URLhaus Database

You are currently viewing the URLhaus database entry for http://cookingbuffet.com.br/wp-admin/d1l2Mr8eXjAwejN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:936431
URL: http://cookingbuffet.com.br/wp-admin/d1l2Mr8eXjAwejN/
URL Status:Offline
Host: cookingbuffet.com.br
Date added:2020-12-21 22:15:11 UTC
Last online:2020-12-22 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-21 22:16:20 UTC to abuse{at}hospedagem[dot]net)
Takedown time:19 hours, 51 minutes Good (down since 2020-12-22 18:08:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-229GXORNJI3R4ASG2I.docdoc d86732f28284b8dbef93bd8eeee3150fa2696a1ccc22d520bd82a2a53c58c32bVirustotal results 42.86%Heodo
2020-12-22VABN89TM5JP8WOFU.docdoc 6191dcfff06f36e7ae3ffab9272718d60482913bac94ce985ce8a5eaca930e26Virustotal results 43.55%Heodo
2020-12-22S48OON7.docdoc 40a6e4fc5788a8fe8d3ae1e732c5f4ac0ac13a1bff111aa979d857b4a82ddfaeVirustotal results 42.86%Heodo
2020-12-22FSGUV4T1F318K4O.docdoc 258bf32591a0ac34fc68c8d36075c55b6f45b79eaaf16e3e853ba48e90a3a220Virustotal results 41.27%Heodo
2020-12-224TR91EW6W8.docdoc f263f7f7759848e0f9900bddc71fccc212d9432b745154fb9529ec701034a945Virustotal results 38.10%Heodo
2020-12-22GHXUISVD2R2WCZ.docdoc 6f31c56a8ea0949ade1a3cabc55e00d367bb073cfaf7f1b447258c79483910f4Virustotal results 38.10%Heodo
2020-12-22TGY4SZ42ZP.docdoc ca93317d1d526ec7ad19a487cfff9df808e5ca37aefd09b481f17cb982adf0ben/aHeodo
2020-12-22MFUFS1QSTFIU.docdoc c6c497b8b80b60aaac20c3b297c075a7c33721474d225bf1a52d33cf2d9a6924n/aHeodo
2020-12-22BDWGQAD8R68Y.docdoc b7bad120c0c3ba7ed2881c98fc26104cefee58148b7c5850ceb87b683595f2a8Virustotal results 34.92%Heodo
2020-12-228W9MVBTL8Y.docdoc d314d90e4d1d49a5c8c82aa438c7c5c4be663a4f68879244a87adfffe358f8b0Virustotal results 35.48%Heodo
2020-12-22115WHJJ83CX1G.docdoc 6b865ef4ff2653d141429f88dc0b8e77f14d9315c583a24169804ef1a619dbd4Virustotal results 35.48%Heodo
2020-12-22E9TA5H3BE01UN.docdoc 6e80cf87bd4ef21287958848ca5250a78cf17cf17f09a9b1b11cd37a01a24202n/aHeodo
2020-12-22FYKGDU7BA3U.docdoc da6ae027905e668507b86b9b9b4dd2dc2585d7ac3cb4800e01b88c63796e89ecVirustotal results 35.48%Heodo
2020-12-2228DSHORJAYFMSTKY.docdoc 7ec200a834392208ae8521c4804d11ff669137b4265b732a17660527ccf3cf36Virustotal results 36.51%Heodo
2020-12-229J4867CDYO.docdoc f5d52678316f377c59a3f063b29a06a415106d5833d1786533d7abb7e27008ceVirustotal results 35.48%Heodo
2020-12-22GOBPAY.docdoc 2eb890f47074a802abff73fabb722541ca607ff36a0139e4d236e875191e0078Virustotal results 36.51%Heodo
2020-12-227PUB75.docdoc 551910c092733b7324c377351583667a6389e76f8e36f1ee73c82d354f970cbcn/aHeodo
2020-12-22RI14O3WZM9179.docdoc 5859c620940889e8f706d72a664c360201c9ba13ef890968418d85e89488b940n/aHeodo
2020-12-22RF5909QU.docdoc 44567a5fc7455899c29966d8b05b823a60aa48487ed47b4ee9262fbd73bb6a1dVirustotal results 34.92%Heodo
2020-12-22IGNUYS3YLA.docdoc 3b5c9187cd87a172187f9ff9585254d03337d1d7c08cf1841e87cf41250a8397Virustotal results 33.33%Heodo
2020-12-22EQA09P6O.docdoc 9715569196b0c4f0928ad28a0d6bd5cbda2ea599848b47d1850ab6ef01a1e794Virustotal results 31.75%Heodo
2020-12-226II0JJ1HT0F2Y.docdoc 9720a3e0e322e5daf89a2d48916ae17a8d58eadcf34fdbddd7955ecf2d7007e8n/aHeodo
2020-12-22J5LF6Q8ZBR7CK56.docdoc 3ffaf475cb8655c59598f2c4591efaf0b153a52173bfb3a63c238008edb72201Virustotal results 32.26%Heodo
2020-12-22ZE46X0EQO9.docdoc ff2576fe2ef3d0e73e1b95e7283535cf0d6874a1da73b31c6c320f25ac2a4245n/aHeodo
2020-12-22ZE9NN1YT.docdoc 205ebf3346876ecce80616025b86de13965c5e1fb6f8e252fe9337ed8390bf31Virustotal results 32.26%Heodo
2020-12-22OX4MHLAKN.docdoc e18f34fd2b761c5ff699a3bb1e6bf4fa2f9d43f91cfc0ff44794e8ae7e4ae926n/aHeodo
2020-12-229FSWXQ.docdoc 5149cb89cfadd9c7f7be6ff7dcd70eecba452c53d75bd5622bbb334b4ae587dfn/aHeodo
2020-12-22HAWW7MVBBL.docdoc 676ba746091154d8c359580e500792f3b421e5c71ce4a42acc39ad450b612bd0Virustotal results 31.75%Heodo
2020-12-22NJR1JDQ4O.docdoc 776b2b58c63e7f8a7fb02fa5b3417b23424f00e19b62cc13de945804930442b3Virustotal results 29.03%Heodo
2020-12-2294PLD522BL.docdoc f1484f77d7833c2797c1f51838d30018f62d6b94cd90a17ac0f72633d22222a5Virustotal results 49.21%Heodo
2020-12-22S7RHKMDN2F.docdoc 5107a8bea0eaf25e9678f18390225717dd772522a6645b195e40d9e9214f058bn/aHeodo
2020-12-22O3NBRRO2TOM6PWB.docdoc 8c609a2a6e8a0753a2e8749e054a04f699c4bc379523bf3029413cc4f61163c8n/aHeodo
2020-12-22ONSJSMG5J9.docdoc 179c65c6aae9e8a8896992f0857998ef7e72fe3ca772839399d9185a8fe328d1n/aHeodo
2020-12-226LALF7YTHXWIXR.docdoc 852a163a7446bab72a51cddd9a4f9779ed06d409186cab20d69127d08fa490f7Virustotal results 45.90%Heodo
2020-12-2243M3P1TKCCP2HV.docdoc 99791db1cb487d25ca3160836589adcad5fc57a1dceecd3cdc82ecbee51716beVirustotal results 47.62%Heodo
2020-12-22VQTAQEFXF2.docdoc 419de57605bb9474687edcff1207a053c0da9c08c58d7ad4671981603cc08743Virustotal results 47.62%Heodo
2020-12-226ZTQSYLN9N7OA1Q.docdoc 131c12376698272b58eac7309a57016198b292bdf5b742e66c1ed352ff788736Virustotal results 50.82%Heodo
2020-12-22YBLT34.docdoc ba2bc32f4daa30fda2e05c5960a6a160167101889384e98690e6abbeff973434Virustotal results 47.17%Heodo
2020-12-22IOUQDO49DUZDG.docdoc 6adf12a084ccf2eb6dd19a35742a35f03bcba878416ef83b9c520e17d55ac329Virustotal results 50.00%Heodo
2020-12-22BO7Y2VZGM.docdoc 716592916c6f39ede3e673f03bfadfc09349bf29a45ad31bdd83faa58b0efc0aVirustotal results 45.16%Heodo
2020-12-22PHCGYOBIPU42.docdoc 6c26774c4763bbbc05c970dbe0b96045fefbdffc80c2d7878e8ca8089f0215c9n/aHeodo
2020-12-229FQ8C31WY.docdoc 200414fe067c46610fc5739841fdbd2c50b2c19b65693fffa9e8999c094b45feVirustotal results 47.54% Heodo
2020-12-22QLI75392.docdoc 45defa35954d6268fe26f6ffec131a6de427af2f682079ef11852a33ff1db07dn/aHeodo
2020-12-22N7TNASR3D0.docdoc ba1218e38d9223acf507cfc1a458681e54567ca72f03040901578a63ffc0ba06Virustotal results 42.86%Heodo
2020-12-22J60JYSD4I0.docdoc 47d01951e8e4d0425373658359ab6e4e764c29adf9f0a674dc51fc859ee31719Virustotal results 38.10%Heodo
2020-12-22RJBSEJX.docdoc ce6fb78ce0ce59ac239eebb55984e0497f6f9616a5a4ab3fe28b63e8456f3e8an/aHeodo
2020-12-22SH7NVYJLAP.docdoc 9eaf41a79c3932d4be36d56a7b01c16f4bc4ae8d3df11291ba46f7e2dc784627Virustotal results 44.26%Heodo
2020-12-22NY6B2EIAD3TZE3.docdoc 474bdf90e53ddd00548e4df1cb15832ba181a53459588ce07109ac9d69f7ae4dVirustotal results 39.68%Heodo
2020-12-21IWEKX3KFAMY2LMNC.docdoc 83e9ba22a2d674453b12f9150d400d11d35d268d6965b4082c08f070fadfa169Virustotal results 40.32%Heodo
2020-12-21YH6WP5XDABVDM.docdoc 6a7525a409509ac4ff33649e2dab4cc9580795c516cf135dc3a0b5fb5ad0003cVirustotal results 38.10%Heodo
2020-12-21I10FVKSPNA11.docdoc 798206f85b1ad48e7117fee89bc496a003d67f0b2079a39f3d80d975e8f20c78Virustotal results 38.10%Heodo
2020-12-2142IRRMYVX0RMGF.docdoc aefe4fff4d754c7faf5c1ba8e33586ac4732827c66e5621c0fe5a711895657c2Virustotal results 38.10%Heodo
2020-12-2152NQ0D87FE3I6.docdoc 199329cd5b35fa9650fa7ddb3597cc3c1c1e88242b94558bda89b7aa7bd6c463Virustotal results 37.10%Heodo
2020-12-21RC30E09GTUL8B.docdoc 38a05045c1e8dd70252d43a09d6aaf12e75e21ee3f9a7153ad1c99101f28d933Virustotal results 38.10%Heodo