URLhaus Database

You are currently viewing the URLhaus database entry for http://hostoficinas.com/building-structure/ewgjhjhbv41idt/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:703083
URL: http://hostoficinas.com/building-structure/ewgjhjhbv41idt/
URL Status:Offline
Host: hostoficinas.com
Date added:2020-10-16 17:47:05 UTC
Last online:2020-10-26 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 17:48:24 UTC to abuse{at}microsoft[dot]com)
Takedown time:10 days, 0 hours, 25 minutes Bad (down since 2020-10-26 18:14:12 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16606Z-20201017-106055.docdoc 4773da38da0ba3154bbb3b813c803bd6e1f9ab3bad1888f1402f7b17073620ecVirustotal results 51.61%Heodo
2020-10-16UNTITLED-20201017-V3233.docdoc 49cdf52f6974aff3348c2c2ddb75be089f05da06c6dbc7f5b28fb6b5ee4cbdfdVirustotal results 51.61%Heodo
2020-10-16rep-2020_10_16-86402.docdoc 38a11481f8db3eb3a204bc7199da74cf95b722b0b5ff283001ff594b5bde8dfdVirustotal results 52.46%Heodo
2020-10-16DAT 20201016 604885.docdoc 6db73d3f7fc4ac1265b81af31cd04fb1ef63de503ea603a20b93daa896e18c11n/aHeodo
2020-10-16Arc-20201016-CZ548.docdoc 0f3f04ac85e78d80efbda9617f67a8790049ba50df890fc992c9b0ea0688cb96Virustotal results 50.82%Heodo
2020-10-16Dat 2020_10_16 J6078.docdoc e78b57e96d5a3632c93a56a0bbc199107c194dae316c84dd64473a513a3b6745Virustotal results 49.21%Heodo
2020-10-16UNTITLED 2020_10_16 53376.docdoc a1d573517ffbaeff20370dbfc3a3c7ae1abfcbde0154abf7010feae3d2911f3bVirustotal results 50.00%Heodo
2020-10-16arc-XD8235.docdoc 0b39de8a1d12106ac3b6445b1837e1997793d2942550058963532f19297f3843Virustotal results 48.33%Heodo
2020-10-16rep 20201016 679824.docdoc b4c0e8d0e75a368f062085d1359814e8f1735154278231aa2b701d875f0f6cfan/aHeodo
2020-10-16File.docdoc 08720082a85becdd96c2f6a15bd2e14fc19f13517c2a0b9aeae5fc4334adf92eVirustotal results 46.77%Heodo
2020-10-165434WUC-20201016-6677482.docdoc 3eaa0b65ba2011470369ab443b530cc881c190b9504553bd9944dde2e377e698Virustotal results 48.39%Heodo