URLhaus Database

You are currently viewing the URLhaus database entry for https://bnldata.com.br/test/paclm/967134/CHxLPNV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729837
URL: https://bnldata.com.br/test/paclm/967134/CHxLPNV/
URL Status:Offline
Host: bnldata.com.br
Date added:2020-10-21 15:15:11 UTC
Last online:2020-11-13 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 15:16:07 UTC to abuse{at}lacnic[dot]net)
Takedown time:23 days, 6 hours, 29 minutes Bad (down since 2020-11-13 21:45:41 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-23Payment.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 54.10%Heodo
2020-10-22invoice.docdoc 401e3ed004f6a908758dcda91de701a2bf29c67379e11a3fa21438ceb5323864Virustotal results 48.21% Heodo
2020-10-22INV #0083 FOR PO #720911860.docdoc e1c18ef2692a84d679e77f98cb2d79c78ce841f999715235aa5aac42607ad26aVirustotal results 48.08% Heodo
2020-10-22form.docdoc 8849667217cbf5aaf17be7bc7eaef3b073f32d6d7d7a6f36a022c270228a0d8bVirustotal results 50.00% Heodo
2020-10-22JD-100120 MQDR-102220.docdoc 711fafda2f160ff5d89246ee698c4ba0738663a2a0a61469c401fc03f59b4550Virustotal results 49.09% Heodo
2020-10-22Payment.docdoc 65fab287607d55bb546b639bcce9b869bae1c1fda07a15c68e1b9ebe8a626a68Virustotal results 49.06% Heodo
2020-10-22Inv_26475.docdoc 20cb9774c3025651dcd7afb95472891f1b6bdab40da18e17775e4ec56084d0a0Virustotal results 49.18% Heodo
2020-10-22October Invoice.docdoc 495313b4809b48cfad065e665cb9bc04759262897b08b142734ff1f15316f5d9n/a Heodo
2020-10-22INV #00952 FOR PO #00669840286.docdoc 098b7a1d812c209b85974e1f187e3a670e02821164c1dba212da04d78e86ff33Virustotal results 47.17% Heodo
2020-10-22Payment status.docdoc 973f68fa660b0ff4da0047bc9d942a6f2faf63713e745fe19eaf4cf5d29828beVirustotal results 44.44% Heodo
2020-10-22PO# 10222020.docdoc 7fc0ea2dff012c502278a94d7dddb537859be6ac340e8ddecd41eb42b169a7a7Virustotal results 46.43% Heodo
2020-10-22Inv. 04639.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1n/a Heodo
2020-10-22invoices 65417 & 5585.docdoc 14a0d5ba65a4585300b4daafa06c20898b303bcea1302012ef2f19559124edbaVirustotal results 41.67% Heodo
2020-10-22Electronic form.docdoc 4d7e619f0381816bed7d0ffb6ea0a43ebd6050cbfb10f691c1bf8d8466c11345Virustotal results 45.16% Heodo
2020-10-21Invoice.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo