URLhaus Database

You are currently viewing the URLhaus database entry for https://jabconsultoria.com.br/wp-includes/ossNIROv3ip2ia7RwzfKbG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752947
URL: https://jabconsultoria.com.br/wp-includes/ossNIROv3ip2ia7RwzfKbG/
URL Status:Offline
Host: jabconsultoria.com.br
Date added:2020-10-26 18:55:05 UTC
Last online:2020-10-26 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 18:56:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 41 minutes Good (down since 2020-10-26 20:37:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26FILE_MDB_100120_DIM_102620.docdoc fef9e77f6d9e84345a020f567b892fb4718af268465b5a6d505a6f2bbfa19e92Virustotal results 39.34%Heodo
2020-10-26REP_87929620.docdoc e8caccd0e30b68aa3a338537f9164503821ec1089daf287db3acf97ec74e59f3Virustotal results 38.10%Heodo
2020-10-26INV_SG1I77Y25P86RYHD.docdoc b9efcf9bbdfee20efe56047ca5810ea88974d9e7b9ec968a57f814842c7946ecn/aHeodo
2020-10-26MLT3BE27V1IM.docdoc 9c6f43dcc3bd1778ac7082fcd98251f2ebbc67b02f5d6e41ab97c2e8924a4e17Virustotal results 38.89%Heodo
2020-10-26ELAP_PA1352382670LK.docdoc 9a5ff2d10eb6a49a82083f2f52e3daba519399794197d526ab76a68dd6849e69n/aHeodo
2020-10-26INV_RGV_100120_KZK_102620.docdoc 77308b34c7f167510dcdfc5e0de665824b0826603235b32f2c644ddf354cf6fcn/aHeodo