URLhaus Database

You are currently viewing the URLhaus database entry for http://saudadedos18.com.br/wp-content/Reporting/8dlzvzzclt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:492437
URL: http://saudadedos18.com.br/wp-content/Reporting/8dlzvzzclt/
URL Status:Offline
Host: saudadedos18.com.br
Date added:2020-09-14 08:51:30 UTC
Last online:2020-09-15 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 08:52:45 UTC to abuse{at}amazonaws[dot]com)
Takedown time:16 hours, 30 minutes Good (down since 2020-09-15 01:23:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15INV_16752865.docdoc 23adb5a46e285b5dbfc94b24cfba24c796c5ac4ed407661ab8bdc83a007de7a1Virustotal results 39.66%Heodo
2020-09-15143924967543198769341.docdoc e534714104dce95e26cb8d7d6f9025c18e27c6106ed4727b430d97f861f6294cVirustotal results 31.03%Heodo
2020-09-15DOC_PO_09152020EX.docdoc c666da0a8b5362097e6f268f64fc6726437abf1124b825916b75989743f85887Virustotal results 40.68%Heodo
2020-09-15REP_YX9C199M.docdoc d1561f797d8c7b185a29acca5b8b8db71f711dd129448acf96d3ac1d0c23d0a0n/aHeodo
2020-09-14DOC_TKXR1LXDBUXC1N.docdoc b1519746d2c2a349f5fd48d89760bc67161a6474005f9060909bcf2e2c3fa1c2Virustotal results 42.11%Heodo
2020-09-14REP_03252790.docdoc b64645b5ce17a47798bcf59e362143227eeedd23925ee7e62e7443b1e8b8b7faVirustotal results 40.68%Heodo
2020-09-14REP_8100090221065561.docdoc 5e9694ee68dfea978dbc805fe72b5788f079caf4dc6e7cd66c811286bf943772Virustotal results 38.98%Heodo
2020-09-14FILE_8UNVHTN0F.docdoc 28852a0812d4c493c54382ee8489aef1695d1f07cedc122e9dff86a2ecd451baVirustotal results 37.29%Heodo
2020-09-14INV_27015612.docdoc f0e0bd710b0178b6000d573906078f6906c0cc4781b7634a9e0dd95d33785aa9Virustotal results 26.32%Heodo
2020-09-14REP_518993774.docdoc 228f4f253488803c245aad64df1d3673fa7c72874fb54a9d60741e1cdac97b37Virustotal results 32.20%Heodo
2020-09-14REP_BE2214139119HG.docdoc edb81dd2ee5a1efcb1e3b8822b14ec26e91bb44f52ebf4443b3d934cbd503e30Virustotal results 32.20%Heodo
2020-09-14VS0998926298PK.docdoc d12456a497cf26a25ed636e926612df889ea191a9713e2200f184af59a1a35c1Virustotal results 27.59%Heodo
2020-09-14035312772252843365.docdoc 44cca8cba5ff51e2195e4c42279930fec3adf0cec60c38f0827e18f52070cd95Virustotal results 25.86%Heodo
2020-09-14K_RVW_090120_XKC_091420.docdoc 722c2289021be18bb5a72a4cbd7f2110cb74562d2273b9fd51bfc84a938a15d5Virustotal results 29.31%Heodo
2020-09-14DOC_AA2964160406IP.docdoc e9dddb9c45be4bdea8979c858ffcd44610b0e57e6270b3839ec1f9578862c5f3Virustotal results 25.86%Heodo
2020-09-14BAL_PO_09142020EX.docdoc bb914a60b7b4a135cfed6a5fac2daaefdcd613f1f4c8a1abe6dcbddf9bb58a63Virustotal results 25.86%Heodo
2020-09-14REP_GI9850998966LM.docdoc 26f08e160cfca8f495a847e27d56a77374220ca6245eaf0ae508c37fa408c910Virustotal results 26.32%Heodo
2020-09-14BAL_HE0140866840UB.docdoc b86d9e2cdba854df265e294a80f0de997998b62a7ad1fbb72a58d5bbbdc9372aVirustotal results 40.68%Heodo
2020-09-14FGD_090120_YSM_091420.docdoc 616c517f0e78d80664c32194b017ac706d9badc987d53cdebbee8e58ed5e6827Virustotal results 38.98%Heodo
2020-09-14CJXT5CDH5YEUGYS.docdoc f90da3a95eb5cda8091517c76ee5bf6c38a18c4974d6b882eee3c3a8863fce3an/aHeodo
2020-09-14INV_RSZ_090120_WXK_091420.docdoc 796be372786267239ea478d2b4acb8c5c1f6b4fb8e6f31a3a104bb12f29705fdVirustotal results 37.93%Heodo
2020-09-14INV_129541429.docdoc 4ca85ee8fbc72417267b0d182372896931cbe7025b65001e38019e3bf74cfec4Virustotal results 37.93%Heodo
2020-09-14REP_LF6224899336IY.docdoc 894bb7216efcd37908b4ffa39eaee5a09c5a3c264cdaddb5918bfbb9e7b65860n/aHeodo
2020-09-14TYXL_PO_09142020EX.docdoc 6348c6adae8dfaa6f36c3c709f0f8df4e90d5af5b6fd5852657a6d825d18871fVirustotal results 33.33%Heodo
2020-09-14DOC_GMB_090120_LTS_091420.docdoc 493f41475530b76b9d0d6620de2763277bdaa51bbe084ec12fff5853fa44c208n/aHeodo
2020-09-14BAL_PO_09142020EX.docdoc db5dc06cd13c8fe3e12b314bae4c8be7651a26ed861eecaac0e79a8f8bf0ef43n/aHeodo
2020-09-14INV_NIPL9GWFMSN.docdoc 3e64b6ff86edb967541e4c0b1dc3667ccbd807e99af91d16f9682597b1352ee1Virustotal results 28.81%Heodo
2020-09-14DOC_GT8186332440JN.docdoc 875aadb39437a5366487bf9232ad64eb3d635fae59449e241d84be3133ed2a44Virustotal results 27.12%Heodo
2020-09-14INV_461918679089.docdoc 5d29d4ae2581a27221609c7e3877aa9139dd44042bcde1fb62d7e901d285e4f4n/aHeodo
2020-09-14LGIW_31MRN14JR8Y9D0V.docdoc a153e7d47a196c8848cbd1aa6b81d15adb43a1cc0c6402dca515ea34723c0ca9n/aHeodo
2020-09-14BAL_ERK_090120_CSJ_091420.docdoc 8b92293792b289249b31bcb9f2904fea4360b6d0fa95b90b8e03a6b4d9691fd5n/aHeodo
2020-09-14REP_PO_09142020EX.docdoc e4a9024be2fd969f3d64de3bcff992a2d29ad69e823b5ed145c96a395a013e19n/aHeodo
2020-09-14REP_12676068.docdoc 5b130b9eebaf7a809dc4549ff3dbf09d689b4ede1581cd7f2395e94bd5675355Virustotal results 22.03%Heodo
2020-09-14GAA_090120_VSQ_091420.docdoc bf5e604c3ef6c684bb10f3877f5aaad357943c8b08c0ef560972419d1d80f43aVirustotal results 23.73%Heodo
2020-09-14G_IDB_090120_JYW_091420.docdoc 6c582c81ef9f686301cf1a663938a08c6f793a3f45403b3d4d87da94d5eefc00Virustotal results 23.73%Heodo
2020-09-14PO_09142020EX.docdoc e080d3e47109955d920cea3412153304a44c6675154bdb704180405f9f36b099Virustotal results 21.67%Heodo
2020-09-14REP_PHD_090120_ZPD_091420.docdoc bc08b7a8310a6206226dd767a9c4cc26dd5d5316ad80e399359db8c090294b43n/aHeodo
2020-09-14REP_PO_09142020EX.docdoc 42c4b1eb39af3f83f49c39994431eb0a042d94a008313cdaf1831db93c45cf5dVirustotal results 22.03%Heodo
2020-09-14KSU_090120_OHM_091420.docdoc 358777fc6c34cc75ebc7d92ee6c2bd0b29eaf38c4a215fc317e920ab0f60476fVirustotal results 20.34%Heodo
2020-09-14BAL_6366999187068372.docdoc 089bf49461e57f29762b5c1f0b89fd5db567a615c5fde7cc529369f7472f8f3dn/aHeodo
2020-09-14REP_64072349064.docdoc 79717451025cac2820d0e2aeb5f9cc7b8df2fd300b3c76c4dcacbf8605746debVirustotal results 22.03%Heodo
2020-09-1473384917.docdoc eceae0ba2886d41470b5aacd0de4ac004bc97d88e4bfd489d7e8c420c5f00b79Virustotal results 24.56%Heodo
2020-09-14INV_PO_09142020EX.docdoc fbb786eb4a0f0a9ecf9da92977d330921554d0c4cbdc1218de3641c9a9a16933Virustotal results 23.33%Heodo
2020-09-14BAL_WI4095688879FH.docdoc bed57dded8f474e1685273acb47e279b76b699d0e2c44ac0f299ee924329f3a1Virustotal results 23.21%Heodo
2020-09-14BAL_96923330.docdoc 0cc20101093fe0717a459f14250ba02273813050342e588fed50e77c5b9e52c7Virustotal results 23.33%Heodo
2020-09-14PO_09142020EX.docdoc 33fdd2105c6792ea0096f87c5be02c0a4077e059d550eae962c72be773a41bacVirustotal results 23.33%Heodo
2020-09-14FILE_PO_09142020EX.docdoc 80d8e37e856ada6bc31bdd15d3ef46e47cf2163c6394c78aba7ee026b55a6b2bVirustotal results 22.95%Heodo
2020-09-14IOM_PO_09142020EX.docdoc 3b211810dcd8176df286ff6d29407b15b8977014c8a22899ef51874995c40462Virustotal results 27.12%Heodo
2020-09-14DOC_09493382.docdoc b55cdf490435476aca6b1d71b6b9e509cf20125e5c8135c53de653035fa5a76aVirustotal results 23.73%Heodo
2020-09-14M_T3S7YNRS.docdoc 61c53f6c53756e4688c1b4976287215231032f9f4e38b3ab6aea59c386de1517Virustotal results 23.33%Heodo
2020-09-14A_30127516.docdoc 2e215528092b344b0a24685e8a198c966686cc291bb40928657a8418d60e6dc2Virustotal results 22.41%Heodo
2020-09-14803534899631017.docdoc 4828ea08e57d65a9b30f86f4064c885c040ea13314bbcd0c5275ef0dd7e9a46fVirustotal results 20.34%Heodo
2020-09-14DOC_XS1104679833YZ.docdoc 545c9d3db8ab6b89f55b30fdc4e712ffed6df46456b43712f1c817c0d51eeff7Virustotal results 20.34%Heodo
2020-09-14TED_090120_TPB_091420.docdoc 18f375d906194321adf18d6b5a5218a0a0476e0ff78b0dec48a6775a5f966b4dVirustotal results 23.33%Heodo
2020-09-14IQ3168939675TF.docdoc 785e1a7b7818be6954ac21f9d27f2d52615235cd8915f6580b94a3ccf806c8eeVirustotal results 20.34%Heodo