URLhaus Database

You are currently viewing the URLhaus database entry for http://vendasdesaude.com.br/erros/FILE/C8EKJ01DXtEALKIot/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:539269
URL: http://vendasdesaude.com.br/erros/FILE/C8EKJ01DXtEALKIot/
URL Status:Offline
Host: vendasdesaude.com.br
Date added:2020-09-16 23:58:05 UTC
Last online:2020-09-17 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 00:00:28 UTC to abuse{at}hospedagem[dot]net)
Takedown time:13 hours, 31 minutes Good (down since 2020-09-17 13:31:39 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17FILE 7814429.docdoc 8f91dde780ab0a7bcf8fcf57511eff5c919226d21b835ae1754b7c72bc8d391aVirustotal results 30.51%Heodo
2020-09-17file-2020_09_17.docdoc 96eeeb31a1f499dfd36fd8dd65250c5639ec0b33444d5b47b2c37f95a2914336Virustotal results 28.81%Heodo
2020-09-17REP_20200917_QO898649.docdoc ab216eb174619e6724c2be5b7dff2fc7c76a1ab5a8af39dc295515707455dbb2n/aHeodo
2020-09-17List_2020_09_17_R4505.docdoc 3bbf96c87172c96d0a2cd7ca4a4100475a30d0c6285e69faa75f4bae9c8e8812n/aHeodo
2020-09-17Doc-K792314.docdoc 0920fd8f96f19fb4f53a54cd61f13f29309f2939c2eeabb115472120ea37b74bn/aHeodo
2020-09-17INF 2020_09_17.docdoc 22f5f6c960c4008f562bf7d34f803b15610e0542c351a24a43d90c7d86a63df0Virustotal results 31.67%Heodo
2020-09-17UNTITLED-20200917-005.docdoc 99de5b08c80271540dbc672e7af4161673700258914417bd7087cb843303a53bn/aHeodo
2020-09-17mes 2020_09_17 258.docdoc 854bcd59fa6d9dedc3e6021ad7793bc443b022868cbc0ab394c72373e237d3bfVirustotal results 33.90%Heodo
2020-09-17Dat 2659651.docdoc 577145a90888049667fe0faefce1bab143ec16a84550461a596ebc4cc7d30c5dVirustotal results 34.48%Heodo
2020-09-17Untitled LZ137.docdoc b92c9f9837fd578d8b611fb4b9247bb2e153bbfc1b46af2a3114830059ae3599n/aHeodo
2020-09-17inf 72192.docdoc 90977cee153334af0c84b8bfa29245fcc56734d5c0d84a6db5f3c51173e935c8Virustotal results 33.90%Heodo
2020-09-17Mes-20200917-214578.docdoc fb5fff7878856cd2289cf8e0f9cc0f6f8ca84d0945a229a1d94dae877518f3a1n/aHeodo
2020-09-17Rep.docdoc 5ca2faec670c85dbaf71d46de792eec5b7475ecb4a01861ab2e1606dc9d2ffebn/aHeodo
2020-09-17Arc_2020_09_17.docdoc 21302b9888a9706e983c89b820ca95529af59fd6247f951fc9fc1a4271131b25Virustotal results 33.90%Heodo
2020-09-17UNTITLED-2020_09_17-2827203.docdoc 1583ff2b2aa0f561381343773c8693a1a1e0f08896fc5c2f8d2aa182e77f3cb6Virustotal results 33.90%Heodo
2020-09-17Mes_990.docdoc 1d0eb0bcc259726383e2d351d1fbcfb5cfd92fce33941766914bd0c987b85f81n/aHeodo
2020-09-17ARC_F7789.docdoc 7e81cfac7c5845aec91ab20b076dcd629559592c6280096ea6d3b8e8bf86f141Virustotal results 32.76%Heodo
2020-09-17Attachments 20200917.docdoc 93e5518c6002c39658a208a4152fadd0a31be8c6ec72ef32390e1e082d8a9982n/aHeodo
2020-09-17Arc_2020_09_17_BBT215.docdoc 3efda29907b74c348feb380198e81f82dfe13f13cf585d8738dc6a8d134ddafdVirustotal results 29.31%Heodo
2020-09-17980-20200917-KKI811.docdoc baf58e21819121a357309e1e125edf6017266c02f9d3d2bb2dd9da34e1387dbcn/aHeodo
2020-09-17ARC 20200917 KNG034.docdoc 9c98e089c945cefbc8299157f8e0c77b285309ca93d5b1fa28a08ec168b3d823n/aHeodo
2020-09-17File_QRT9702.docdoc 5a468353a435f890761d3728d9d3a3f749ab60c3a84a4130d3350e7c11ce4562Virustotal results 30.51%Heodo
2020-09-17inf.docdoc 254a33e1b25338514edd5ba6d1d64f958a599a411ae5e53777ac52cc6aee8258Virustotal results 37.93%Heodo
2020-09-17dat_YFT94857.docdoc dad3849c48e7bcab3910f21714cf78be123d625e4198309441654f24ec7b2b9eVirustotal results 36.67%Heodo
2020-09-17UNTITLED-LCN93268.docdoc 1f78ddc5ed3c3410d1dae6bbdf7801d065a07f11d652a3275d86939253a064c0Virustotal results 37.29%Heodo
2020-09-17Inf 3019.docdoc be20f5c8e432d65baa21e6758f82d0b3994eb4615d14a7ad56c7af30135d5919Virustotal results 37.29%Heodo
2020-09-17File-2020_09_17-5588.docdoc 35088b84f2026bcbde876c9c9188d18287ccaf07b304b1fa9910f476c7aa36a7Virustotal results 33.90%Heodo
2020-09-17ARC_2020_09_17.docdoc 40e2159469907d860ab2495b9e79a86bea6f7976fdee23dabcb7ba3e52e199b6Virustotal results 34.55% Heodo
2020-09-17doc_G923476.docdoc dc7e2135030000c1ea2210105e8eaebc8efd26a873cf4828a4e2d84a0b81805dVirustotal results 33.90%Heodo
2020-09-17INF_20200917_123316.docdoc 0abf8b157b81a076c15c594185b4718db8113e7911641db991e7b44644d7ff0bVirustotal results 33.90%Heodo
2020-09-17Attachments_Q161151.docdoc 68b722df7ebc8c17375e2a8490c5054b77530b12e82fbb5645bac262b6fbed82Virustotal results 32.20%Heodo
2020-09-17Mes 20200917 OOS045.docdoc d452df085e4fa1e9de2c26da033abc9944b538757f876b06980b6ec948953f08Virustotal results 32.76%Heodo
2020-09-17Rep_717.docdoc 4a302b44df11e4712e28d8e684fd9be280473a1f16ede2d69ee10c7aa97122a8Virustotal results 31.58%Heodo
2020-09-17rep 20200917 BGT254772.docdoc 687981cc120b53bf16672e61aa62fe4151a7b790802eaab9f3839cd82612429bVirustotal results 30.00%Heodo
2020-09-17REP-20200917-40328.docdoc e778b3db0521e8c8b9f7429eeaafee991bca2bca736c3a9330e0252dda698f66Virustotal results 30.51%Heodo
2020-09-17FILE_2020_09_17.docdoc 0ee3ee6d46932766c0b60ab6d06d8791a97c6cc37289e03f7d74543916ca8145Virustotal results 31.58%Heodo
2020-09-17Inf 20200917 584.docdoc 2af1ab2f6d90a659c195d1c00701bb985a6832bc342fa817f3b24c1e590dc9d0Virustotal results 29.31%Heodo
2020-09-1783588 20200917 OJH443368.docdoc 3538192f3f10da92ecaa87637e9f5a9614f36d3da3b52866d70bf314c7c7d26cn/aHeodo
2020-09-17LIST-20200917.docdoc c5b888495a9bfa112794f936114fe7d3ab9bbbb1fa68b41d1d25a67f6372efb5n/aHeodo
2020-09-16Attachments-CD112252.docdoc c7f64e6d64eb913fe7ff98e6407db3f38448cec6eaf8523531da0b29843acd09Virustotal results 30.51% Heodo