URLhaus Database

You are currently viewing the URLhaus database entry for http://congresso.redeunida.org.br/wp-content/themes/form/8644164/HVqEU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:733035
URL: http://congresso.redeunida.org.br/wp-content/themes/form/8644164/HVqEU/
URL Status:Offline
Host: congresso.redeunida.org.br
Date added:2020-10-22 05:53:06 UTC
Last online:2020-10-22 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 05:54:04 UTC to abuse{at}digitalocean[dot]com)
Takedown time:9 hours, 10 minutes Good (down since 2020-10-22 15:05:00 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22INV #001767 FOR PO #00443502912660.docdoc a89a346ba95533594891a15e53625209199e68bad7519485b3bfaf1954b2a8b8Virustotal results 45.16% Heodo
2020-10-22Inv. 12973036504.docdoc 73dbec89c21200a9e7dd1ec67b06b9efad9718584b71af252f4926418abf32f6Virustotal results 48.15% Heodo
2020-10-22invoice.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937Virustotal results 46.15% Heodo
2020-10-22Payment status.docdoc 9e13f2a6023aa5aee27ad5d18154d66135feae3909574687817e602e90390b5bn/a Heodo
2020-10-2200800305.docdoc 410f511f7ba84ffbd69fbabc0226828f52eec22c5b5db6759f60fb65ea20270an/a Heodo
2020-10-22Inv. 0146499.docdoc 49e99a2c9064c24011dc0c71ff29d661e2b447f8213bc858b7feaa28d5d22576Virustotal results 44.26%Heodo
2020-10-22058982.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 60.78%Heodo