URLhaus Database

You are currently viewing the URLhaus database entry for https://fechamentodesacadas.com.br/app-krog/9Muy3htT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:757910
URL: https://fechamentodesacadas.com.br/app-krog/9Muy3htT/
URL Status:Offline
Host: fechamentodesacadas.com.br
Date added:2020-10-27 20:34:05 UTC
Last online:2020-11-03 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 20:36:36 UTC to abuse{at}digitalocean[dot]com)
Takedown time:6 days, 19 hours, 53 minutes Bad (down since 2020-11-03 16:30:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Doc_GLB_100120_JGC_102920.docdoc 41439f935c27535a7752ad0b7a778de41fa076af62cee2bf3ce8138567fd7060Virustotal results 35.48%Heodo
2020-10-29Attachments_PO_10292020EX.docdoc 66f21ad9f94f3926c870736b3a33af58b00eea538ae8da9b7cd71ad1eb5614d6n/aHeodo
2020-10-29E_ABO_100120_TZU_102920.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29inf_BOX_100120_OPU_102920.docdoc 4578d3920daacf96ae730e547892639558d1ae71b1820d402dbcbfc3ebfcc816Virustotal results 26.56%Heodo
2020-10-29Mes_61169381.docdoc 5a00d4a9d8e50c06f30007460af1dc4f73950dff8ef4d1966ec4098c16712bf0Virustotal results 41.94%Heodo
2020-10-29Mes_74695404.docdoc ffa31d45d93161ab298442d4f9d83cf8b0bcead9e50e92a048b6b0900415b59cVirustotal results 41.27%Heodo
2020-10-29YSZ_100120_EDS_102920.docdoc 384a86ce03971610e03d72c4c46dd311c1719b3264e1f8724c6314a5f724b5ccVirustotal results 37.70%Heodo
2020-10-28Mes_FTE_100120_KMY_102920.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28doc_07971614.docdoc 3e40a7defd105440e12f2955234fba81780b20f1dbc188417b1381f6738ab15fVirustotal results 17.74%Heodo
2020-10-28DAT_DDVFYVK2.docdoc 8d7bfba7aa5d45dfacce4f1d01bd73c49ac08a57ca60560244f8e4d9220ca53eVirustotal results 18.03%Heodo
2020-10-28Mes_1883538955709966647092.docdoc ba7c3b043597f378a97d2fb07531d71476797e94aa5d0d6e29c3398b9b051ca0Virustotal results 17.46%Heodo
2020-10-28list_PO_10282020EX.docdoc 5a3856662e4cbb0a005a296d49553490ac6012c6d56158cdc1b75615410ad792n/aHeodo
2020-10-28I_98DBBTQ8IOIGKMG.docdoc 783e3178de387969ad58cadd83de2b88c6cffa406063d2f66e5ee8b67db11b4aVirustotal results 28.57%Heodo
2020-10-28list_TCK_100120_MIR_102820.docdoc 2a46f3f595f2eea533b556a67f2558d85d955f1784d1d48cbe78b2e5fae35f34Virustotal results 28.57%Heodo
2020-10-28DOC_61929725.docdoc f6fd4d78eaf23a55319eb3b14344a592bfe7d542cf1f7e45a9ff6fb8ad9f90c7Virustotal results 22.22%Heodo
2020-10-27Mes_PO_10272020EX.docdoc ef29a8422b09e506af3affcef90be9236f769d51ce6a686df8fb8dfc6fcd1284n/aHeodo
2020-10-27LIST_NIB_100120_BGN_102720.docdoc 18d5538b99af884d1bb696f03df08bb7ab04370724b050f1dd643690430da470n/a Heodo