URLhaus Database

You are currently viewing the URLhaus database entry for http://laschuk.com.br/default/EN_en/Invoice-4673713 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:55483
URL: http://laschuk.com.br/default/EN_en/Invoice-4673713
URL Status:Offline
Host: laschuk.com.br
Date added:2018-09-12 08:37:23 UTC
Last online:2018-09-13 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-13 21:14:05 UTC to abuse{at}hospedagem[dot]net)
Takedown time:1 hour, 1 minutes Good (down since 2018-09-13 22:15:51 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-13Outstanding invoice.docdoc 1e87808f2a505c93cf95345d43b97124d655eb080d1263b785e08d3fe0bf206cn/a Heodo
2018-09-13Invoice Confirmation 1305832.docdoc 6207c24972e68133a2f34cac9e49035ae0dbece716af77006626d2232c2260f3Virustotal results 18.33% Heodo
2018-09-13Billing Invoice - Job # 5400773.docdoc 5b13e439c9bc2479ec8aaaeabc516377178fdeafff910e94ec586e6b665aa031n/a Heodo
2018-09-13Invoice as at 13/09/2018.docdoc 764122c8c7d3c80f2c4c5c812333b6d804683a90cd5c6ffe28d36e6bbd2ac90en/a Heodo
2018-09-13Billing Invoice - Job # 3495858.docdoc 8870a62f875161882a0c93807ccc85209554a068953ae16190484414b427b173Virustotal results 36.07% Heodo
2018-09-13Invoice as at 13/09/2018.docdoc 30594291490a1928a7bf89f633c88b3e8bb41c4ae795156309a0f076652d072cn/a Heodo
2018-09-13Billing Invoice - Job # 6771474.docdoc ad3176f417bc5f65c70bb74f406709e4057a3b798f89488b559051e5743528afVirustotal results 32.79% Heodo
2018-09-13Billing Invoice - Job # 6771474.docdoc ad3176f417bc5f65c70bb74f406709e4057a3b798f89488b559051e5743528afVirustotal results 32.79% Heodo
2018-09-13Billing Invoice - Job # 6771474.docdoc ad3176f417bc5f65c70bb74f406709e4057a3b798f89488b559051e5743528afVirustotal results 32.79% Heodo
2018-09-12Invoice.docdoc da2a56412ba9240e01d478074dfee4cd0ef92d0d8d1d2b42b01411212c2e6e83n/a Heodo
2018-09-12Customer No 3921397.docdoc e6a578c89917327adb9fcd46a34823c0f2b34ec26d7e0bcdd08f2fdd0b3e534aVirustotal results 29.51% Heodo
2018-09-12Latest invoice - 761851.docdoc eabb02e2198c7641bf9d3f8c1e1a467f5a7c55cfd6516f39078a2528083daefaVirustotal results 31.15% Heodo
2018-09-12Customer No 4431197.docdoc 907aeb750eb680cb57c7e93fdb76af114de2bcd12fb4ea47af5e76e755f832c9Virustotal results 31.15% Heodo
2018-09-12Outstanding invoice.docdoc 2ceb81f9c7601592ac7b99888c1c7611f0cb9053aed8a7a9306078f4c1d9fb92n/a Heodo
2018-09-12Month notice.docdoc d4482c6be7b3208e3668f55f40b2207dfe7acd33c26f93e7100757827eafe66fVirustotal results 22.03% Heodo
2018-09-12Statement as at 12.09.2018.docdoc 1858e2a692ef2d989e4cc717bb602057d9fb6d6bf7b65af08260f6a3cb39eff9n/a Heodo
2018-09-12Review invoice required.docdoc 0fc829670e8ddcd6df974c9972671f835426fa1aa21cd00f2e631e49e709d6c1Virustotal results 34.43% Heodo