URLhaus Database

You are currently viewing the URLhaus database entry for http://laschuk.com.br/Payments which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51258
URL: http://laschuk.com.br/Payments
URL Status:Offline
Host: laschuk.com.br
Date added:2018-09-04 14:04:21 UTC
Last online:2018-09-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 17:46:17 UTC to abuse{at}hospedagem[dot]net)
Takedown time:3 days, 3 hours, 42 minutes Bad (down since 2018-09-10 21:28:36 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-05Doc607876.docdoc 64850c28f4f1bda5d5d325df5c92269eeba272c05a9cbaf7c63779cf4351e5deVirustotal results 46.55% Heodo
2018-09-05Doc6401.docdoc e0de084abdb8acde6c3037d57c9cd23bb061f8d61ebae6302cccde04579b2e3en/a Heodo
2018-09-05Doc3290.docdoc 50128add4f9eb89878473727c1e18acca17e7bf243b8437455dec4995dc44141Virustotal results 45.00% Heodo
2018-09-05Doc105537.docdoc 5f144e4bd0ed7e20e208f8642259165047acf67d4387d507a649d82f557909f9n/a Heodo
2018-09-05Doc59790.docdoc b364ef7c9ea67200ea5164f83f5362e4bc5793a93773fabeed1dc99327b760f0n/a Heodo
2018-09-05Doc9719.docdoc 868b40b41a744340afe778ead2c1f2a96194a8a821e51e221e3741c9fffd6986Virustotal results 35.00% Heodo
2018-09-04Doc730967.docdoc f23e29008e424c4efa7e5c54bdc2aa505a1636ef75af701940c429c9be9356e6Virustotal results 31.67% Heodo
2018-09-04Doc346846.docdoc 78a2e9738b5c7f05d3ca5e50eca5613e33c2e2fe1023258a4e1e1e82f3f6f50fVirustotal results 33.90% Heodo
2018-09-04Doc260230.docdoc 2130de7af1045f9de0149584233713c4bd6c58b4804fb3f09449b6d9964dda49n/a Heodo
2018-09-04Doc94849.docdoc e60aaaee60ab14bce7a6abcd43f186249a4ec2637d77079b2f78b172f2191232n/a Heodo
2018-09-04Doc84701.docdoc 358f8bd815ea5ebae81cea7f4d98fd1a462b402cb8a41520285c822d27084b6fVirustotal results 33.33% Heodo