URLhaus Database

You are currently viewing the URLhaus database entry for https://remalondrina.com.br/phone-cloning-ozul7/wygYMIY1pMwEzttoQscyBk6aaWTEnWnDW02XDrH46zddH2DxCJruU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944180
URL: https://remalondrina.com.br/phone-cloning-ozul7/wygYMIY1pMwEzttoQscyBk6aaWTEnWnDW02XDrH46zddH2DxCJruU/
URL Status:Offline
Host: remalondrina.com.br
Date added:2020-12-29 00:27:05 UTC
Last online:2020-12-29 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-29 00:28:06 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 5 minutes Good (down since 2020-12-29 02:33:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-299Y68FMSQMSE.docdoc 89ce07abb5363601631f2875dfa84e1589ef67f12fef2f298f3a9855bfe6b5adVirustotal results 24.19%Heodo
2020-12-296U3IG6G4B8.docdoc 61448f3704633ca0124dc77499079853503b7d9a14f0025066d715ae80e8e8b1Virustotal results 19.35%Heodo
2020-12-29YSZ9AQDBD6JXMEDL.docdoc 84008c13a44430bcf1f708a152bd99b047e38e4f66c500d5e6c9fbe3c9fac84dVirustotal results 25.81%Heodo
2020-12-29035L9R5HOW.docdoc 9ee1088bf930cbfa09f67536b5766c7f8244b634dbb2d97c8bd5acb1e0e819e5n/aHeodo
2020-12-29DT40U3.docdoc dad1ac448db2f4de85a54fef16d3bf90b1c8537c7ac935d0f0e2b5534a7cc668n/aHeodo
2020-12-29BDC8GZ.docdoc 31635b1f0402afa859abcb541f33761eafab1551aec0b47118b78f3e671b1590n/aHeodo
2020-12-295YG4E01RP8OQ9XPK.docdoc 3f9b8498660385229fa4c9000d3b46ca6a43f6f2d91bbde9391d1e752762134an/aHeodo
2020-12-29IJQ4V28MT.docdoc b757c7ffb783759ec9464a1631212131a15f2aa4cdacb5f974e9f1c026dd4f59n/aHeodo
2020-12-29MPF2YXC.docdoc fcc61c1b3639ee120a6b1e8e9709614682434b8a6017bea91fef29a063f0d3b9Virustotal results 20.97%Heodo
2020-12-291DF3UF97TFA05.docdoc 4b2c9f87676f3cf3eb61380529d83e39e8ba3f87eaf2d64bde0dc70d75941104Virustotal results 22.22%Heodo
2020-12-296GSQZKLCR.docdoc 6648b51c5a828a4b145d0292f72e3333278e3c97b08ce2faa174a6513b4964e7Virustotal results 20.63%Heodo