URLhaus Database

You are currently viewing the URLhaus database entry for http://tecmicromg.com.br/templates/balance/vzmq94099812161875k0jnlqdg1mfuiukdm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452607
URL: http://tecmicromg.com.br/templates/balance/vzmq94099812161875k0jnlqdg1mfuiukdm/
URL Status:Offline
Host: tecmicromg.com.br
Date added:2020-09-03 17:34:34 UTC
Last online:2020-09-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 17:36:02 UTC to registro{at}homehost[dot]com[dot]br)
Takedown time:2 hours, 18 minutes Good (down since 2020-09-03 19:54:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03P_76055680.docdoc f50133085cf408fa42e3568d8466e35d6ae2ceffb26ec78fc25041eb5e5d7c93Virustotal results 26.67%Heodo
2020-09-03OYNH_WP6239184825ZA.docdoc fbede719be1983fff9ca06d29412edfcfbac49c78901582ccf686c3f3e50e2c5Virustotal results 26.67%Heodo
2020-09-03DOC_07BPG7QR90TGGWN.docdoc d7dccaf606ccac241264d06440a58415ea545b955e3e2538954c3ab166c541c3n/aHeodo
2020-09-03REP_458527674899624.docdoc c1924a497d65fe1edfe3f41fa1f0010c8b39633a80994803811dba21f11e934bn/aHeodo
2020-09-0310312078.docdoc 5861ffbfd99c2436cd216d199a0e6e8017a643cb62bd4eafedaada809b02f759n/aHeodo
2020-09-03INV_4607727481.docdoc 45df584b759aeebac31b1c7dae71ed74a5711867e836b62aabfdfcf73e94d5faVirustotal results 24.59%Heodo
2020-09-03PO_09032020EX.docdoc 03d9aeb5a4238c8cf02bf8908fb5eefc7f88cfd9effa918ef5d9dc66a2d8e59aVirustotal results 25.42%Heodo
2020-09-03B_705753574296717.docdoc 70d8f24daa7b00f5210bbb7109a7b9975a0ad05c280d207f3504d82411c1bd83Virustotal results 25.86%Heodo
2020-09-03RW_87500062115.docdoc 65a803b10719f7420467e6a66a5dbe9f9dea0a8dada387e1022e3e3c8340f750Virustotal results 25.42%Heodo