URLhaus Database

You are currently viewing the URLhaus database entry for http://rommaconstrutora.com.br/tmp/protected-zone/test-62814889-JgslHwjoMgvRB/repb-622s6vzz2914z3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299118
URL: http://rommaconstrutora.com.br/tmp/protected-zone/test-62814889-JgslHwjoMgvRB/repb-622s6vzz2914z3/
URL Status:Offline
Host: rommaconstrutora.com.br
Date added:2020-01-27 19:59:11 UTC
Last online:2020-02-17 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 20:00:02 UTC to abuse{at}vieiraarts[dot]com[dot]br)
Takedown time:20 days, 17 hours, 23 minutes Bad (down since 2020-02-17 13:23:04 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29File 2020_01_29 1643.docdoc 2df80238394c3883f0ebe4f4c07af0fafb41cd51443cca87bdd158ba485f0dc5Virustotal results 32.26% 
2020-01-29List 20200129 58990.docdoc 7e8c0e91d30b485bed7963d9d3169c243edb3f5f2ce5e8049df4731007ea4d61Virustotal results 32.26% Heodo
2020-01-29inf_2020_01_29_00478.docdoc 49725f6641477d5fcdc1933e66eb652922a1e1264277a6aef8069967eb0084f0Virustotal results 30.16% Heodo
2020-01-29Dat_2020_01_29_1766175.docdoc 8dc40d99f92dd1c2ff5556ae1ece5c86052c849ee3b1c2d6f92a088e0ecd17b3Virustotal results 30.00% Heodo
2020-01-29mes_20200129_844.docdoc 7caba02f08e117aabc3a0f109c1e5d565c3fdf3aec3ae0c90d0d78a16b6c2a8eVirustotal results 26.98% Heodo
2020-01-29Arc-HBL50631.docdoc ec9b05ca4512e2e594339751e698ee57b1373c749a8c8b26cbe5c79dc1e978ccVirustotal results 26.98% Heodo
2020-01-29Dat 20200129 53805.docdoc 535c5234dd69ac3a1a95e01ff9c97dc628806d9004c4c59bc93a9694d3d91935Virustotal results 28.81% Heodo
2020-01-29ARC-3986.docdoc 49b8fd89ee5214a640b987bf72e14b9ef0ce65d9d14143e63ed55e8e8113f7fdVirustotal results 30.16% Heodo
2020-01-29File 20200129 CN018416.docdoc 66ecd1fbf53f10ac6f349605be071821abddb87b684dbf9e12b5add72eb5a61bVirustotal results 26.98% 
2020-01-29MES 2020_01_29.docdoc a4edb0742bb50f5c20c88508ef0dd1028d985dcf0b9ced6c6c9bdf800e1c6748Virustotal results 25.40% Heodo
2020-01-29List 20200129 KJ40881.docdoc 2c68f8e2764dd94c2229034f644bf7cb24cd34b1fa153e999d321e0e4eb8e73fVirustotal results 24.14% Heodo
2020-01-29Doc-0022646.docdoc 1ef6105a74f740cf1d57a9669a882f56dce5e41b6ed9f71ffbebec2a9f17e586Virustotal results 24.19% Heodo
2020-01-29ARC-G67294.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29MES_ICU75148.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29list-20200129-UTW2827.docdoc b40831be7daa247208f2f37c223101e825eca3eaedbae7a72de040e21852ae00Virustotal results 42.86% Heodo
2020-01-29List-2020_01_29-T358361.docdoc d7bcb9c0a8ff27400a3e2a846976dd062129a404c432e34e4fd885f734300144Virustotal results 44.26% 
2020-01-29List 2020_01_29.docdoc 0788ae6d38aa4ca42ced77443fbd28591100f61e80dced716e0f7166a4d6c73dVirustotal results 44.44% Heodo
2020-01-29ARC 2020_01_29 LOB87234.docdoc 26e9b52ab2150b5410b69fbb020642053c81b652e8c997a7bb304da089232cacVirustotal results 43.75% Heodo
2020-01-29list-20200129-540.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29arc-SR076128.docdoc 99f4cbe6a9549c0dd8d99cdbee3c8ffe2c85d61f8a3cc94d1e57a962e4497be1Virustotal results 41.94% Heodo
2020-01-28MES 2020_01_29 GBG2102.docdoc 3184cbfa34c1ffcc3a308983dbff824aa454bb50b733e4cfd2cbb343030b9d6bVirustotal results 41.27% Heodo
2020-01-28Dat 719.docdoc 8b8474795d9bdbc5d8247db653044a519fc7895540dc1f99c035f20657232fe2Virustotal results 39.68% Heodo
2020-01-28doc ZLT435176.docdoc fb2b108e0a60dd86b0478caee0c19cb0056953fbfdf00e100184e1a53a031948Virustotal results 36.51% Heodo
2020-01-28doc_20200128_Z7038.docdoc 4f0657b4834de2757799949da41f3ed5391b919f6539122e9dd06523c75df20bVirustotal results 36.51% Heodo
2020-01-28file 20200128 XXB847.docdoc 1372742adcd190a98aed80628931953e5790da849a501253fdb4968664b2cc91Virustotal results 33.33% Heodo
2020-01-28dat_QVD756962.docdoc e973fec4c3e5b5f599c5defe0c00df33eae0e9b00f1f8a1d8f9479d4e343e446Virustotal results 25.00% 
2020-01-28Rep_2020_01_28.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28list_96451.docdoc 894514926b92fd7ef2300717c7110a6a2aa938dff494d0d40fec8d927317cc34Virustotal results 24.19% Heodo
2020-01-28Arc_20200128_EZZ4577.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28file 20200128 69364.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28list_20200128_HRD587.docdoc 61514048db1a55f3925167e476adfb92d108fb4a6bb26d4e7059c42cf03f7fbaVirustotal results 29.03% 
2020-01-28FILE_179587.docdoc fccf3876128e78c8d3a6385aa312b1333c822a2b9efafb26daf1d2ffea296d59Virustotal results 25.40% Heodo
2020-01-28FILE 20200128 JJL993082.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28doc-DR61099.docdoc ee9887fd294a87ab64121883286bb7719cdcaa2efee9f5436b73aeac0ded07bcVirustotal results 22.22% Heodo
2020-01-28doc_20200128_R02021.docdoc e7ad66bb697a067a77d8161ea282f57732ad655dde508698cfc0b31ffdc18988Virustotal results 22.22% 
2020-01-28File_4702.docdoc fd375e3e635e2233a2c582c4aa48c277ad9d0bc9b9b8d498d9c632641e894c30Virustotal results 22.58% Heodo
2020-01-28rep-2020_01_28-2595268.docdoc 61d0d2aa3f2b0af2db0d2e4037ac0753965f1d03e0231b17a3695337b66ddd79Virustotal results 40.32% Heodo
2020-01-28Doc_322.docdoc 33d3ef3b1fb0f8ed8ed87b487e184b207ff302b60481dac9da9487ca210247e9n/a Heodo
2020-01-28File_2020_01_28_557.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28FILE 2020_01_28.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28File 20200128.docdoc c13b52eb583794eb0a50cdcaa031505507d999bc95725e77c29eb6b1adcfffa8n/a Heodo
2020-01-28file-20200128-124420.docdoc 5d122705ee27c72e755eb8df3baab283269868ae0095c36474b8195aa96048daVirustotal results 41.94% Heodo
2020-01-28doc 2020_01_28.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-28REP ODV97277.docdoc 3927da4014a56e521774e33625a1ac60e65e39edee26dca5fc703fc240bc0c99Virustotal results 37.10% Heodo
2020-01-27Rep_20200128_7526386.docdoc 8a5d48bf4570d69fd4c9398857cb6bde479600de838113e497e4d139720ab207Virustotal results 34.43% Heodo
2020-01-27REP 483.docdoc 2d501d68c1e225c67050206bd812c1f22671ec54a92dfad493ac47c632194301n/a Heodo
2020-01-27arc-X169998.docdoc 00d3cdcfb18c2255d5b25ec56d010091f4b247ecfe7fdc9c2168e88e2c2c1768Virustotal results 27.42% Heodo