URLhaus Database

You are currently viewing the URLhaus database entry for http://www.toplevel.com.br/medico/paclm/84hq2v9n7e/c170jb26950023468861styt4xcog3uhfcglvq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452336
URL: http://www.toplevel.com.br/medico/paclm/84hq2v9n7e/c170jb26950023468861styt4xcog3uhfcglvq/
URL Status:Offline
Host: www.toplevel.com.br
Date added:2020-09-03 11:36:10 UTC
Last online:2020-09-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 11:38:02 UTC to CloudFlare Anti-Abuse API)
Takedown time:6 hours, 35 minutes Good (down since 2020-09-03 18:13:17 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03FILE_Y974T5ZSY9.docdoc a4f23a9a66e7c4ffc2dac35ac7bd62987cd68bfe28f2e307dcb4347808eccacfVirustotal results 25.00%Heodo
2020-09-03BAL_52778036809876364698220.docdoc 65a803b10719f7420467e6a66a5dbe9f9dea0a8dada387e1022e3e3c8340f750Virustotal results 25.42%Heodo
2020-09-03IHZ_090120_FGO_090320.docdoc 7f77b3b194b1c10f8bf8df9c595af942e2316862c4305b8ee4fd80b598b8f67bVirustotal results 25.42%Heodo
2020-09-03KJD_090120_DOI_090320.docdoc c5069077ce5c3f4efd898a6725755925a3ec7b1c6c2b99a3d04a26d47fcd88b4Virustotal results 25.42%Heodo
2020-09-03REP_PO_09032020EX.docdoc 5325916cba7c2dd93e907f56b9e92f83fa1919b03b5525a5aecd4ea611b9adedVirustotal results 23.33%Heodo
2020-09-03J_00949497.docdoc 100cc000ad85991dae1f7a526fa6cdb150fd7800013adb43ac0914af591456ban/aHeodo
2020-09-03KTU_090120_WFZ_090320.docdoc b0f01523d8f17d5b95b99c2e15a3733f3f6045b8f465a000089aada0d641702fVirustotal results 21.67%Heodo
2020-09-03FILE_L1EHRFIWY56Z3.docdoc 739a1c9d08b339c2cf25d7ef2982c60dbc66611489e3878da793ccd8a19d6ca8Virustotal results 21.67%Heodo
2020-09-03PO_09032020EX.docdoc 1f6bddc9ff487e35f1a1961922465830f538914af66d1cde543512522b507ff3Virustotal results 21.67%Heodo
2020-09-03REP_U3MDRXHH3A5Z.docdoc 6448dfa84cebaa860897333da67fde04092fca4881363ec037215b2a168124ddVirustotal results 21.43%Heodo
2020-09-03V_82954406208966757750884.docdoc 4bd06982c449ac8aa6ecb108e03fba7be8d4f762de3feb18725f3bfd2c1e1a13n/aHeodo
2020-09-03REP_B1VR3JHM0VANVUB.docdoc f750bc2de2eeb95b5c7ee52fcf5b4b2398e778fcde63f85778805ff37753c83bn/aHeodo
2020-09-03FILE_305869270658424704664572.docdoc 7b5836662cba4f5fe9b0f77dfc795736f639e2a412e9ba770e1fecde78b55e7en/aHeodo
2020-09-03OX2603828754JE.docdoc feb68022d4541ffd2ac8ac987ced84820eff930b11904e21bd930ad75115981cn/aHeodo
2020-09-03DOC_PO_09032020EX.docdoc 45876e016cd5c003447e756f362f1d7b5a8b35cfaa9e8946cfe4507e8bc50a16Virustotal results 38.98%Heodo
2020-09-03DOC_7725654404869210796.docdoc 6c9fc30d18facaf2b4c12ece2295a651e742612c768cb2ea841fdd78dbf64eb7Virustotal results 42.37%Heodo
2020-09-03BAL_2KKX0MY.docdoc 0d0948aefd92e755b9d91bfd60fa4df0a21121965f4ceeed612c2fd6995a2b18n/aHeodo
2020-09-03FILE_7JGAIPTBW5CD3NIF.docdoc 0fc719a91dc87f9b6391f66625742ae104912cabe17425b6fab15e8e8aff5490Virustotal results 37.29%Heodo
2020-09-03DOC_3138979372234371.docdoc 0d0302e42e84b5c197fc3e3e92c8ac30a3e7a14db5b2b030c9d1814affa40652Virustotal results 33.33%Heodo