URLhaus Database

You are currently viewing the URLhaus database entry for http://santucciarq.com.br/hotelinfo/uHVnBnpZqbN6ssMSRF3el8T8COlHAcbawdl7CX96WIdTewP/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:758754
URL: http://santucciarq.com.br/hotelinfo/uHVnBnpZqbN6ssMSRF3el8T8COlHAcbawdl7CX96WIdTewP/
URL Status:Offline
Host: santucciarq.com.br
Date added:2020-10-28 00:59:13 UTC
Last online:2020-11-18 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 01:00:17 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:21 days, 0 hours, 59 minutes Bad (down since 2020-11-18 01:59:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29106148621441846.docdoc a943a1b78c2ddb8ea536ad08b2eaaec624c324079322f272f1e1a319b5603a28Virustotal results 20.63%Heodo
2020-10-29ARC_80854886.docdoc 3c82747f9b2229d7edabf0907aaaf771f5e6c007ce5c3f507b56ca8c10a20d38Virustotal results 42.62%Heodo
2020-10-29Attachments_VQI_100120_TQR_102920.docdoc 6cff316da0b26621e5b1fc3d5a85c6931a68a90fde20acf702195a175fb4ce44Virustotal results 41.27%Heodo
2020-10-29LIST_PO_10292020EX.docdoc 648262e8476fb8b619abd0b6929748ed5354de0997068e2d2c349a3c15d8f1d6Virustotal results 37.10%Heodo
2020-10-29W_93951853.docdoc 17d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7Virustotal results 36.51%Heodo
2020-10-28List_JUZBGLBVV.docdoc 558f9ea460d8f9e9babcc477c01c40ba377d80607e6dec6640f78b0f12794bd1n/aHeodo
2020-10-28REP_44370498.docdoc 146747a5fe14e9c8f3de53906c757ebbcd932487aa7e6e1da69baf9ebca99e58Virustotal results 23.81%Heodo
2020-10-28file_DVL83BHTH8IO27.docdoc c79ff6d2cb77b1d4e7bc6bea1ea1b05d78d536e72254e93dbaeb1122ff214d8eVirustotal results 22.22%Heodo
2020-10-28Doc_FUA4CNLLM.docdoc b6a96390b242aa0846471f4e8be2000c6d0a46330c8a838c25b95c0dd7874378Virustotal results 17.74%Heodo
2020-10-28doc_21633178.docdoc ddcf5630aefa8de831c95d68479b3d2b92bae966f6e994b16ff7c9821a227c21Virustotal results 18.03%Heodo
2020-10-2814554615.docdoc 19377c68fd4d0b3d66624ba4a1aa465efb840857e142ec38ddfe4e1e9c573b8bVirustotal results 18.03%Heodo
2020-10-28Mes_PO_10282020EX.docdoc 6c318a9098138d3197e96b6f8b19f0e341154549e78ea5e0671f54f96328d340n/aHeodo
2020-10-28Attachment_GPX_100120_OBX_102820.docdoc 0cf82bd2a650438c7818a19c6fe0732ac0c004c56b13d070417bb70bfe3b75ccVirustotal results 17.46%Heodo
2020-10-28mes_PP1673575076HF.docdoc 499af6e46284239845d6e547823d8f197a8c92a084b2aecf1123e44d44a764e6n/aHeodo
2020-10-28PO_10282020EX.docdoc 68cb170125b6d8fe85e4573f3324f27ca595e8a2a2f0d624742c817590b42765Virustotal results 27.42%Heodo
2020-10-28FXV_08107356.docdoc 5dae469fdf99625a0b53d223a55b04fc4e77d3e660e1ab904e79071d5dc13c9bVirustotal results 28.57%Heodo
2020-10-28List_MTA_100120_XLF_102820.docdoc f43cc95ed3a2f8900938c6a240d69a2de909494821ee8308e740e2cda2fd31d7Virustotal results 32.08%Heodo
2020-10-28DOC_I0JNIG8.docdoc e6e605ad811f416df52bdd27b76218c84b0f27c3ce272e28b373c86440fb089dVirustotal results 25.42%Heodo