URLhaus Database

You are currently viewing the URLhaus database entry for http://pridabravo.com/joomla_243363182/5FHK9S8/R5SL/gmBsUNn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752034
URL: http://pridabravo.com/joomla_243363182/5FHK9S8/R5SL/gmBsUNn/
URL Status:Offline
Host: pridabravo.com
Date added:2020-10-26 14:41:05 UTC
Last online:2020-11-11 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 14:42:49 UTC to admin{at}internetnamesforbusiness[dot]com)
Takedown time:15 days, 11 hours, 30 minutes Bad (down since 2020-11-11 02:12:53 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28October invoice.docdoc 138f68878f0c09a4d5a982087da5f57943a8f84e87f9ff80bf9b66949d9bcb02Virustotal results 42.62% Heodo
2020-10-28October Invoice.docdoc 59bc37fdfd7ca80bfaa9586846db4d3d14026324219c35cc909e7eed62533e28Virustotal results 43.33% Heodo
2020-10-28FN-100120 PVKR-102820.docdoc dae0cc43be550a6d83464a1f5b2ba4ab8dafdaac48c3441bfc941279afd56de1Virustotal results 24.59% Heodo
2020-10-27Invoice 008755305.docdoc 25a38466146889f4833a21d4be2e6863c6f4617e632f0bc33436d7023cbaf734Virustotal results 27.78% Heodo
2020-10-27FC-100120 PTZO-102820.docdoc 0265d621d36ce8fa5ab27442f8af6b2ff09e4c00563947aba99868174be82a58Virustotal results 26.32% Heodo
2020-10-27Payment status.docdoc 4955a66e9711e8207f53c9204d68f89903e7aec37f30cbd298ff102bf68f937bVirustotal results 28.30% Heodo
2020-10-27INV_5549.docdoc 8572cb899b936699bc1d20c1b922b10340cab95df6e94f179476da4dd2286996Virustotal results 26.79% Heodo
2020-10-27invoices 02892 & 63522.docdoc 799de3c0b3c57093a424c4e80e471b26b7f7d121e6e4b75a250304ed59ab9d6fVirustotal results 34.92%Heodo
2020-10-27October invoice.docdoc 618b42ed1f918805007ba2386a3456d92250a54d5091f096234f293b695a5715Virustotal results 35.19% Heodo
2020-10-27Copy invoice #71111.docdoc 083c20d80dfd7f17a95d7bbfd891cc3756255aac0c24d4515b8c3b2d8bf87d12Virustotal results 33.33% Heodo
2020-10-27October invoice.docdoc 0021bbe25ff5b692875ec9b22ecc7f278d7859484560e1b975c37770a227a1cbVirustotal results 34.92% Heodo
2020-10-27Form.docdoc 6f4a718c27a0b032f3c9dcfb1b7b13363c6d7b1cc501579470674fbc4f94d8e2n/a Heodo
2020-10-2700053733.docdoc 87aff19e4da90231f8986afbfc0da7864ac4cb35626e8e520f7e299f5dcbee75Virustotal results 51.85% Heodo
2020-10-27N9 invoicing.docdoc e46fd80923092207fdfde7d99af929b43f3c66eeb30bf6914255531cd77a59a0Virustotal results 49.18% Heodo
2020-10-26invoice #593796.docdoc 160cdfd946aa8c04ca0f2e1f621bf04d63403d69ca338b2d7c47dc4657d6bbfdVirustotal results 42.59% Heodo
2020-10-26U-100120 TYXL-102720.docdoc df79c5ac52cb9b66b05a9a1fa95575b895fe157d766fdee900dc948e749ad73an/a Heodo
2020-10-26Electronic form.docdoc 419c646f83fffb2d831fb02787f0a5b78be08dfcad512baae2a856447920cfedVirustotal results 37.04% Heodo
2020-10-26PO# 10262020.docdoc f3ec8599a28ca38748328b6927938d26775d3a732a9c2591740bf1cda6d290f2Virustotal results 36.36% Heodo
2020-10-26Invoice.docdoc 2ce2349b04071d26f78975046ce8455435523abfb528b5545dffd191c1eae93eVirustotal results 33.33% Heodo