URLhaus Database

You are currently viewing the URLhaus database entry for https://loginbr.com.br/help/OCT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:533657
URL: https://loginbr.com.br/help/OCT/
URL Status:Offline
Host: loginbr.com.br
Date added:2020-09-16 15:36:16 UTC
Last online:2020-09-16 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 15:38:10 UTC to abuse{at}hospedagem[dot]net)
Takedown time:3 hours, 50 minutes Good (down since 2020-09-16 19:28:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16REP_PO_09162020EX.docdoc 9ca5390e9af21757dc77575f56e9d0528c527843951ae719c3aedd2d8680ce7aVirustotal results 39.66% Heodo
2020-09-16PO_09162020EX.docdoc d4d482bd99e2f75b977c3fe22ee3df44c1e3758bd61f0636d31c1e35c2d38be6n/a Heodo
2020-09-16PO_09162020EX.docdoc 278fc88598a0bfe49be55465fdb975272c6315e3845d604caba7631cc5f32595Virustotal results 38.98% Heodo
2020-09-16ZC9008375919HO.docdoc 6ffa316248fda88118682551c3b421820281e25578cdfb9a13e6457f174d7ba8Virustotal results 39.66% Heodo
2020-09-16BAL_490875136487619057.docdoc 4254483388cd90e041291de79b3a3d26456908113cb0b2957401b5838c949c38Virustotal results 38.98% Heodo
2020-09-16DOC_PO_09162020EX.docdoc 4d88090314c39059da536bb37270cdf7ffadeeda4ea768b55dcb9f2b807586f4Virustotal results 38.98% Heodo
2020-09-16REP_CW3954818708KH.docdoc 9c7a17b3e9bd6913701b7e8dac9cf2408ec57752e2c2515ba3e1b917fe40659dVirustotal results 39.66%Heodo
2020-09-16BAL_XDZ_090120_RWI_091620.docdoc 3cddfe22684c82c3eeeb0d3c0c8745719dcd417db42c4ea6774c9a10d1a88f3bVirustotal results 38.98%Heodo
2020-09-16INV_TFT_090120_XFI_091620.docdoc 962d453203d41ae26badcb1083a24aada6ccb51ae5ef7a416d850a0b8cee6c90Virustotal results 36.21% Heodo