URLhaus Database

You are currently viewing the URLhaus database entry for http://aqfsistemas.com.br/manufacturerl/wpbuq134538584ys42gj8cxm1z9y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:609324
URL: http://aqfsistemas.com.br/manufacturerl/wpbuq134538584ys42gj8cxm1z9y/
URL Status:Offline
Host: aqfsistemas.com.br
Date added:2020-09-24 06:27:06 UTC
Last online:2020-10-06 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 06:28:10 UTC to abuse{at}dimenoc[dot]com)
Takedown time:12 days, 8 hours, 41 minutes Bad (down since 2020-10-06 15:09:27 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24SL6570246851PR.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 33.87%Heodo
2020-09-24D_29488140.docdoc 3321abc9c460868cfafe80f968ccea4254b02ede808bcabe4dd58055ffddb358n/aHeodo
2020-09-24BAL_WP4569282267LF.docdoc b8a9d5f54e75467b003cb37db317d9537fc49705aa3334531937929937b0eaaeVirustotal results 29.03%Heodo
2020-09-24FILE_OU9072458313UL.docdoc da886aa9c4cf9af28406c6c6b2bd1a84fdca0dd1861259185aba9da512264acfVirustotal results 29.03%Heodo
2020-09-24FILE_DB7YPZ89R2D.docdoc 0b102ec43b4bf3d7459491664e5c2f731286d92134e87e00967a144e59c28ad0Virustotal results 29.03%Heodo
2020-09-24REP_237Q6HTL53O9Y.docdoc 673b66564bc293cc5e89a33f4b16692f12071b7984f57342f1e011ddd5cc96d0Virustotal results 26.23%Heodo
2020-09-24REP_48520957.docdoc 3f0693ecde0d7c9983bda3bfa22fbb8243695bf8a48ae127e121813ae527334eVirustotal results 29.03%Heodo
2020-09-24DOC_GQPUYDSBWAPT.docdoc 251086a8d6a3f83e2b9ee3ee013730af40923e3ba194b89a3610e20becc05a1dn/aHeodo
2020-09-24PO_09242020EX.docdoc 11e3728d9ed2d0468dd44f01dda3611b75b1b9dd7645e9322036d913c43b138an/aHeodo
2020-09-24REP_449597320.docdoc f57bae29b433bbff72dfe50e3dda325580fedc58d7c032948cf5360ce803b390n/aHeodo
2020-09-24OLO_HDT_090120_VDY_092420.docdoc 0c0a47166f8b2bd4ca8b24c44ebdc1729d7dd6a49d3ba2fb400812d5409b7648Virustotal results 21.31%Heodo
2020-09-24BAL_QU5300011234AS.docdoc f2566951b2f270b88cd2a864576ae53db3bd5f3fcea221a1b088b8ec0d6f6eedVirustotal results 22.58%Heodo
2020-09-24R7AWTPAU6Y6P.docdoc 5b276cd9dc10cbdf1dc7dcb147761fea97b3b9407dfd13b460721747f767238fVirustotal results 22.95%Heodo
2020-09-24MJ_PO_09242020EX.docdoc 6e5bcd9db826f2b855f63e8a591e02ebb0bbd141387d2922e3e251fc8ddbcbb8Virustotal results 19.67%Heodo
2020-09-24DOC_RS0879051797MH.docdoc 860994a6cb882e801a963f6e00a8bca34f28efaa71b690e5f77b8c2e644dafb6Virustotal results 21.31%Heodo
2020-09-24REP_FVW_090120_LQL_092420.docdoc 22d0afad8f9bf09478e526450db6e58a140ff80ce34be8b6cab70ec7b9ad475eVirustotal results 20.97%Heodo
2020-09-24FILE_68987279.docdoc e2dffd7e2a3663a738dac21fd590dec2cce14df9ccf7aebcc5944258a827bc04n/aHeodo