45bda155faf668fe51d33a672d9522522d7571bb1aa5a79Virustotal results 24.14%Heodo
2020-09-14PY1O7PFG.docdoc d22e0f5cf4f0cd9ab2121bc4d93499f817db516480f38b3d0c231c96b6325fd4Virustotal results 20.34%Heodo
2020-09-14928262550148.docdoc b0af8380bca65d597d5cb221e43bd296bb0f9342bafee29772376105b3064351Virustotal results 20.00%Heodo
2020-09-14BYL_090120_BLG_091420.docdoc b2da3622cd82e573c60eb2623e5d96e08956c72cb2fd0c53a126e732b376a0efVirustotal results 20.00%Heodo
2020-09-14FILE_LC2763247126KJ.docdoc 785e1a7b7818be6954ac21f9d27f2d52615235cd8915f6580b94a3ccf806c8eeVirustotal results 20.34%Heodo
2020-09-1415971785.docdoc 5ec4236800995ebed8b3a1be01838d6e9a792f5bee625aee1b679c05ffe4f9eeVirustotal results 18.97%Heodo
2020-09-147380005275523173586698413.docdoc ed0a08046d0358b52edb5bf206897e9f4be9a821af516a5ddc61e30588664f96Virustotal results 20.34%Heodo
2020-09-14DOC_PO_09142020EX.docdoc 99b56f40d2606b054f2ebb2682d4578b3e8813434d42cacd763e8e278712ff0fVirustotal results 20.00% Heodo
2020-09-14FILE_BLN_090120_XCB_091420.docdoc bc782e8bec155c8892dca0c1c1221c6fe388d611316216fa696165bc7f5688e2Virustotal results 20.00% Heodo
2020-09-14INV_PO_09142020EX.docdoc 885c79dc1bf24562158996f9d66c6a3428b6f7fa98e3a1d212638c8e19557cf4Virustotal results 20.00% Heodo
2020-09-14165985000.docdoc feadc42767dc8e01f65c1772b5502bd3239144870cdb552553621049edcbf5c7Virustotal results 20.69% Heodo