URLhaus Database

You are currently viewing the URLhaus database entry for http://greensync.com.br/aspnet_clientOld/9406470676/dFFi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762155
URL: http://greensync.com.br/aspnet_clientOld/9406470676/dFFi/
URL Status:Offline
Host: greensync.com.br
Date added:2020-10-28 19:24:06 UTC
Last online:2020-10-30 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 19:26:21 UTC to abuse{at}hospedagem[dot]net)
Takedown time:1 day, 18 hours, 14 minutes Poor (down since 2020-10-30 13:40:56 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29invoice #598564.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 34.38% Heodo
2020-10-29form.docdoc 55948fa440efdbe28f551bded69dcb747f665518a10876e4ae3ebdcb5e44ea67Virustotal results 34.92% Heodo
2020-10-29Form.docdoc b35e8c1cf63de1025db2d2f786b3252b88272d9bad9576c7e2a223a9b4187663Virustotal results 34.92% Heodo
2020-10-29invoices 2875 & 95623.docdoc 1425e6db29a588c212da92116660246ff0b96ee0e493edb96c54bcf45dcf66c6Virustotal results 34.38% Heodo
2020-10-29VK8421388097GK.docdoc ff2bb9d11fe9eae10cc06eb741a262e915e218c4c4157428cde979b3975f49a9Virustotal results 32.81% Heodo
2020-10-29INV_12414.docdoc acbe2412c4aff06ae0a1c4b17bf4acab3d67874fa57aa0a31578e524d063f715Virustotal results 33.87% Heodo
2020-10-29PO# 10292020.docdoc 64176cb24145e182cb8783aecc0c2b5ceca0e851c932775b5a44431abee2a611Virustotal results 34.38% Heodo
2020-10-29177144.docdoc 407011017107dd82209d02b6714d52efaf3270f55a81de711db2f20d9b918d23Virustotal results 34.38% Heodo
2020-10-29Form - Oct 29, 2020.docdoc 092adc3e63864e36764ee209d07e652c3b37b55e0f433d9ae5c69a1619a482a5Virustotal results 34.92% Heodo
2020-10-29Form.docdoc 8912ed633b4518995c5cf68b1037b5f3755e2573d19b35873884074daab8e1f0Virustotal results 32.81% Heodo
2020-10-29form.docdoc 67adcb665e495bdce7d8234ef01fe0cebc5d615a6b630a2222366cd51a871658Virustotal results 31.75% Heodo
2020-10-29U30 invoicing.docdoc 07e080dc70dc704b7d6f6eb5138fc133b388aa42e3e4f9db824c0aa5e7637285n/a Heodo
2020-10-29Electronic form.docdoc e30eceea75b291ff394ffb670b46a3b07e8725dc0a146c1df069952d9ed885a9n/a Heodo
2020-10-29Inv_39108.docdoc 62da1d16914ee7b918b84c1bfd2714584b9f6a979558c8e3c09c779b4b30deeaVirustotal results 31.75% Heodo
2020-10-29form.docdoc 1c6a68700c5a829d8c421561d670c1f86cb25027af4b54be19724b1b7a979ef5Virustotal results 28.12% Heodo
2020-10-29024736304.docdoc 99d886c1a8460ebf04f28f6695c165f45ead399cf1d98bf8ab140aeaaf04572bVirustotal results 31.15% Heodo
2020-10-29invoice #96350.docdoc 493d0b6b7fe96f6e344c94ed7931ec69f8344a424f6083374387322b6ce037c7Virustotal results 29.03% Heodo
2020-10-29form.docdoc 2df17cda9f5ded819514b9060733138dd171d92eba13d68bfa61efa6d39a85bdVirustotal results 29.03% Heodo
2020-10-29invoice.docdoc f3068382cc295bad25bc7c5ee96d09893b73ed065dd521170ec6c4cc731d6145Virustotal results 25.81% Heodo
2020-10-29Form - Oct 29, 2020.docdoc 7fafbcc83ea713a0c58c02025b505e177c9014edc2dc1229d9d7487cd3075faen/a Heodo
2020-10-29Electronic form.docdoc 7ae576917499bdb77da8f95dbec37ae4f819b800e62b5f467f0900d1dd716d1dVirustotal results 30.16% Heodo
2020-10-29invoice #706414.docdoc 154471acb1707b19c1efb5b7bc06211dd35e28a69e0db7f663b983d8712d8727Virustotal results 26.98% Heodo
2020-10-29Payment status.docdoc 19d1d7b47cc9258f228a84f405d6832d66bed17bdc8f3dd9615b448d9a238780Virustotal results 25.00% Heodo
2020-10-29Form - Oct 29, 2020.docdoc 7d41847fb131218d629e6bb8132dc6b2b1ce714b4090c01c3f531fa66ad7274aVirustotal results 21.88% Heodo
2020-10-29Invoice 39097.docdoc 9eddbf9eaa4b753108631f0cdbef5ecc758378c188d216542bf2db06a4c4e7e5Virustotal results 22.22% Heodo
2020-10-29Invoice 001402690.docdoc 9da8a687183313d2dec4f41ff6c4b5b6fda388b7d8d295b3071df72518fb318eVirustotal results 21.88% Heodo
2020-10-29invoice #97300.docdoc 26e0dedfbc389de133350f134455565f185e864b79466539b658dacc21fb1bb6Virustotal results 22.58% Heodo
2020-10-29INV #00480126 FOR PO #511563194730.docdoc 95b4f0a791e9ffefe35972f8c4e1a90c115fe1c8976f779e44b5190d859b3eb0n/a Heodo
2020-10-29invoices 4164 & 0931.docdoc dd46084c550c55905276f7c43df92dbe4a91d31ba7afebe0313262ddbfbd56edn/a Heodo
2020-10-29October Invoice.docdoc 3e84e096f2f889c271504b8dcfb1e9fb78a347087b984a219d7749a8a0839c31Virustotal results 20.63% Heodo
2020-10-29invoice #915831.docdoc 4076636560061cc4ff5eef39af1175c75192f566e214b6cb17be9f9f819c0390Virustotal results 19.05% Heodo
2020-10-29Inv. 02217790.docdoc 36bc0b0a45b7b904804ec1e2efc5349ac69bbdd883633311f3c89eea32884799Virustotal results 19.35% Heodo
2020-10-29October invoice.docdoc d35618fba11f6c84539c7888912e7eb42799ab92025b7d9b15eb542b4b380d33Virustotal results 17.46% Heodo
2020-10-29form.docdoc bf01de28c8cf6dc5958da2bedc45b045e3978c687cc80c399c8fb63407e8562fVirustotal results 19.05% Heodo
2020-10-29Invoice 008068096.docdoc 8744e383bf013444ed1f687f385d558ee1c4e2a153cdfe224250a02fd1eada2eVirustotal results 19.05% Heodo
2020-10-29Inv_21374.docdoc 995bfae8132d4637a2d2e72e1f40a22043e19520c5c45039b2f257e9430f3cd5Virustotal results 19.05% Heodo
2020-10-29Payment.docdoc 2dc19d1576e1d7e5d43a3e0cf6ed690d3b66634515389ca782f0af0198069e65Virustotal results 19.05% Heodo
2020-10-28MZ-100120 LMVM-102920.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-28INV #0847614 FOR PO #07106111562.docdoc c6446a1b82e57959baa73f792dba78e1b5374bf16e60ae5bacdd7a1981c45f9bVirustotal results 27.42% Heodo
2020-10-28INV #0204234 FOR PO #000827547624.docdoc 77011899c5b86d17bd9c00bf4a80339feebd6adb1135b65512e1dfa8653e6ca7Virustotal results 26.98% Heodo
2020-10-28Invoice 02812632.docdoc 0c5643d4a7b85e177802b1eae495641a49631f1e3016455f0c7ba45709d27026Virustotal results 25.40% Heodo
2020-10-28Inv. 087651561.docdoc ccdb2c5ed40ad6227647ac04e1d3d1cb499a0d67ae9dc428c3ef6b275f786a8cVirustotal results 23.81% Heodo
2020-10-28PO# 10292020.docdoc 5177894154a2ad0d67c6ea62534a27cdc18b7cfe9c73c8ec6071d72fb8c198a2Virustotal results 22.58% Heodo
2020-10-28October Invoice.docdoc 2a87f25fe351249b33ffc8d24f6310b9d8e1e3907a6b53b06e324566027dcae0Virustotal results 22.22% Heodo
2020-10-28Payment status.docdoc 6c5d2dceb77aca3c35f72874bcb483c53950fd5f5aeb9dd9a66fed7341d3cd3aVirustotal results 20.63% Heodo
2020-10-28X-100120 SCDU-102820.docdoc 550bb4afeb580c5ca1bef73de9f4548610129a2f407d1375aa69b29c109ee9bbn/a Heodo
2020-10-28Form.docdoc 661694d6fc62c1af16ddbe2db10c54b471f5acb387cde760666a6a672635f16dVirustotal results 17.46% Heodo