URLhaus Database

You are currently viewing the URLhaus database entry for http://globalizze.com.br/wp-includes/Reporting/kb9xdzrcqo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:530120
URL: http://globalizze.com.br/wp-includes/Reporting/kb9xdzrcqo/
URL Status:Offline
Host: globalizze.com.br
Date added:2020-09-16 10:31:35 UTC
Last online:2020-09-16 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 10:32:08 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:13 hours, 22 minutes Good (down since 2020-09-16 23:54:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16INV_PO_09162020EX.docdoc 8c089f8051a3844931c97e3148b53085bc199788e03ac5bb8bd6c8450976ecb1Virustotal results 32.20%Heodo
2020-09-16C_424566885.docdoc d568208ba08c7d30eea80ea82899d3af70f76cbfb55c2c0700fa48c40f5aaaa5Virustotal results 25.86%Heodo
2020-09-16DOC_PO_09162020EX.docdoc 4127d459a04c32375faea92c1b93077f9a79c1c7ffff36dd050303fe2c295bccVirustotal results 23.73%Heodo
2020-09-16REP_PO_09162020EX.docdoc bdf14c66a5a4843014c1fef6f147f6a7454f8f34223c51a2cd78f684c80e010aVirustotal results 20.00%Heodo
2020-09-16PO_09162020EX.docdoc 6166313f65b115a61aa233fc6f476490bf8ebb4d5e8fb8790bec568541b2c561Virustotal results 20.34%Heodo