URLhaus Database

You are currently viewing the URLhaus database entry for http://wagnerbandeira.com.br/wp-snapshots/2I8I0DIEBJ8O/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:539256
URL: http://wagnerbandeira.com.br/wp-snapshots/2I8I0DIEBJ8O/
URL Status:Offline
Host: wagnerbandeira.com.br
Date added:2020-09-16 23:55:07 UTC
Last online:2020-09-17 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 23:56:19 UTC to abuse{at}hospedagem[dot]net)
Takedown time:14 hours, 58 minutes Good (down since 2020-09-17 14:54:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17KW_PO_09172020EX.docdoc b1c4f3f033c7084b7df61be8340d0190e40a7ed5742d46dccb477e27ee853c96Virustotal results 35.09%Heodo
2020-09-1732042348.docdoc fdc92337b2b2e66b79997a395980d7d7de9e80daa006d7af482876a6571daa6fVirustotal results 35.59%Heodo
2020-09-1790014536304410428.docdoc b4f9c32e1cdc0458eeb13b08c2894307dc1cdd9df8a610264a5aa0995e9e96afVirustotal results 36.21%Heodo
2020-09-17SG8623558461IL.docdoc 1df5b6fa599fb3c788702a36ea699399ccd479a07f4dff1b7372b1bc6fcf6968n/aHeodo
2020-09-17BV5724994086DP.docdoc 17dab688841a1d907eb36a0850b082eac66fa7d5d3ce3d213033c08b3613e60aVirustotal results 31.03%Heodo
2020-09-17BAL_22NQEVO6K.docdoc 6274d6fc5f58fb23f021e998ce3ba08addb461bc1403267302e7e7a2abc376d4Virustotal results 32.76%Heodo
2020-09-17J9YLYGEJFGI.docdoc 22823faf02dacc31bab524d0ff73e36775b3f629be5a241f9334b6f094220b0eVirustotal results 32.20%Heodo
2020-09-17DOC_WM93SCB7.docdoc 58e9e29b2ad9adffb9050f55dc81946e45a9f4dfbf263e4b4a1af049f2897148Virustotal results 33.90%Heodo
2020-09-17IE9802806609QK.docdoc 1e7768f22ed163e40214a6e4cc98050525441233f7a49852621606f4eedf937an/aHeodo
2020-09-17REP_8676981202976170723379043.docdoc ad55f28a8afc74e7d12b0862d1efc14cccb40e3ff5a2faff1b30c26d2cba6d17n/aHeodo
2020-09-17REP_PT5890015181CJ.docdoc 594c81be9be769fefbfc0df02c470a9ef138fac68992f136b55532e736d0e93an/aHeodo
2020-09-177873716566149822554339405.docdoc dcd3e00d8637a9ba1d0bd4b50e2895294c67b06017af07497a032472d7ade91aVirustotal results 36.00%Heodo
2020-09-17REP_44451625.docdoc 2544f7f03bcb606491b39f0f8cba55899e5e9dd8871128a268329dd6a539f5bfVirustotal results 33.90%Heodo
2020-09-17Z_100050507529217230344715.docdoc 27eba47f653b19797edea37d8dbf75215328081ca3b6abb42719eb226a877a5dVirustotal results 30.51%Heodo
2020-09-1705623639.docdoc 1356c113c2e17f52077c000bfac7f6eeeb2aaa7fb1f9e3650fdd9d72fe79eadbn/aHeodo
2020-09-17INV_QL0205925477HY.docdoc 9d101c9ae5aad02aab0e581cf566b9cf7e1f0e39db512e79045e651ee42ab9a6Virustotal results 30.51%Heodo
2020-09-17INV_06165276.docdoc 8a208192487ebae685a63017664df013b885234a7104db17ec13514b4b9ced41n/aHeodo
2020-09-17BAL_876674172395876.docdoc ac629bfa977c9c601f69581348de29fc7da506da5a9b40c3c9111d37dbc3076en/aHeodo
2020-09-17AUJ_090120_HGB_091720.docdoc 803c6c54c4ebc1733d67a3a13191e80339304b93da85bfd7945fe48a0bc95fefVirustotal results 31.03%Heodo
2020-09-17OM3281426336ST.docdoc fd0f987936c01acfb91bb84e9e9c3e6f425f55d07887f14ee595ec418d252849Virustotal results 40.00%Heodo
2020-09-17DOC_91205439.docdoc 0ed1adf222903a5b3335427d554d4a74c05a27cfd1a438788c04f3b3d720c002n/aHeodo
2020-09-17XNH_090120_FRV_091720.docdoc 595abb95ad8bea9fcd875fee5c21baaf5f829e997eb430384a8fd7f43da2e0cfVirustotal results 38.98%Heodo
2020-09-17PO_09172020EX.docdoc b01858672d33ba389a6a20f1c3d0cdf3987bb6f7d3009d178478ec6bf0fbd674Virustotal results 37.93%Heodo
2020-09-17YCC_PO_09172020EX.docdoc 9a88ee70e3fe3b917d0907d5061182917ad1a2fce66ea4cea78b8a9e870be220n/aHeodo
2020-09-17AAA_090120_NCP_091720.docdoc d15ec5002184364b882e5c3dc5c4fad1d083eeac52de352b2d263205c92e3165n/aHeodo
2020-09-17W_81126331.docdoc 9c68396b3fa012c514cfdcff37a8d8abfa59cbbb9ced4911f1133453bf1d7c5dVirustotal results 34.48%Heodo
2020-09-17QTK_090120_XXU_091720.docdoc 289d6e951815f7869f284dab3b630a8adcaa56a31d17ce61c4de04bdbca2894aVirustotal results 33.90%Heodo
2020-09-17C_92472151.docdoc 8bed6a4e027b38076c316eb5378c9d60d8fd9305217dba0e315e93974091667cVirustotal results 34.48%Heodo
2020-09-17D_PAS_090120_VFR_091720.docdoc b4306a30afe6746f29ea38b3e2dca0704d5d3d18107aa1b8ca555bd35fa918f7Virustotal results 38.98%Heodo
2020-09-17R_MA5311630504XH.docdoc a2d7a015bbf13ab37b0062c97dce2a11c02f0657166b6fb813780017ba5de723Virustotal results 34.48%Heodo
2020-09-17INV_PBDAURW.docdoc e5e50b3fe1f789a9a2a4a7b75735e5bd4bb90824b7925886453fe6c80d5641aeVirustotal results 33.33%Heodo
2020-09-17PRK_090120_LFI_091720.docdoc 524f6d1744c625d4ee827ab1ee1406f5aeef8c8799b8cf6474c2a53014a1dfadVirustotal results 28.81%Heodo
2020-09-17V_WR7215760529WK.docdoc 6d9cad95f8aa3d8219f21391e294a8dedbde904308f501b7f4be63eb92a8dcf4Virustotal results 33.90%Heodo
2020-09-17REP_52627258.docdoc f8be1cb32fdc9776f4b599f4b99eb0315d3fccebbdc850498b96f6a65fe9e02cVirustotal results 32.76%Heodo
2020-09-17B_64233442.docdoc 528a62bc2a5bb42529a57abc0367b0a612ebe84f846906aa5a6737e759d6ae84Virustotal results 25.42%Heodo
2020-09-17J_54049522211992956.docdoc 7a8024cf777ab45c5c969c5efff3dd4f289bc22baf1c91bd884fc2d29435c884Virustotal results 25.42%Heodo
2020-09-17FILE_K97IYHVL9R9.docdoc 39c83fd21ce730714e93e6bbe85f21770a761285c3fd1b2b2473e00644785e82Virustotal results 27.12%Heodo
2020-09-17BAL_68790322.docdoc 89c63f940c17124065f94ee04b40a3cf2f048fb270b93b38fe1b1e937ab4abffVirustotal results 25.42%Heodo
2020-09-16INV_XO2360288723DU.docdoc fc4eb4fb15308d6878f61e096934ed77f56f5f25b48dc2f5f30f0f02cf23a0ecVirustotal results 25.86%Heodo