URLhaus Database

You are currently viewing the URLhaus database entry for http://babilonianoticias.com.br/cgi-bin/j1c9jafhTwh89DQkHCQvLJArmv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974381
URL: http://babilonianoticias.com.br/cgi-bin/j1c9jafhTwh89DQkHCQvLJArmv/
URL Status:Offline
Host: babilonianoticias.com.br
Date added:2021-01-22 19:00:08 UTC
Last online:2021-02-11 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-22 19:02:07 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:19 days, 6 hours, 6 minutes Bad (down since 2021-02-11 01:08:57 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23S2CGD6A.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-22F88XNJ4G3A4X.docdoc df60461aab62bf09077b67a5fd122fa46ed22f8a8d184035786a7ee3be961927Virustotal results 31.75%Heodo
2021-01-22RV7IYOE.docdoc dda4d5d6a43a16422b43d2303fca26fdda00b3b7836e9aff4ddbdd19442d9697Virustotal results 41.94%Heodo
2021-01-22JDKEUE6UAK8.docdoc c82d9f636e5557e336f7590d7012768bd8060c6ccbe44a3a5c1c2e3976c62b3dn/aHeodo
2021-01-22RITP682.docdoc e86d93199f2f416bf5dca9a736c5bdbac4ee3989ab0f04baad2c7e0066316e72Virustotal results 39.34%Heodo
2021-01-224UXBN1KCWDXI.docdoc d369edd4ee295fafd1231bb5d370fff75a48505360a64708bce6418c7f2974a1Virustotal results 38.71%Heodo
2021-01-22ITZKNPVZTVLREO.docdoc 8af280e70fb92f35455e9f18296c0fbaae42288517c6925a9db673a9368e9bf3Virustotal results 38.71%Heodo
2021-01-22V0EGDVWDW0N.docdoc 9849abef3e272dea13e211d946b289bc80ab32efd5e83178ca17a6bb094be274Virustotal results 35.48%Heodo
2021-01-22VWA5FAX.docdoc dda31bb204e2a3207fe515d3d1952604f010c2b3bfad0df8a1b33e7b4bde2b94n/aHeodo
2021-01-22BZHP6N2FA8.docdoc 912f6f38547eca79cdd2f66b1252ac5b777f454c8d4da059d319ca9a42d1cf24Virustotal results 37.10%Heodo
2021-01-2228YQWF0ZNY.docdoc d25d5d359b01bb46095375c553f2b4ea91e2e4abee77df10d21d6ab08740dc97Virustotal results 33.93%Heodo
2021-01-229D2QZ4OMAE2Y.docdoc a1714164bf96046b86ee335216b926f51c376447578ad9dc401301d954033388n/aHeodo
2021-01-22KZTCA66UTY.docdoc 5b8a09ecc983f2bfa3c172b58755d141faaaa80c8016de77c9cbcdd83805d5abVirustotal results 32.26%Heodo
2021-01-225UKVGIUKWK6.docdoc aa52526574d2e2f917022706d1422b52cc611dd7b27e5edfc22d8cfabe29878cVirustotal results 33.33%Heodo
2021-01-22AY53BV6TH4M.docdoc a6e3f80247934f88e6f81b410856f90de3c0f41e5ae883b9f469e68c8c67ea38n/aHeodo
2021-01-22FTJHC2W.docdoc c7f261f11d0e317860ef68857f8457e85439e702a7c90170b9b74b1508656b99Virustotal results 33.33%Heodo
2021-01-22ESD468.docdoc c47dd140c6bc057daadb9ee597e65f4354bd84521ed7631a0f100eb027f6adb8n/aHeodo