URLhaus Database

You are currently viewing the URLhaus database entry for http://cookingbuffet.com.br/wp-admin/Overview/awzoerestewu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:697748
URL: http://cookingbuffet.com.br/wp-admin/Overview/awzoerestewu/
URL Status:Offline
Host: cookingbuffet.com.br
Date added:2020-10-15 11:34:05 UTC
Last online:2020-10-19 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 11:36:15 UTC to abuse{at}hospedagem[dot]net)
Takedown time:4 days, 2 hours, 34 minutes Bad (down since 2020-10-19 14:10:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17BAL_718767495893493554.docdoc 8d13034de40b71141b07afd251984bb9b827f62b140815127683e779ebb9ab43Virustotal results 51.61%Heodo
2020-10-17LWVD_J0CIJW3JD.docdoc fd0ec2733cb7fc4d8f934cf81b56a9a6fd2dd7290c257cdf4c2a1b3da2bcfc10Virustotal results 51.61%Heodo
2020-10-17Q_019476498028894189864771.docdoc a106e1da9cf3b1b5b2f7211307b55422cf772fb176003bd02070def6d3b1c13eVirustotal results 52.46%Heodo
2020-10-17FILE_058327719.docdoc af4011781c0a2add45a6f72b8d52e5bd7d7381ff28c93e478dede0ff100ff237Virustotal results 50.82%Heodo
2020-10-17AIG2CLZSMWDC566B.docdoc 99acccb026919eac0d3249c8a9207a71d032fbe59c7540c12aee398ae86e6780Virustotal results 50.00%Heodo
2020-10-17KPV_PU0820004600HD.docdoc c40e490d1149a43b982a7c65d5f04d36117a86623374f75bf8d47f31090f8b18Virustotal results 50.00%Heodo
2020-10-16QQ3592197869YI.docdoc 3bae78182dad47ac43920171f44e275863e25a8cbdd07ac0b0279edb751dd12aVirustotal results 50.00%Heodo
2020-10-16QW3603115491YX.docdoc 2d4a3ae690cd64017a114de08ffb095c8208ca65f5647809600f6caf8ff7cd97Virustotal results 50.00%Heodo
2020-10-16DOC_GSA_100120_NUI_101720.docdoc 6647111dcc98f3a01470eee7de5a3b93b579a08c585cd3553cbfbdf3d54db556Virustotal results 48.39%Heodo
2020-10-16FILE_BFL_100120_ZLT_101720.docdoc 546efc6d0a2cf1ff3052b328188d26e9576664e7795de51b7ac16d3e5513208eVirustotal results 51.61%Heodo
2020-10-16DOC_IJD138B6.docdoc 23600bb2ceb80154b049764a263e10cc02148048a332d10edf6458fc4b2cc34cVirustotal results 54.84%Heodo
2020-10-16JQAPOJB5ROJR91.docdoc b22624074fb5efd4b4c7a4882f6a7bf06faa842197e9fc9199e85c8c1fe02b8bVirustotal results 52.46%Heodo
2020-10-16FILE_GC4251501186ZV.docdoc f8b980774cc06cbfa822245a47e48d9bd3280bf6cf2bd96628d02e54c84baf3aVirustotal results 51.61%Heodo
2020-10-16REP_PO_10172020EX.docdoc 9c44a164c70d7fdbd796c9805e3ce506cf8fd1d8df4d84e27384d794e3c075b1Virustotal results 50.82%Heodo
2020-10-16FILE_JH0190109667FS.docdoc df19a925071882d765b1555ee283418bb9aaf49438f8f980e343b4d4be6b3784Virustotal results 50.00%Heodo
2020-10-16DOC_53984427.docdoc ba3ac6b60b4acb6aa9b534e4cdbab1c537fdb07b6fcd10d5e16f076fac5fbf1dVirustotal results 50.00%Heodo
2020-10-1678374095.docdoc 8b5585bc3f128dd3a3ef10f180c3a5cd06e2f68e9894551fe177b09b5b1ee0c6n/aHeodo
2020-10-16FILE_KNP_100120_QCX_101620.docdoc 11c67e93ede508aef0bb3d1c43fd0dcc4109fa2c3c93811c94f36094662b2c23Virustotal results 47.54%Heodo
2020-10-16UZJ_OC4357210613DB.docdoc 983555bf6e5340b9a14130644379b3ed4d7c6ccaf937b3e800ae1c1b1164dc25Virustotal results 47.46%Heodo
2020-10-16FBP_100120_BYY_101620.docdoc 0a0ac374574dd78365ae4b5e84357a2387d99dd14752f6a53391324841412b19n/aHeodo
2020-10-16FILE_KU2074641538RD.docdoc 69723a53775c6a9e152a508cdfa347a0e07201d2efca1c2c0ac1112748a9fcd6Virustotal results 48.39%Heodo
2020-10-16FILE_ZR9304884465LX.docdoc 9d28dd58c8ee62277f91e152a8c7e9964052f5025f10424ec75b9563e6b50cf2Virustotal results 46.77%Heodo
2020-10-16BAL_RWQ_100120_GHB_101620.docdoc 17d53f5f8cf330045f438b412ee075f2dc7a6354b6c9b7551981fb63b4e2ca83Virustotal results 47.54%Heodo
2020-10-16INV_4301421169.docdoc 45f7ed6acb52b3f758297672fcb90f410da0edfe48718c002c3b97016ac99d81Virustotal results 40.32%Heodo
2020-10-16DOC_UOZ_100120_HYF_101620.docdoc ccaca18fab3cf85f49be61cdac5f891f12961393dcfe120af01e6a75b3768b71Virustotal results 45.90%Heodo
2020-10-16REP_VE0809476250YK.docdoc 6312f90ec6b5552f4405eed96edb974c807da0ceb9ee39eebdf680a2fb6c3095Virustotal results 45.16%Heodo
2020-10-16DOC_IX5602028556GS.docdoc 9ef9aea93327bfec6723725da363f724f06ca447c1a54fa84210ec1b01c86415Virustotal results 35.48%Heodo
2020-10-16REP_LENIDAEEO.docdoc 0e12f49796d6d8f40e96ccabd14b42ccbd1c2097b8e8419790c0d793c3226bd1Virustotal results 45.90%Heodo
2020-10-16BAL_VSH_100120_XVP_101620.docdoc 9c709e26cab4a752ef535629ca0789fa9454436ac24b8d5577c2cb420c60b20bVirustotal results 41.94%Heodo
2020-10-16IR_NPZ_100120_EOL_101620.docdoc e1350796dd3663bdf614b62a143749edf7e6a79152f8a705253bba4a593610dcVirustotal results 41.94%Heodo
2020-10-1635797695.docdoc 603619e4d81dda77197d6ff40406a6f101a494901653c22f181ecb7be55111d6n/aHeodo
2020-10-16REP_ZI6150385382CO.docdoc 7925fefb0bb1f5625a8189d9ee045b2f5f7ed06a22fc3a75a5c4cafe11f466e0n/aHeodo
2020-10-16G_64832323.docdoc 31d6b7258df89266703cadb66afc3728ffbd629f68ca60c950bd3b27d4cae086Virustotal results 37.70%Heodo
2020-10-16REP_38605155.docdoc b3ff4cb5f91a87ecd1fac32d460a2af1d07bc9dc1d2eba676a2602e6016efcb7Virustotal results 36.67%Heodo
2020-10-16FILE_NL5097961578NL.docdoc 6a643872b2481769c2b5927a429f7f678557018b9e08015b2be084d104bbad4eVirustotal results 32.79%Heodo
2020-10-16FILE_ZIG_100120_VGT_101620.docdoc 928ec3474e204aa23a9fe0971c55669cb5ad9a752f46fdb16c46c974035fdd9fVirustotal results 36.07%Heodo
2020-10-16DOC_OE4709886586ZL.docdoc 33c9159cb870c324fdc315846558083363dc9560f0156ba73478128c25a3b38cVirustotal results 32.76%Heodo
2020-10-16NTQ_100120_EPL_101620.docdoc e740fc6270797a0066f81948906ef8e53161c3fce038be592daa80d3f8c92516Virustotal results 30.65%Heodo
2020-10-16PO_10162020EX.docdoc fc806b39237bec90a8815cf600d9f371357926be080869be6a1cfce9c6a2e9caVirustotal results 32.26%Heodo
2020-10-16RZBL_XJ3699538539UW.docdoc aa3af1b21af839268143b000b0e8f4a431079b94f69c8025f31315e8ceac2b47Virustotal results 31.15%Heodo
2020-10-16FILE_MYJ_100120_CUJ_101620.docdoc 9e16a1c487318559bca602d0c341d760109650549d600ab32ea6c5b07b9c838dVirustotal results 30.51%Heodo
2020-10-16N_PO_10162020EX.docdoc a74b230d5a83dd721b98493e0a752cd0f9d6739bc4ff6f0046b798fa98513fbaVirustotal results 32.26%Heodo
2020-10-16XS2770649518XU.docdoc 3550b173f084aabdd854dc658b31eeac18f28c421c23052d45d5e8a92f8a3e93Virustotal results 32.26%Heodo
2020-10-16E_PO_10162020EX.docdoc 874551f55294cc8838b596c8ffd8d4600ade4c1e932ea618012210a3ac7137c2Virustotal results 48.39%Heodo
2020-10-16J_ZYA_100120_VCU_101620.docdoc 98852e4e9b18aaefa6bf7599dca0b76b3e9990ec9b0cbf54ce1dd3a03015cc9aVirustotal results 46.77%Heodo
2020-10-16LQK_100120_LHR_101620.docdoc 29d8f14d9aad7f7303bfffcff57109e4a24983050638c356af826bf4febc04a2Virustotal results 52.46%Heodo
2020-10-16INV_PO_10162020EX.docdoc 2fc8f20d9cf100c7de1244d5ccb17f14230e534ff24921e0cb537ebce7668908Virustotal results 48.33%Heodo
2020-10-16S_M2YSETGWUPS.docdoc 28a6bdd824538dcbdc61dc5ffe9d61ccf016e4a4bb027becec2d522503ec8b0aVirustotal results 46.77%Heodo
2020-10-16PM0637911159KV.docdoc 63409e6742b521d02cfb6f833ee7484c6db70237e48675a06c28cc7c9920bfe5Virustotal results 50.00%Heodo
2020-10-16DOC_74983956.docdoc 35063a36e2a9b2ea2f0a17e4f4c22a81de62a240888fbb22195984501125bc34Virustotal results 48.39%Heodo
2020-10-153472111132732239.docdoc 2889aa2818bb6b697ece0258b29a039f5f46f85444792ecad4d3667806bb5610Virustotal results 50.00%Heodo
2020-10-1516876612.docdoc ab321ed0f56034ac636d328802440c291af5a379fee4ff6b31fbc859ab2d9004Virustotal results 52.46%Heodo
2020-10-15REP_HW6407955577TC.docdoc c584c1bd086b6f8007e1a594498dd51149f97a492dd8113493a6dd21f9134ad6Virustotal results 51.61%Heodo
2020-10-15VJZ_21668874.docdoc 2955467d39aee8efaa08f284298b86e105ff6b8855c674bb41e38ca21d2c6bfen/aHeodo
2020-10-15ZYL_XW0233833354VV.docdoc 598b4cf3fc5b97854ae8b54625407b4e6b7f05d8ad96b446baaf0855b754074cVirustotal results 46.77%Heodo
2020-10-15REP_39191664435268320643079.docdoc 9e6ccb86ca25351f22a9960687787487cd93476f21e943368886f63c03167222Virustotal results 47.54%Heodo
2020-10-15DOC_DP1449442627NL.docdoc 966af50d9ffd82cdc2a4fa693620dfe90172ef15047cc10d3b35fcd47ae47c4fVirustotal results 46.77%Heodo
2020-10-15FILE_HP5636534836UQ.docdoc 5611d69fb48d899f85406429e354830c4c4f33259af76c16a74afbefa925fd1bVirustotal results 47.54%Heodo
2020-10-15DOC_63990367965.docdoc a0af2c0d46bfa10fc4589560d7055a18babee6615726fb2893b817e111f9ecbfVirustotal results 46.77%Heodo
2020-10-15REP_PO_10152020EX.docdoc 1d9754d306c2afe8fd501b6a7449ce2b31988935a52af20866fe321c5a5b0645Virustotal results 47.54%Heodo
2020-10-15REP_UVY_100120_XYS_101520.docdoc 200fd063fbce58987452058b68b6f0d32d9fd51afddd74f6ed466124627fc51bVirustotal results 46.77%Heodo
2020-10-15DOC_PO_10152020EX.docdoc 928793e8f0d35a4a78f1935358fffc9f25ccf0b8f0d4cf8ad4a9e7a1508f22b2Virustotal results 45.16%Heodo
2020-10-15R_4187928794676481.docdoc c092eeeaefd8e9d4c328cc78e77530cb40fc820d921ce06c271c47781aae2da4Virustotal results 47.54%Heodo
2020-10-15XO_58911471.docdoc 590e91cfd2bc7164b8528b3e845e9d45e8328e9148b90c0836936e9d870ca895Virustotal results 43.55%Heodo
2020-10-15INV_GB2502527668YD.docdoc b4a13d579c367f64c35555628c0386cca34afc9ac0de28d4949ca37328f6b8b4Virustotal results 43.55%Heodo
2020-10-15BAL_11258597.docdoc 9e399c9bbd8e0a5be20ce299ce14f5e1f7ae22f19f564231c3650f1a6c055c3bVirustotal results 42.62%Heodo
2020-10-15EZG_909IN3FR8NV.docdoc fa437d31c734102e84da67e8db9d8af76a88f24bc9fd85ac6e53f60ac3d98726Virustotal results 41.94%Heodo
2020-10-15REP_83178543551921226.docdoc 3f6955a4c8030234f81c5371a9fe055356a777586aec5021a269eb74083d6ce6Virustotal results 40.98%Heodo
2020-10-15FILE_TN1318534673CF.docdoc 680221d36ed6fb5e4e98995e827e0b4e4e54b17783b70834fe88879a5b54b400Virustotal results 41.94%Heodo
2020-10-15BAL_05142089.docdoc d30ec2dde96e92164e6be1b42ad79b2b25464da4be6140e0965cb115a5d9e8ddVirustotal results 32.26%Heodo