URLhaus Database

You are currently viewing the URLhaus database entry for https://mukah.com.br/anjosdaguarda/wp-includes/balance/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:590885
URL: https://mukah.com.br/anjosdaguarda/wp-includes/balance/
URL Status:Offline
Host: mukah.com.br
Date added:2020-09-21 22:50:08 UTC
Last online:2020-09-22 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 22:52:21 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 hours, 57 minutes Good (down since 2020-09-22 01:49:42 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22NTKB_78753372968517844.docdoc 23184d215b3db4bb670b2c1e70e1b7f81760cdec7e35b8a0a90cebc4a6797eccVirustotal results 32.20%Heodo
2020-09-22PO_09222020EX.docdoc ed6598e7e6d37524439397ed78a735fe41117f47c0964cba780b5800d4eb5146n/aHeodo
2020-09-22INV_99115576306.docdoc 0489a6b94e2c6206bd2730cc32c8f873d1ac1af2ad02bdb69a77a8078460741cn/aHeodo
2020-09-22BAL_198281284122986341504.docdoc 66a72b85f41d624425d7d908104bfec8a8c0c8412c8a23337b71844f909a0175Virustotal results 30.00%Heodo
2020-09-21ZS0191399866WT.docdoc a09dd0e095d93b68eb0713e31e92eb9caee82983e99ddccdb71177216cc52f30n/aHeodo
2020-09-21INV_80R9ODJ8BGN7GM.docdoc 0b406d237fa37888f1acd0ffc4b59577ffd5e45b792a835c2141483e2206ce9cVirustotal results 30.51%Heodo
2020-09-21INV_LI5795844453RA.docdoc 86a8ee1c5f1f5ce84a8f3b31c04f51e324a47d2de0936339357ee0e9a139e0c6n/aHeodo