URLhaus Database

You are currently viewing the URLhaus database entry for http://infratecweb.com.br/US/Messages/2018-11/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:77370
URL: http://infratecweb.com.br/US/Messages/2018-11/
URL Status:Offline
Host: infratecweb.com.br
Date added:2018-11-09 00:22:04 UTC
Last online:2018-11-09 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-11-09 00:24:04 UTC to abuse{at}hospedagem[dot]net)
Takedown time:13 hours, 45 minutes Good (down since 2018-11-09 14:09:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-09file-8686732501278671.docdoc dc5ec3b2cd77da307738fe6d7b128b18a907c6fdd1eaeaff37e82533bf1b9e06n/a Heodo
2018-11-09doc-2060007751864.docdoc cdc79aef87d547d7797c8f1950754c7943dc6da4d91604a1e43cb7f32346be73Virustotal results 39.66% Heodo
2018-11-09file-6327366268.docdoc 12e9b711e546c9c1d12719740e48e599fd299db60f21126abbcf1b0495cb80cbVirustotal results 42.37% Heodo
2018-11-09DOC-5801541622.docdoc 003591243133d77d308b2aeabaa396dbb8287c60fecf6a7645771e10317d9e5fVirustotal results 38.98% Heodo
2018-11-09form-575574567996.docdoc 68e5cf10c297a7862c047d35228f9121d32a9d7012c9df0aa015e496e3fa434cVirustotal results 36.21% Heodo
2018-11-09FORM-386205552113.docdoc 8481620269d137b8bd05d6808d7f84072fff396f4acb2f445b2685d4ea1c20cdVirustotal results 34.48% Heodo