URLhaus Database

You are currently viewing the URLhaus database entry for http://www.weblabor.com.br/avisos/browse/w4eai49620761898s9tjwae2euzi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:527979
URL: http://www.weblabor.com.br/avisos/browse/w4eai49620761898s9tjwae2euzi/
URL Status:Offline
Host: www.weblabor.com.br
Date added:2020-09-16 07:44:04 UTC
Last online:2020-09-16 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 07:46:39 UTC to abuse{at}hospedagem[dot]net)
Takedown time:7 hours, 42 minutes Good (down since 2020-09-16 15:29:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16INV_94780141636.docdoc 54f3ff0a6c12843bdb1b448362320aac7421e7a1c1a210779dbb9c57ede15a75Virustotal results 32.20%Heodo
2020-09-16YF7P5HZ26OJX1A.docdoc 7e6eb01ae2a01609fa859b74092e049509e4c10f6c3fa6b81c728154ba97105bn/aHeodo
2020-09-16INV_GK6769273657LD.docdoc 0c982fd7e6da85d772a410a46a6569667df380d6fd19d4c597ca1a0f30c140acn/aHeodo
2020-09-16REP_GC3773109456JX.docdoc 5aa5a3b76812b8b3edc3768f494fd3550f5088d44872ac9f4bbabb99137427f1Virustotal results 25.42%Heodo
2020-09-16REP_0Y092331VMHH0.docdoc d568208ba08c7d30eea80ea82899d3af70f76cbfb55c2c0700fa48c40f5aaaa5Virustotal results 25.86%Heodo
2020-09-16BAL_0WBMTVCCXWH.docdoc 6ba958c1d5b047f3d205a8d70c0603727e7777113e1a94b4a6cd6da9a2981de1Virustotal results 25.00%Heodo
2020-09-16C_PO_09162020EX.docdoc 8df40fea0429dee60fdf8fa354db52ddf3cbe643cd5945d226b5eedca75bd659Virustotal results 25.86%Heodo
2020-09-16JZU_6QV7S7NVXZ4A59K0.docdoc a8dab829058b2200575ec6773790780a48c8d38587dcd02bc094c9084cd57eb1Virustotal results 28.07%Heodo
2020-09-16DOC_09046083.docdoc 4cc531c7241824525205b57dd2b2ab65b3d2d37861becf043ff065f0a091dbdcVirustotal results 27.12%Heodo
2020-09-16IMS_090120_KTH_091620.docdoc 4f21e25c362b1dc72f9dd3b2b0910516918a46a4016a631a2ee276493d7d160dVirustotal results 20.34%Heodo
2020-09-16D_PO_09162020EX.docdoc ba11cc626e1527c8dec4bf3fe20af2a338030cdb646252a4e170d19512d19d89Virustotal results 27.59%Heodo
2020-09-16R_42QDIQBU494JRYHN.docdoc b3f649438cba7dc8f34dbdea69bb67a356906ead944752b8abcc4fcc23b737e6Virustotal results 27.12%Heodo
2020-09-16AWV_090120_MMO_091620.docdoc c24eaf2c7e9192b22bdb558cdcb458e6de607d17f373c4d46d92561b2312f1d0n/aHeodo
2020-09-16INV_27863861.docdoc b8d558c1ac20808b0809fcfa0c5a017da7e300736b6dbfee52ed1930c7b19a08Virustotal results 23.73%Heodo
2020-09-16REP_BIT_090120_QVT_091620.docdoc 4127d459a04c32375faea92c1b93077f9a79c1c7ffff36dd050303fe2c295bccVirustotal results 20.00%Heodo
2020-09-16DOC_50381867.docdoc 8398f9c5f37ef0558a84d839ee7058340351a71fe4cf26d2590652a5a66857f8Virustotal results 21.05%Heodo
2020-09-16J_QKV_090120_EOI_091620.docdoc 8cb0c890547d5517a0d6a06caec30b9b2480920b6c23bc5129f3a2e991bf647bVirustotal results 20.34%Heodo
2020-09-16DOC_UUU_090120_UVG_091620.docdoc b7d7c443145be4e2543b2786517f68cfef114f06e7c276368a6046c98963b766Virustotal results 20.00%Heodo
2020-09-1677794373.docdoc b8684570ff020824676af136d3c0076181180c4d7abe963ffb04a340ecb68186n/aHeodo
2020-09-16SOW_RO0220551750XL.docdoc 30f103a39f5ac055f29f5b9364d03f9777737256ea1096c2cb957cd5285ea8b8Virustotal results 20.00%Heodo
2020-09-16DOC_73045287.docdoc 733150afe58d633a7748c6b98f7f64f72685083f5b0535ee970260073452bc1dVirustotal results 20.69%Heodo
2020-09-16INV_PO_09162020EX.docdoc a28a23ca128d4219c14856421649e8be9836b60650040fba71022341d239b6faVirustotal results 20.34%Heodo
2020-09-16AICV_533243715903955842.docdoc b465429729fe580c1862844b5e743b4913418b2bde007ae65a8b150f3defe751n/aHeodo
2020-09-16WPTC_LBV_090120_TLD_091620.docdoc dcfdf9a342db69a880c3acc43b01f2e3f04938ed129c9b3597ee7aad3377f25dn/aHeodo
2020-09-16GYG_08002241438570063.docdoc abd53fd5f66e4ea484f4c037e59274f3933de850d9e618d2cc9123d48a571affVirustotal results 20.69%Heodo