URLhaus Database

You are currently viewing the URLhaus database entry for http://andrademendonca.com.br/wp-content/2YL86MTKGTJKHU/Oib5nGCJOw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:611411
URL: http://andrademendonca.com.br/wp-content/2YL86MTKGTJKHU/Oib5nGCJOw/
URL Status:Offline
Host: andrademendonca.com.br
Date added:2020-09-25 07:08:14 UTC
Last online:2020-09-28 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-25 07:10:10 UTC to abuse{at}ovh[dot]net)
Takedown time:3 days, 16 hours, 7 minutes Bad (down since 2020-09-28 23:17:29 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-2681554_2020_09_26_4695.docdoc 4893d5828613a7b157505151182a80ad894439fe4f65ebeb87fcf641880ca47aVirustotal results 51.92%Heodo
2020-09-26UNTITLED-X5365.docdoc d4d110faa9f3e93616925231c70710a1ec091493282efac6c1d4958e84065ac3n/aHeodo
2020-09-26DAT.docdoc ae25313bc038282f959a652bf45059a6e8673d1f01fcba998615a3d037de3475n/aHeodo
2020-09-26doc_4455504.docdoc 1aee15ed7cc7f4e811496a82f1cc51038a3361763ea0e8351c39764d7bbd31een/aHeodo
2020-09-26LIST 2020_09_26 932797.docdoc 28a4375c5b9b8810beab924e04ca34cba98e1beb9994113664043fa471fc19e4n/aHeodo
2020-09-26doc-32482.docdoc 7b4679977e2c23652c6f34f665ffe1878c6c9c10391c92a1261552c1be4f34ecn/aHeodo
2020-09-26Attachments-K579634.docdoc 75048add99a2875852bc75ae5ca35b799949322fef0dec0c73c42d9063ac0d04Virustotal results 53.33%Heodo
2020-09-26dat-4531104.docdoc 596d87f7e54bf140984c650fabcdb9f4361940c565d4bf594bb9f941f44d1c2bn/aHeodo
2020-09-26UNTITLED-2020_09_26-939.docdoc 05d7164a911316ca65eef36fb07402a3eab4e12a6725715aa2ca44439e9b4947n/aHeodo
2020-09-26inf XF864.docdoc e7761eddd9efbfc68a336da4974a0117ef1ad8db9bcdc9557113613a80a5b5e5n/aHeodo
2020-09-261123996 HR21366.docdoc af2847d2c2882683be8ca6e3427299937eed1bb01ef9e144b028083a5ef81fd8n/aHeodo
2020-09-26List 2020_09_26 FR9828.docdoc 561e3f77560f930e3d90738e1ac4c6153a56c040383f4b27b1109db78ebd7075n/aHeodo
2020-09-26LIST_2020_09_26_H04808.docdoc 85b05659e9157af806f3d1861f5a87cb6e3955b3fa30e8c9a9148f8c78426848n/aHeodo
2020-09-26MES-20200926-UI45036.docdoc d4d2fc2a83554e65e3bff58981378a49df573fef9348ee538ba725c4829aae18n/aHeodo
2020-09-26UNTITLED 470018.docdoc 033ce1f42508eadad9833a6e8759f2730949208eeeb1fba3b15fbb7e7803ad15n/aHeodo
2020-09-26Dat-C2853.docdoc 9e9d0d2075fc44e62f8bffd65480741ac00e708030fbdbd2486d66a7fa37dd9dn/aHeodo
2020-09-26ARC 20200926 799.docdoc b9b65e283047ea4a5b064c5bcf6ff09e9ea9590546748996cbdb244e008c2f8aVirustotal results 48.39%Heodo
2020-09-26Attachments 20200926.docdoc 45cd60548e81a7edaecad70b1791561a4e31482de55707796ab69800a2aebc38n/aHeodo
2020-09-26Arc 20200926 797.docdoc 4d102f8a088cc31f209a50fb5697c8eec3e08d205cf33e42971b797d30dc4a24n/aHeodo
2020-09-26Attachment_20200926.docdoc e104a530f7eac1471eb26fac40b6710767d01c8f72b89456e46bc78fea3bf68en/aHeodo
2020-09-2680008_20200926_470.docdoc ef90a3e6df3c91e01ecf85aa1cf62138348f6a558d373a4c45a2ac8ad8a9ea01n/aHeodo
2020-09-26MES 2020_09_26 84872.docdoc faf7ed24aa5991a653301120b138611b6ab03b4b6241d93739d871c81cda1540n/aHeodo
2020-09-26Attachments 2020_09_26 2602029.docdoc ce57d0d9f8f579c1faf2c83bec7412d79a6d6fc20af37f4e49ca562cb1f4f1d4n/aHeodo
2020-09-26Rep 20200926 R1330.docdoc 614c937446ff663272b12024b799c803935aafdf6c51f49ddc2b345084f6c458n/aHeodo
2020-09-26Doc-2020_09_26-O71972.docdoc 6293636c1068224e5ba13bfa9137fe56539210dbb2f595a8d64b9d0a8a773d6fVirustotal results 45.16%Heodo
2020-09-26Dat_20200926_8001.docdoc 93814c97eed9fe1dca366820408b28822e03b6fb5f384e9e8c9f91f0873f929dn/aHeodo
2020-09-26DAT-2020_09_26-86645.docdoc f338bc969edcdccf6e8b69b9be2878e3ef0c754e606a3db48d2008c89fea553an/aHeodo
2020-09-26KQQ976_MYI624643.docdoc edebd19379bba13e971a663656c8cd524451c811f23db66086c06b2006c3f374n/aHeodo
2020-09-26dat-20200926-S7202.docdoc 39fd66bdc8cc523c521e1a1da7d113a95cc3f42298595a07640de3e012cab783n/aHeodo
2020-09-26ARC_56815.docdoc 203d0733f9ad955c692064f78e8127bf5e6f5cec247198e7b39cf8d40a45dcb3n/aHeodo
2020-09-26Attachments_20200926_Z94037.docdoc 138b00070d28b50974f31f9c2fd12d29ee7b9605d9b38646697ad5cbdd7554a3n/aHeodo
2020-09-26arc-HS85569.docdoc 9852afc0a8c0798b4c4ca5210106ab0b56830cd5972babb4f535ed176b205c45Virustotal results 41.94%Heodo
2020-09-26DAT_X6346.docdoc afaa9219defac1d5d8fe6bdadec5e75b804186664ec40edcd7c6a8e23dd40f2cVirustotal results 41.94%Heodo
2020-09-26Mes-20200926-74668.docdoc 6160cb0ee48c0bbb5d5f29ace0127eff11055c643b8a3f84c9f17cc296f2c28fn/aHeodo
2020-09-26ARC_20200926_257500.docdoc ba03dd83921cfb2bcf5f655a6651e0777828b825417be2ed69fe9dc8f707a27dVirustotal results 40.32%Heodo
2020-09-25dat-2020_09_26-NNH802320.docdoc 89330bfd1e55e367418cde1f916544fbcc67b1e91f018b1ae886e0126bc56aa9n/aHeodo
2020-09-25DAT-20200926-G225983.docdoc f7cffbe586a143c6f536e5b1b6e586504b46f8f74e5b8c1bed7eb63ea6f83c56Virustotal results 40.98%Heodo
2020-09-25INF-20200926-AP23769.docdoc b2ee4ecb1670894afa8edb69d932d7861cc2eae3fbd8914559e236d18ad50a78Virustotal results 38.71%Heodo
2020-09-25Untitled_20200926_1809.docdoc 87e3b261d300d8e8748b73fe7c0da2e243802db6a335b3d5c3ac4603fee7bf70Virustotal results 38.98%Heodo
2020-09-25List 20200926 41966.docdoc ba683cc10b1ba9c13b5db6984ccf32d7986a03cec689d83754b058a226eb983en/aHeodo
2020-09-25Untitled-20200926-F23491.docdoc 33add54d60a5ff8d181fcea0f74d669a1f176226cf04e7703e54ed51383e8a4bn/aHeodo
2020-09-25DAT_20200926_TZ642.docdoc 2479881bf38a51219ca0f5342d009d05a959c91f66e4a3028dde3bd137296b04n/aHeodo
2020-09-25Attachment-20200926-266.docdoc e85dd950d7ef4fd9bdc533f41d90961eaf78b6a9500e88a156bd55de7cd338d8n/aHeodo
2020-09-25Attachments_2020_09_26_TDD760093.docdoc 037bf55f3b894392e1e28aaee8695d24e42e12c2fd741af2e74904c135e98587n/aHeodo
2020-09-25Inf-2020_09_26.docdoc 5acdd7def61463f4658cdaf92e50b51fb65140b83bc9261e2972f49e1565fcbcVirustotal results 29.03%Heodo
2020-09-25Inf 2020_09_25 NO1833.docdoc 54c7aca6fb60c9b4c3a63fe269c9be1722b4ad76bdd837e9c41cfe50d2c75c03Virustotal results 29.51%Heodo
2020-09-25REP_20200925_710.docdoc 0af0ce557b9cc0351e7c7358018dfe9d18cd9554481debdab64ba090f88f67d9Virustotal results 29.03%Heodo
2020-09-25arc_U23907.docdoc aed534163591cca69a6aa137638c0b9a7a07aeb7792f3c85cabe9ff012f2202cVirustotal results 30.51%Heodo
2020-09-25File_20200925_3683920.docdoc 34172fac16f26b4cfbc1a01621467e5d3eabd46919978c3afb3209950d172105Virustotal results 29.03%Heodo
2020-09-25Untitled 20200925 SM77547.docdoc 16a51da0daa97e291824237b776471416538f83ba60aff0485de1c3340a368c2Virustotal results 29.03%Heodo
2020-09-25Untitled-6279.docdoc 11d5ae5dbe98037bdaf8ee5753f38a0d58255e27f35d18a618e4d20854c617c0Virustotal results 27.42%Heodo
2020-09-253647996-V964.docdoc e7a8b6afd22770bc66130ea17743d82f2ca42ff41912aea7c611fdf0098a3463n/aHeodo
2020-09-25doc_JHI39564.docdoc 4cef0ca9a01702013c2eb2cd95b045e367911963ab0556c82bb908034f147a61n/aHeodo
2020-09-25Mes.docdoc de3f3d3187c3d5a9eeb99de8ec6e690da7bb3e7c02e7ee853260a019b889f05fVirustotal results 27.42%Heodo
2020-09-25Attachment.docdoc f62796452be9729b1e8cc40b7981ada95588c1fc692d9b4cfd923d41aa2738efn/aHeodo
2020-09-25Mes_P795493.docdoc 5be096c9afbb309328e357ac0198ed3279c97409eaea75444c58841fb601efd0n/aHeodo
2020-09-25INF-2020_09_25-QX588202.docdoc 0f32f4590ff3bed0c890c4c8db46d75c5742f03eba5e5f897442f4c1816b1e58n/aHeodo
2020-09-25file 20200925 H4807.docdoc cf3a5700fd3e86271380e00e3ab1cece7eec098d6f54eb9e28d23f74d1dedec4n/aHeodo
2020-09-25Arc_2020_09_25_080.docdoc 52d69c4cf08cebd0405ff88467010d12997950eed8398d8ca3328cbaf5160bb7n/aHeodo
2020-09-25QZ6746 2020_09_25 RR663720.docdoc 3487f6d0d55b7b959173694e8b42778f7d5a7f428ea973ff5bd2b4fc0f7c7c2dn/aHeodo
2020-09-25INF 2020_09_25 7799151.docdoc b5c9a44a1c1e7cd771088b3fe0e2a732139e6efadfcf02efd068074c29a23fd2n/aHeodo
2020-09-25file 20200925 SW42383.docdoc e41c293ab7bdf65642ccca64a0aae04d6c3c1d79b33cc8840d2f135bec4c322bn/aHeodo
2020-09-2584326_20200925_I747932.docdoc c7afc3cfeee36591b535ec144f3f655ee52293d6e1eac3244bc2709b807a991an/aHeodo
2020-09-25List_2020_09_25_B243.docdoc 24e78676926b29d8a9496c0645e100f485bfa4211b9c610c96ee4e04a79fcdc0n/aHeodo
2020-09-25List_20200925_TTL603.docdoc ab4f0dfec4f0321dd92dce1b3c21bbfbedefd1cb39ba661e7fc91ea364405e6bVirustotal results 37.10%Heodo
2020-09-25Mes 72404.docdoc 77d6b1d1b611183e4bc185610dedce6537b0a280e331f1e2758dad5ef2cc4125n/aHeodo
2020-09-25List 2020_09_25 EJS139931.docdoc 6e26cb19bb0f62adefe68ae3b394cc2b6f1ea847d3ee5c55f32694a562984f3dn/aHeodo
2020-09-25Mes.docdoc ba0cbeec35d9c1edad96817f4e7729512f2e7bf151107eed9b6ac7d8cdc4bc3fn/aHeodo
2020-09-25Untitled_2020_09_25.docdoc 8184716f0f234f3296e458730d9d455caeecfdc39fd53ecb85372e504927d125n/aHeodo
2020-09-25List_2020_09_25_7661772.docdoc 62466a8d4f2f6a06c5614c30388f94c5d1a66f11fd1d62fd99f1d8dbf374b006n/aHeodo
2020-09-25dat 3200614.docdoc f4cc9f780fa49d42f2ddcbb2e78293e5011432b4c4828221774f336c3abf787bVirustotal results 37.70%Heodo
2020-09-25FILE_2020_09_25_997055.docdoc e55b497502188dc8b8da281b3a2e03550c1ff2299b5d45e61f51502706652bcbn/aHeodo
2020-09-25UNTITLED_2020_09_25_744.docdoc bf6720e73cf3991f50455b524bdb7bdb5f8e6bfae9d1174fede5e8b3e98597b9n/aHeodo
2020-09-2521913103_2020_09_25_BK338498.docdoc f8d5a1b46171cde4b65081fe6bcfd6743315f78b691ca2624381b28e068d44fdVirustotal results 35.48%Heodo
2020-09-25UNTITLED-2020_09_25.docdoc 2890d3ddbc287a674ab46cd243233f0fa7549d3cfe93134fad193e18c3d5a53cn/aHeodo
2020-09-25DAT.docdoc db37f09a3e61aea7c44c7f41e1ddc440080ebef590062a99f2033a263c20dd93n/aHeodo
2020-09-25rep_20200925_SS014700.docdoc 423f63eebfd073a0861727cc705ee239ecf673ba8ca42c3fd4fdc61e18e423f0Virustotal results 35.48%Heodo
2020-09-25Doc 2020_09_25 2248.docdoc 9263c083ab944b928f26ff755452523911a15b846408b1350d3d42587c56daa5n/aHeodo
2020-09-25Arc-2020_09_25-656859.docdoc f125ea1d91450e442e4bcbe2359484a15701dba8e5ec5257cca121b4873ca9f4n/aHeodo
2020-09-25rep.docdoc 00aa2833332261ee444a5437a5ab56474bb743924d2d1be87777f4fa2a1688c5Virustotal results 29.51%Heodo
2020-09-2547258188_2020_09_25_562.docdoc 287129015a4ad65dd6d62d78df6c13cea9eb499926a73e039360a97f4815e1fcn/aHeodo
2020-09-25REP.docdoc 1157d25d77ad7dd6a0c899536bc79a3110cf1ac31f5d565dd6873ccd8b656decn/aHeodo
2020-09-25file 20200925 ZGX5448.docdoc 685256ea285a03753b190f28a32007f358856ab0685da8ec4bb92e259fa10165Virustotal results 25.81%Heodo
2020-09-25rep 20200925 PEY178183.docdoc a21cffa6aee262c7cede6e64c0727d655e4ebf9ecdb510368317786c1560c2c3n/aHeodo
2020-09-250601222 2020_09_25 ASI7801.docdoc d763e3f76bf25b9e26cbc9cf13b9df3c8af129ee5287e96868659ab6508ffa89Virustotal results 27.42%Heodo
2020-09-2504632 148.docdoc 059202ce7b96a89a3d55a0f47f496ac65e242c3fad84762019f5ddd4c00f6a29n/aHeodo
2020-09-25Doc 20200925 3449.docdoc 19665d81b443fbbea43c2269393dd1497a8ca560342eb9bcbb5bf6133033c0dfn/aHeodo
2020-09-251858F 20200925.docdoc 2eb0e126883c1dc1eeede8fdaef687a066e55219976ade6e4bc2f567b6e615b4n/aHeodo
2020-09-25Attachment-20200925-046313.docdoc cf58e5bbf98015c40d7a94d69fe21c835345c50fe12e09c28e25b3a1d3b23a98n/aHeodo
2020-09-25Inf AZL077.docdoc 64a2df4abb20c12df5dfa46750e83ce6acc37fa4b2fcd0a227ada250905fe7dfn/aHeodo
2020-09-25dat-2020_09_25-2915.docdoc 7af65b3e6ff098ff2470d97bd7516a4be13b0853251bd92c07bea314fcc3a209Virustotal results 26.23%Heodo
2020-09-25Rep 20200925 RXA921478.docdoc 55ac5280a7142fc79c894cdc890d3a3b76a4eaed03f0b938b355e07b95316e17n/aHeodo
2020-09-25Attachments 647.docdoc 9d71d83ccad45ec81540fa2fdd1ebb126016b0a66de537c53d72f71ba21085e6Virustotal results 27.42%Heodo
2020-09-25list-20200925-87099.docdoc 35b20290035a4adc02a158303d41cc5f9f0b3c5342ca320c17d838edea2b7736n/aHeodo