URLhaus Database

You are currently viewing the URLhaus database entry for http://trampo.com.br/cbot2013/browse/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452538
URL: http://trampo.com.br/cbot2013/browse/
URL Status:Offline
Host: trampo.com.br
Date added:2020-09-03 15:31:10 UTC
Last online:2020-09-28 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 15:32:02 UTC to abuso{at}guzzo[dot]com[dot]br)
Takedown time:24 days, 22 hours, 1 minutes Bad (down since 2020-09-28 13:33:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23IDV_090120_TCZ_090320.docdoc 54db84a7eab0ad73dc1fd9b802cbea856c41d186a7ece87b0b2dffd42a9c1edcVirustotal results 69.49%Heodo
2020-09-03INV_GQFI08GN.docdoc 34e226cc8c168a37bf37367d93f797b8a5b449f27218a526e356a1da9deb245fVirustotal results 25.00%Heodo
2020-09-03X8LI416A.docdoc 1c8354b2ffd08c377bb61eabec461f1fbe0bd8e5a46aabe288066a665e7551a0Virustotal results 25.00%Heodo
2020-09-03IB_PO_09032020EX.docdoc 03d9aeb5a4238c8cf02bf8908fb5eefc7f88cfd9effa918ef5d9dc66a2d8e59aVirustotal results 25.42%Heodo
2020-09-03BAL_7LJXL35EXOVAI.docdoc 70d8f24daa7b00f5210bbb7109a7b9975a0ad05c280d207f3504d82411c1bd83n/aHeodo
2020-09-0349549579.docdoc 65a803b10719f7420467e6a66a5dbe9f9dea0a8dada387e1022e3e3c8340f750Virustotal results 25.00%Heodo
2020-09-03DOC_PO_09032020EX.docdoc 7f77b3b194b1c10f8bf8df9c595af942e2316862c4305b8ee4fd80b598b8f67bVirustotal results 25.42%Heodo
2020-09-03DOC_VV6417641556YI.docdoc 9346a534a8f4755997abec57f858bf8520dace47c7f3331030051311251d3758Virustotal results 25.42%Heodo
2020-09-03P969Q0UB.docdoc fa99ac815cb340989e6358014994fb398fd9d987628a7a218a4936d52db7d015n/aHeodo
2020-09-03REP_PO_09032020EX.docdoc 1f6bddc9ff487e35f1a1961922465830f538914af66d1cde543512522b507ff3Virustotal results 21.67%Heodo
2020-09-03REP_V73WJA8SVWYBCN0.docdoc c8977118b5d85e3a720b534813d511c2460e60f91118a3159b0c172258407ea8Virustotal results 21.67%Heodo