URLhaus Database

You are currently viewing the URLhaus database entry for http://hlg.juntosporsc.com.br/wp-admin/Scan/arkuyy2a/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:532607
URL: http://hlg.juntosporsc.com.br/wp-admin/Scan/arkuyy2a/
URL Status:Offline
Host: hlg.juntosporsc.com.br
Date added:2020-09-16 14:08:04 UTC
Last online:2020-09-16 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 14:10:22 UTC to abuse{at}amazonaws[dot]com)
Takedown time:3 hours, 10 minutes Good (down since 2020-09-16 17:20:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16QSR_VGK_090120_SCO_091620.docdoc 02451c13f63ed93c6ed0c0e4a3025100834fd59eeaa78acff45d726c056b2293Virustotal results 38.98%Heodo
2020-09-16REP_PO_09162020EX.docdoc 201b4b59a31c60055c285e64737d5bcba8974b4400c27f37765636deea097b30Virustotal results 39.66%Heodo
2020-09-16REP_PO_09162020EX.docdoc 6820256b4c1c4c5b50146126f828d2317ef12e023043a390611fe9b036cfe638n/aHeodo
2020-09-16LRX_47214494.docdoc 3cf9e2dbe6b1d8c1900b0af337159915f15ed317ee76d553df5999d0f7ba6e9cVirustotal results 33.90%Heodo
2020-09-16BAL_JHV_090120_ZHG_091620.docdoc c676f40df939ef32b19cfcd36138370ce7ed85e33cfa4e744be20734235ef2caVirustotal results 31.03%Heodo
2020-09-16741024441220.docdoc 361d848b59beb5b40b7839f66735d926f31725d38136435f01499fb0e4a66463Virustotal results 32.20%Heodo