URLhaus Database

You are currently viewing the URLhaus database entry for http://med.les.inf.puc-rio.br/wp-admin/swift/lblxzsaus0pm/bq1z9iivs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:697881
URL: http://med.les.inf.puc-rio.br/wp-admin/swift/lblxzsaus0pm/bq1z9iivs/
URL Status:Offline
Host: med.les.inf.puc-rio.br
Date added:2020-10-15 13:14:10 UTC
Last online:2020-10-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 13:16:11 UTC to abuse{at}lacnic[dot]net)
Takedown time:4 days, 4 hours, 56 minutes Bad (down since 2020-10-19 18:12:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17S86VAR8SW6L4K1L.docdoc 5bc6a9797e0e1b206a0d2d341e88b730f01312279122e98e1dc2873f48b2102aVirustotal results 53.23%Heodo
2020-10-17INV_24499966.docdoc e9fc0607223bdfcf6365b914d806c89315bbdfff9681454d6b67b060ef04024cVirustotal results 53.23%Heodo
2020-10-17VHO_100120_YYG_101720.docdoc 9fddabb44e0d01bdc8e0886790e1e34059ac1aedbe3faf4cdfa66bf9dec923cbVirustotal results 53.33%Heodo
2020-10-17INV_53508379.docdoc ff9996026d66c80170010bab3d84d0ba1ecac3a6b87f8e694008feb0bc0b3d4fVirustotal results 53.23%Heodo
2020-10-17KBV_100120_MGU_101720.docdoc ea065a0dbc3ca645237d0c98e82887ca636451f3fa822c6c0a087a2fe98c230fVirustotal results 53.23%Heodo
2020-10-17FILE_03256443.docdoc c0f957552ea0bfa9ec43b903ee17f870d19d10026a6e967b5ba434e26758232fVirustotal results 53.23%Heodo
2020-10-171473032560195949.docdoc 7f7aaae8116f26c7d91c5c3d87ab7c7a752e628195c25563cc7c3074669e6c7aVirustotal results 54.84%Heodo
2020-10-17BS7277627487ZR.docdoc 127e5f88e44a1886181820087f5a2d1bb09ecec7ca49c027c33c9cdead79c1acn/aHeodo
2020-10-17INV_ENDBB6ETXEQGDG.docdoc ab8be8e21a7c5f0a158818bdf5fa9883acaffa78d8cfa5cae36ba7d756b8fed6Virustotal results 50.82%Heodo
2020-10-1730659959.docdoc 07d50b9ddd52a094d9ade84a00025402b6b55151fb79b6c1709b4019708e9660Virustotal results 51.61%Heodo
2020-10-17BAL_M6VFEH2.docdoc 58a95bd14fdfe2c4e30b7bce237de2fa3351c1bcf0328c91c9333a29a8be15d0Virustotal results 51.61%Heodo
2020-10-17DOC_PO_10172020EX.docdoc 905c7ae4c62237c4d5783b52652b9eef6be72076862c6f6aaa440f8e7ce23a8cVirustotal results 50.00%Heodo
2020-10-17DOC_Z4W9B5WWHNK6AZ.docdoc 3cf860a4fc48852cfc15307168a655fe09d970de805123a370c888f18b949aaaVirustotal results 51.61%Heodo
2020-10-1789158305.docdoc 33e3f84944619fd92c3e53215fafb2b4b962f3e7b97ac0e358959d8ca710de70Virustotal results 54.84%Heodo
2020-10-17QFJ_100120_LGF_101720.docdoc 02730b23749bb5e945d78771425520fe94a15b5647f34a7efeca54a72c9297c9Virustotal results 52.46%Heodo
2020-10-17REP_XNZ_100120_WEB_101720.docdoc 19b133b4ad7b5c3072ca746a89f06864d39ca4c8985ddfb2eeadd125ff5cd7a7Virustotal results 50.00%Heodo
2020-10-17FILE_PO_10172020EX.docdoc cad389f338446345616f9a4f005b47f186be55fdd914d1b88f42bc4f26220685n/aHeodo
2020-10-17DOC_9523647830749184649.docdoc a106e1da9cf3b1b5b2f7211307b55422cf772fb176003bd02070def6d3b1c13eVirustotal results 52.46%Heodo
2020-10-17REP_VSI_100120_MDW_101720.docdoc 5990f98a0aeffb24181deb144a8519e54f7695794e545b9ba0cb52fe28e3f987n/aHeodo
2020-10-17HH_P57M93VIMIDBY.docdoc 99acccb026919eac0d3249c8a9207a71d032fbe59c7540c12aee398ae86e6780Virustotal results 50.00%Heodo
2020-10-17342721337480575886.docdoc c40e490d1149a43b982a7c65d5f04d36117a86623374f75bf8d47f31090f8b18n/aHeodo
2020-10-16PO_10172020EX.docdoc c25321d27755dd74dfcb51c16c96a607d16b09b59b1cbe7f025dc89763d9d630Virustotal results 50.00%Heodo
2020-10-16L_AS2377886982BC.docdoc 70c3e11a1960c379e6be0215b70999623bb37cad12e932cf4d222f70f078c6d2Virustotal results 50.00%Heodo
2020-10-1631VNT84M60X25MRU.docdoc bf79372e0c3a2b7a3b0df0f3994621206443404f5c382b8ad5e5c609c6b0e043Virustotal results 50.00%Heodo
2020-10-16L_UZ0512538292ZL.docdoc 39dced6aa4d3785efffcddc9b87bb1744c386d811cf509ac1baef383eb0c38ceVirustotal results 52.46%Heodo
2020-10-16REP_PHU_100120_XTN_101720.docdoc 69bf38e708fcc10caf5824bb4460ed7f950dfb3085f715c81303b992c3bb6857Virustotal results 51.61%Heodo
2020-10-16W3305D1Y77WFB.docdoc 59330f6abd11ccf8373697955746b598be71ca8c69774640b41ebd9650abb398Virustotal results 45.61%Heodo
2020-10-16NK9421241473CZ.docdoc 8215f350c6c5d2b5f615bcf7260cb9eeb60747b75a9e6a8e4b9c3ef3b70b8cfeVirustotal results 50.00%Heodo
2020-10-16F_EA4363494532YP.docdoc 80605d4761a1447fe034eb12aa555f3c47129991eb479b0d4da31493633ee464Virustotal results 49.18%Heodo
2020-10-16FILE_EHP_100120_EUS_101620.docdoc 65e2d908e6ada4277630aa4113bdde311bd7e49c0e6e656f3102bbb4f61924e3Virustotal results 47.54%Heodo
2020-10-16E_LBPWIOVDZ0S.docdoc a556f655a5fe240f6e969c6e0c449f47d357b453c5940205ce2d867f7ca64e4eVirustotal results 50.82%Heodo
2020-10-16REP_PO_10162020EX.docdoc f05cfe8aae97657d11e98c72cd612a7d57f949a47efcf75125edfd9e7a7caa4eVirustotal results 44.26%Heodo
2020-10-16PO_10162020EX.docdoc 12dd700209b14c8070f18c7d204bf4cd9232b3a98ddee71e9618c28ca67f6520Virustotal results 49.18%Heodo
2020-10-16ZRMJ_ZKE_100120_CJD_101620.docdoc 70a35d75979116a3deb5a05fd800b019ce1a1e3cfa73a22c3e547f5fdfc702d6Virustotal results 46.77%Heodo
2020-10-16FILE_DR0675274094ZK.docdoc fe64e60c58eedce9a19e9f18a2c5d220d3d38b0aeb719cfbf027218a13121621Virustotal results 47.54%Heodo
2020-10-16J_88927353.docdoc 69d1dfe8740210f2f3a0ac300794d5f0e25e14f5b86e20086036c2c501fb92b1Virustotal results 45.16%Heodo
2020-10-16REP_LKM_100120_FHQ_101620.docdoc 89157919f283aad6306a78ae43e54b55c2431a0a64dbfcef22df553bf09ae681Virustotal results 49.18%Heodo
2020-10-16X_247577316.docdoc ee640ad9d020dedce3c3a18efe2a6a9a14ed4cf50ffa64ba27090765dfb3cc6bVirustotal results 47.54%Heodo
2020-10-16FZN_100120_BTR_101620.docdoc 4bead4acd3e94b0d94cb2d3be3f50f5d9b5dd425a0d5d5caf6af43b13539d717Virustotal results 47.54%Heodo
2020-10-16REP_PO_10162020EX.docdoc 9ef9aea93327bfec6723725da363f724f06ca447c1a54fa84210ec1b01c86415Virustotal results 35.48%Heodo
2020-10-16REP_255300818795780680617.docdoc 0e12f49796d6d8f40e96ccabd14b42ccbd1c2097b8e8419790c0d793c3226bd1Virustotal results 45.90%Heodo
2020-10-16NZP_100120_ZZW_101620.docdoc eb5e0b1951caa747b0a1ebbfbd710a70bd21f0fc5d04d52dd7a480ba2e8c63b8Virustotal results 41.67%Heodo
2020-10-16H_YDL_100120_DYB_101620.docdoc e8cf2d2aeeef9972177572c05c58a7659515a991f2601167d7512ea389672c6eVirustotal results 40.98%Heodo
2020-10-16UV4332311718ZP.docdoc c776db8d620c054dfc36df81dcd693dd59598cce84323f83c4677fec5fc8eb4eVirustotal results 37.50%Heodo
2020-10-16O_PO_10162020EX.docdoc 50582c9e06f7726c40ab166de684e95a6f0de3f3fe6a0d8a749e6b18a5047f23Virustotal results 42.62%Heodo
2020-10-16INV_04061592331.docdoc 83b56f5aea5eab97c715b459c260206dfac6ff8e4e5d1418e3c380091453a5fbVirustotal results 40.32%Heodo
2020-10-16FILE_J6IVWBESGZCX8.docdoc 31d6b7258df89266703cadb66afc3728ffbd629f68ca60c950bd3b27d4cae086Virustotal results 37.10%Heodo
2020-10-16S_SLRJRXR5144IJO.docdoc b3ff4cb5f91a87ecd1fac32d460a2af1d07bc9dc1d2eba676a2602e6016efcb7Virustotal results 36.67%Heodo
2020-10-16INV_QLQ_100120_TRJ_101620.docdoc 85cafbd8a7231965377fdf168bcf3ebbf41b13c90266dd1bc18d4b20ca6b5f61Virustotal results 37.70%Heodo
2020-10-16DOC_PO_10162020EX.docdoc 01f98b1a31eaf93128b65347f3fc0e25b853d2535e9d828263002b80f0e445a0Virustotal results 33.87%Heodo
2020-10-16DOC_DWN_100120_ZUI_101620.docdoc 3b29c8e3eb58dc756778fe366c1768a95e278d08ac62156cef908400044ddbc9Virustotal results 30.65%Heodo
2020-10-16Q_494342780504.docdoc c9146e559eeaafb38494a657eb583b6833b2c35dd60eafe2140ee8bc22150c96Virustotal results 31.03%Heodo
2020-10-16FILE_GRK_100120_GLU_101620.docdoc e1657e2b9da4fc39004ca0c0c681b59985f94ca16d04c3f363122de4bb444099n/aHeodo
2020-10-16Z_PD4000768237NE.docdoc 90d4594020996e8f0785d89697380b924303884de63da77463a13177b21c1858n/aHeodo
2020-10-16INV_RFN_100120_SUG_101620.docdoc d2d38dfe02364f8d066d15519f9fa5d94eb64c1d7e022093f936c50450f2c5e5Virustotal results 32.26%Heodo
2020-10-16R60OS5BWU1WQSNAL.docdoc 3550b173f084aabdd854dc658b31eeac18f28c421c23052d45d5e8a92f8a3e93Virustotal results 32.26%Heodo
2020-10-16MBS6691ZVLK.docdoc 794cd8d6c12b283f0a19f40472aa0817f0b038ddce585fd66b0985d440e59616Virustotal results 50.00%Heodo
2020-10-16DOC_4839012943861952883.docdoc 92d36d8404107035e4524734547170d1517c9ffff23480556c718f4c7c89d3d1Virustotal results 50.00%Heodo
2020-10-16BAL_N8GGHXZU8LKU14Q.docdoc 72b44b8e255ace9d74a54f19671fdcfa1b296bb221e038ab578044b55b309afcn/aHeodo
2020-10-163Z3UH0AN.docdoc f677579d45117ccb457830413b6ee450bfe97425e2b31f2b582368410b0b78e9Virustotal results 50.00%Heodo
2020-10-1658701227.docdoc 2d9023a6f86851ac7ecb86a93a0c083b17f481474a2b8182c64a69cbda7fb2e2Virustotal results 50.00%Heodo
2020-10-16BAL_SG1172341489UN.docdoc 7e1333c6529018473221519532ee51d04523ad9354f66d62ea599d4bcb9b4a8aVirustotal results 49.21%Heodo
2020-10-16L_GOE91AX35PHGOV.docdoc 6bd70c37738737b137dddf5e137cff39eb5baeca80217787c95d5ce885c5854aVirustotal results 47.54%Heodo
2020-10-16PO_10162020EX.docdoc 598b4cf3fc5b97854ae8b54625407b4e6b7f05d8ad96b446baaf0855b754074cVirustotal results 46.77%Heodo
2020-10-16PSM_100120_CLF_101620.docdoc 2ea42eea9abe81ee4415154eabd2fc00bb951b3a234e1b3ef9e824d77ee97732Virustotal results 51.61%Heodo
2020-10-16T_2015737011347959184294.docdoc b9bb517022d0b2c98532d6239bd55d7a33911467a4ca1d6c8d69736530a6157aVirustotal results 50.00%Heodo
2020-10-16FILE_PO_10162020EX.docdoc dc7ade8fcae56fa5c268c86c9602ade9af26324733a73c86e60274a9f5b8e864Virustotal results 48.39%Heodo
2020-10-15826024240254549608319.docdoc 928793e8f0d35a4a78f1935358fffc9f25ccf0b8f0d4cf8ad4a9e7a1508f22b2Virustotal results 50.00%Heodo
2020-10-15TH5579272514WT.docdoc b1ebf8efae5ce8d163d465c5ed7b819bdcc16fdbe03f723da2d0b61114721d04Virustotal results 50.00%Heodo
2020-10-15Y_PO_10162020EX.docdoc 0ab272f979fa9aed2035beb2f578c7dd1b689f64452457def9e7aca2d1c91a3aVirustotal results 48.39%Heodo
2020-10-15080434465884011795518.docdoc 18a1cbac953dff9b006371606aa8ba5ebd1794c14f128e5f46d46629e60383c9Virustotal results 47.54%Heodo
2020-10-15REP_WA3088462212YV.docdoc 2955467d39aee8efaa08f284298b86e105ff6b8855c674bb41e38ca21d2c6bfeVirustotal results 46.77%Heodo
2020-10-158463065519.docdoc 766e921c13edd4367d95fd44b3070b9d4bbee1886ba2e298fc91f030e5e034acVirustotal results 47.54%Heodo
2020-10-15BAL_83529561.docdoc 9e6ccb86ca25351f22a9960687787487cd93476f21e943368886f63c03167222Virustotal results 47.54%Heodo
2020-10-15INV_PO_10152020EX.docdoc 9ff3fa5bcfc5a9b21abf19a4f8f3c406f0874fd93f8508c58e42529f672a6d23Virustotal results 46.77%Heodo
2020-10-15PO_10152020EX.docdoc 677cb2fc5d7a4e66220d66445d3a7fa7129fefcfad236744a558140e65d7264cVirustotal results 45.16%Heodo
2020-10-15REP_5585596311150723038999863.docdoc 28a6bdd824538dcbdc61dc5ffe9d61ccf016e4a4bb027becec2d522503ec8b0aVirustotal results 46.77%Heodo
2020-10-1577572804.docdoc d3c37e88878ac9801e592c464b9f3e15b30ef3096684d4efb9ca6cc6dd042734Virustotal results 46.67%Heodo
2020-10-15FILE_JOY_100120_VHW_101520.docdoc 70652370e67cef224785a44a3bb57d19f00a8b000714cf7117ed9dec27b3c920Virustotal results 45.16%Heodo
2020-10-15REP_4143011255.docdoc 3a655449935db1d07871d79739c4fe01d8792844b72e4bc0c3f2c936b6d5ee1fVirustotal results 43.55%Heodo
2020-10-15DOC_7C0IISGCDA60H.docdoc 590e91cfd2bc7164b8528b3e845e9d45e8328e9148b90c0836936e9d870ca895Virustotal results 43.55%Heodo
2020-10-15BAL_TH0105459523CI.docdoc 004b9a020076d8317b6e57259eff30a147253aafc450379efc2c62a61fcd42efVirustotal results 43.55%Heodo
2020-10-15FILE_576150532282195549930.docdoc 9e399c9bbd8e0a5be20ce299ce14f5e1f7ae22f19f564231c3650f1a6c055c3bn/aHeodo
2020-10-15D_QCJ_100120_KDR_101520.docdoc a601d4de12b342342f6598cd8381b96e29a65844b37244bdff0603a42601f9a5n/aHeodo
2020-10-15F_PO_10152020EX.docdoc 3f6955a4c8030234f81c5371a9fe055356a777586aec5021a269eb74083d6ce6n/aHeodo
2020-10-157053965909848279433.docdoc fc98055fe4921aa92b5fb0b2cbbae5ebc0ffdc932d1ca890b893c19a838d03d5n/aHeodo
2020-10-15S_29065974.docdoc dbd52eeae1181eeddab6c7e1fc6a63564fdf6c6ab43a2ce880a8f1af89531022n/aHeodo
2020-10-15INV_3CY7BXLTAAKPRZ9E.docdoc 4ca916c008b39d7fb20cc3e639ed697d7a55e9aff96c574d84ef918f7488cd03Virustotal results 39.34%Heodo
2020-10-15P_PO_10152020EX.docdoc 1c16646cfeab936d7c06b734940cc016e92adedd7f48dd60de9d7ae5b9c0f0f1n/aHeodo
2020-10-15FILE_336736214769702409234.docdoc 4e6a0c30dbcc9c81697110910d0edcbf9a9f5442eaf0fed07248c448429580f5Virustotal results 39.34%Heodo
2020-10-15INV_69505782872235.docdoc 3af23db230b41473efc4a9e11313c77015bf9f75aaf0e161a94302a653a61fb9n/aHeodo
2020-10-15PO_10152020EX.docdoc 0850678a5e71af1138fff503d804bcefac8f4f1879bd6ef978b7b2ef7ec7a5f4n/aHeodo
2020-10-1581697008291072720229117.docdoc 126e0cb8e06d086d1cb6cd52b90ecd444ee192b4be22ab082735f5c3e8b37228Virustotal results 38.71%Heodo
2020-10-15K_PO_10152020EX.docdoc 099d655f10b7e9d0e9a55994e8e8fa9ee064af726187f27e444a4583731c58ddn/aHeodo