URLhaus Database

You are currently viewing the URLhaus database entry for http://sansorescontabilidade.com.br/wp-snapshots/eTrac/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:539628
URL: http://sansorescontabilidade.com.br/wp-snapshots/eTrac/
URL Status:Offline
Host: sansorescontabilidade.com.br
Date added:2020-09-17 00:16:04 UTC
Last online:2020-09-17 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-17 00:18:25 UTC to abuse{at}hospedagem[dot]net)
Takedown time:13 hours, 17 minutes Good (down since 2020-09-17 13:35:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-1780716688.docdoc 5550d9e16cad7854633fe0ca4c7315a5595cdb78147360f022c916fb27890aa6Virustotal results 32.76%Heodo
2020-09-17PO_09172020EX.docdoc 9ffdb4d90517b3838da2fe89fe09c33a7351ab0d5b14173bf9674c01c88c1a7aVirustotal results 31.67%Heodo
2020-09-17E_JJN2ZR86W1SC.docdoc 1da1190d2c7472ff429ae35611b7120698dca55175d1c298e68f24f33fc4caecVirustotal results 32.76%Heodo
2020-09-17ZBWA_HD5X9QMNCMMAS2P.docdoc 9af94d901782b57efcfe1221696091455a812897cb8a8707d72bd554841ce526n/aHeodo
2020-09-17REP_KMK_090120_ZUH_091720.docdoc 786d28cd90e9a2bc887c9cbf4225a7fed95a3e28b07ced5f8c932e1f1e673b66Virustotal results 32.20%Heodo
2020-09-17BAL_LPL_090120_TNK_091720.docdoc 5a9d0acacf9a1616330ac1559a2243f80f03ec322e564298c0cff70b28014a7cVirustotal results 32.76%Heodo
2020-09-17DOC_MF4864016700VT.docdoc a5ecfee423f7cf0ff0efb76f20542df38a7d88230a256aa5e343d1040950e5b8Virustotal results 32.20%Heodo
2020-09-17PO_09172020EX.docdoc dcd3e00d8637a9ba1d0bd4b50e2895294c67b06017af07497a032472d7ade91an/aHeodo
2020-09-17PO_09172020EX.docdoc dcd3e00d8637a9ba1d0bd4b50e2895294c67b06017af07497a032472d7ade91an/aHeodo
2020-09-17K_MNA_090120_GDS_091720.docdoc a646a759b53cde465f66a1cabf6363c9b826f10073a766cdfff2a015168ae2dcn/aHeodo
2020-09-17GPN_BQM_090120_JOX_091720.docdoc 08ea41da443b28325813eaf4915479f7b46fb810c9abb7ff732f3da617f9aaa4Virustotal results 35.59%Heodo
2020-09-17BAL_197725493565568.docdoc fa191cce995bce7e56b494fa94b13859f68f274e86a7aceadbac93d6778ad84bVirustotal results 35.59%Heodo
2020-09-17FILE_5847012339202475611.docdoc 9d101c9ae5aad02aab0e581cf566b9cf7e1f0e39db512e79045e651ee42ab9a6Virustotal results 30.51%Heodo
2020-09-17FVJZED4.docdoc 983df755ad1ff2fcd969c936320a9571908168ddbff5caa34b63ea51be406312Virustotal results 35.59%Heodo
2020-09-1776361575.docdoc ac629bfa977c9c601f69581348de29fc7da506da5a9b40c3c9111d37dbc3076en/aHeodo
2020-09-17MC0QLZP48OB0LN.docdoc 4cd9f43484e69a009522a8853514539c74fa5b59f03f86c34a85037ff3076a55n/aHeodo
2020-09-17DOC_57914623.docdoc fd0f987936c01acfb91bb84e9e9c3e6f425f55d07887f14ee595ec418d252849Virustotal results 40.00%Heodo
2020-09-17XKW_090120_RDV_091720.docdoc 51d460db7db57fd212907c9aed23bba4891c43175f73978da2c791c60a412c43n/aHeodo
2020-09-17Y_PO_09172020EX.docdoc aee3fb0f9a09817e17c7844a0ed7f8c34fbd6c30a83fa529ebe838670c0c4a21n/aHeodo
2020-09-17FILE_SLCVWHEBABR97.docdoc 55830632b4ab2552e0bd05b69d7e03291c05b89c3f4a37dccb611ec180d70721Virustotal results 38.98%Heodo
2020-09-17BAL_BBM_090120_SPB_091720.docdoc 9e4278eac329ac03d6c9b60c69594f50d2efb41914b428309216bdfe5ae15904Virustotal results 39.66%Heodo
2020-09-17FILE_PO_09172020EX.docdoc d15ec5002184364b882e5c3dc5c4fad1d083eeac52de352b2d263205c92e3165n/aHeodo
2020-09-1762807957422249156.docdoc 8d1ff2bacfbda66fbafa8dd2c05aa1912c32f694f2d0aaac4ac43897edcb677fVirustotal results 31.03%Heodo
2020-09-1758FOZE8JV.docdoc bcf9a2940f9615487667d5d0edb9dfcb6e5917b328bc56ada5fe0d5b9f43a9c7Virustotal results 34.48%Heodo
2020-09-17FILE_34062321622624253.docdoc 8bed6a4e027b38076c316eb5378c9d60d8fd9305217dba0e315e93974091667cVirustotal results 34.48%Heodo
2020-09-171022974256598884.docdoc e09973ac979e2a9efbdb59ea10416f8714545ff719579b21a48327219a3ec797Virustotal results 28.81%Heodo
2020-09-17BAL_PO_09172020EX.docdoc 6758d3603f3eab05e72d8c9e6f7714f93f572ca89397a5018c8104d0c6099810Virustotal results 28.81%Heodo
2020-09-17BAL_124511543197.docdoc a2d7a015bbf13ab37b0062c97dce2a11c02f0657166b6fb813780017ba5de723Virustotal results 35.59%Heodo
2020-09-17REP_PO_09172020EX.docdoc be4589b5f647c7b97fdc399757c263c8fbe549218e25eea82148ad48f7fa5017Virustotal results 30.51%Heodo
2020-09-17REP_89019027.docdoc b1e7a7277e944331a98e7ae6a5910af8b595bf329d5da053469800cdf447f2c8Virustotal results 33.33%Heodo
2020-09-17PO_09172020EX.docdoc 6d9cad95f8aa3d8219f21391e294a8dedbde904308f501b7f4be63eb92a8dcf4Virustotal results 33.90%Heodo
2020-09-17INV_PO_09172020EX.docdoc 76bf8d09a314a6ed1f11e8794d3027fcedcc3762677e37d8f7a304e4d370837cVirustotal results 27.59%Heodo
2020-09-17REP_43596545.docdoc 1a487a6af75caefff2748862adf7200a692c1e5f6453c1d86ebceab252b5bd66Virustotal results 25.86%Heodo
2020-09-17TTN_090120_YUL_091720.docdoc 409d5db4ee06957895e043e25c81a8d9b2438a172c248bfc3f149c6c947e3ce3Virustotal results 26.67%Heodo
2020-09-17INV_89346594.docdoc 39c83fd21ce730714e93e6bbe85f21770a761285c3fd1b2b2473e00644785e82Virustotal results 27.12%Heodo
2020-09-17BAL_IX9356888862FU.docdoc d30169f108ec72fbaf16bb8726e798602988e1c42a7b3020b0ef0ad0572f9625Virustotal results 25.42%Heodo