URLhaus Database

You are currently viewing the URLhaus database entry for https://macnort.com.br/wp-content/lm/WkGW2yirHq6axyE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:765811
URL: https://macnort.com.br/wp-content/lm/WkGW2yirHq6axyE/
URL Status:Offline
Host: macnort.com.br
Date added:2020-10-29 15:37:08 UTC
Last online:2020-10-29 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 15:38:15 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:6 hours, 39 minutes Good (down since 2020-10-29 22:17:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Attachments_20201030.docdoc f7859c423dab46818b45b25833fd584c16ed8e13e40c154fbf31c4266f11566cn/aHeodo
2020-10-29Attachment_2020_10_30_3014109.docdoc a260420dc5be1222922aff55612c7de95fa5a309575098f10604dfd43014e888n/aHeodo
2020-10-29List_J819.docdoc 5989ebebdba93ff92ec47e758b81593c8c33f5ed560f51d2c00f45159b44ff08n/a 
2020-10-29Mes 20201029 4130622.docdoc 749a637bdf40f86a5743764dfcf9c1654d7c1943f00127bf4cdf440d04412f31n/aHeodo
2020-10-29INF-2020_10_29-6009.docdoc b6d3678fe3bec7bf0bd077827bb31835e195f7ddc4cb9e85ad7dc33d0b77beb0n/aHeodo
2020-10-29mes IP215545.docdoc a9adf996fc16c172ac4f9b304cd5bba6914adfff11025c697e9c0ade0193e353n/aHeodo
2020-10-29TQJ78451.docdoc f452ebbb6a749f0cd58dd03de749ef6a2158119219902efa67d5f025461e96f3n/aHeodo
2020-10-29Dat-2020_10_29-5089.docdoc 3ce86ebeb7522e05953bd5076f603c7937e47449bce8168d8ec536b1c388d54cn/aHeodo
2020-10-29file QMJ9394.docdoc 17aad9f175247945c507373641edce9a099ed686ef9766f2440001c66f0d2dabn/aHeodo
2020-10-29rep_2020_10_29_ZZM8317.docdoc 607451ddf8cc5284cc196798661712f31a71570a72463cb08cad137651313f02n/a 
2020-10-29File-4954323.docdoc 36e86b29646738d8621d0a0a76a435b4dfd8bc508480bfe3cf0f7f10c345deb7n/aHeodo
2020-10-29CW551-DFA10371.docdoc b6c6dbf739957462e2888c43c0f3380eba16593b2fe3bf0a587ad0a91a53785en/aHeodo
2020-10-29Untitled 20201029 263023.docdoc 2b6bf06663b63251018866acf0a7fed5d2caa85b0c51bb12b7c63567dfb01cd8n/a Heodo
2020-10-29268835 20201029 UNV992.docdoc ce869158de875fbc33001bdbb7b68789e1eb568ea293d4f62d20382987e1566dn/aHeodo
2020-10-29doc_2020_10_29_TK83518.docdoc 35cfc30ee33e7eb03d137ab3213c99f84c77f31a53101a9f5cb34fd913444d8eVirustotal results 20.00%Heodo
2020-10-29LIST_527089.docdoc c6eea0359a87d3f6b39ebc7115393ee78e0544300a10f031f087fc6ba7db2a7aVirustotal results 20.31%Heodo
2020-10-29inf_2020_10_29.docdoc 5b058e314ca3eea9e01e7991f6234e1ebf0239e38dbc62f38eb0dd7f85d0f390n/aHeodo
2020-10-29Inf-20201029-2450478.docdoc 46d9e560db1a1d687d58d92ded82cd4ddc77a154a7c66bcc99d628f7386c97aeVirustotal results 20.31%Heodo