URLhaus Database

You are currently viewing the URLhaus database entry for http://jornalpovofluminense.com.br/wp-includes/5GSMOAuwaSIFLrsqHv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974283
URL: http://jornalpovofluminense.com.br/wp-includes/5GSMOAuwaSIFLrsqHv/
URL Status:Offline
Host: jornalpovofluminense.com.br
Date added:2021-01-22 17:24:08 UTC
Last online:2021-02-11 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-22 17:26:12 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:19 days, 7 hours, 40 minutes Bad (down since 2021-02-11 01:06:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23ADZ3JTXZGPMSWE.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-22IZDE9D7I612H8O1.docdoc df60461aab62bf09077b67a5fd122fa46ed22f8a8d184035786a7ee3be961927Virustotal results 45.16%Heodo
2021-01-22BL6TRWOPSGD.docdoc a4ca64ab0ba7ae814fe635ce9bf2febea22c4f78b6d9310948f751713214c0d1Virustotal results 39.68%Heodo
2021-01-2218F7PPP5OWMR.docdoc 572f2066bd622ffae9324046ef4e96026a4bff32a177c91ea779269d75ac98b7n/aHeodo
2021-01-22OUYHU0W79PU.docdoc d369edd4ee295fafd1231bb5d370fff75a48505360a64708bce6418c7f2974a1Virustotal results 38.71%Heodo
2021-01-22VX9QQGZ81.docdoc 5baed32dcd265a53a8f5f4182bfa79336ffa1acc17f1ab71e8387529a82b10cdn/aHeodo
2021-01-22LELHO1YI8KM3.docdoc 9849abef3e272dea13e211d946b289bc80ab32efd5e83178ca17a6bb094be274Virustotal results 35.48%Heodo
2021-01-225PWWZV.docdoc dda31bb204e2a3207fe515d3d1952604f010c2b3bfad0df8a1b33e7b4bde2b94Virustotal results 33.33%Heodo
2021-01-22DGZ2W3FDF7H3B1.docdoc 912f6f38547eca79cdd2f66b1252ac5b777f454c8d4da059d319ca9a42d1cf24Virustotal results 37.10%Heodo
2021-01-22BOHA36MFDX5KI.docdoc d25d5d359b01bb46095375c553f2b4ea91e2e4abee77df10d21d6ab08740dc97Virustotal results 35.48%Heodo
2021-01-22X8P6J3KQ5ATC.docdoc db6d1b13388fd56125d3143e660a7d19e7a98fd2ed3787ce35da6fc8a3bd5c9en/aHeodo
2021-01-22W5WJYR.docdoc fd740860d3a13f655a4dbba01a3721f0a412082b7ba59f4b04650493fe6a3e53Virustotal results 34.92%Heodo
2021-01-22K5JX0AFUZCB7V.docdoc 0c12f24715c776b1cca7c4fcae52f35da82d11bc17f962cbc7a01b7baf4e0078Virustotal results 33.33%Heodo
2021-01-22JUMG0HD6J9I7M9.docdoc 067f29b1fa0db6eda53b0f4eb12303b42eb5891eda2e699b7c0a827710ab61dcn/aHeodo
2021-01-22ZM4R1L.docdoc 18eeb3c4acd968e5fb4a847ef4eb4953690be2b5a9ad36d6f82a9cbc7caa7a53n/aHeodo
2021-01-22D8KPDEJA6.docdoc 1d6af24aae07d7b11397907b44aa3108efeaaa211b182a6dc28246b79a36a2c4Virustotal results 32.79%Heodo
2021-01-22H0GNZ51M.docdoc 1da786f3dda2528e89f62d6d75304c3d17d615ae7e2bc188700c2cd1a3a7c21cVirustotal results 31.75%Heodo
2021-01-22W1IPNH8MA.docdoc df5ff0dd34808825942b6b896c5129f63bc36f8fbbba7f3ce145cced467c662an/aHeodo
2021-01-228NQJV9.docdoc 79901cb00c81b1c2bb626096ee6bdf18e1bb6e757f7c48c0bf1c0377e9d3cde8Virustotal results 31.75%Heodo
2021-01-22UTYGUM2GV.docdoc 361afbb90589c1dbaba30c9c8b380772449df5b01544e084fe473b501f583129n/aHeodo
2021-01-22G9ITUCGNM1RJ2XN.docdoc e26acfd8ba9ac131426a2d9667e8ad19344e9977a884531fd2a2127615481f99Virustotal results 32.26%Heodo
2021-01-22OAUA86.docdoc cb61a7b158e7abd85d3eae1f24f813429ca19d16a207e7263022e5ffa0b16fd8Virustotal results 31.75%Heodo
2021-01-22FUWYL23L0QPXP70.docdoc 077fd7de4590c86cef6c92180c5d65a613bc17a38f749b04ac9ec8d2bee2ecafn/aHeodo
2021-01-22JPG4QNX8I3YS4AN.docdoc 0a1a62f399d64c1fbffd740358974f855e76f9dc173292b27ce0eee5abb689e8Virustotal results 32.26%Heodo