URLhaus Database

You are currently viewing the URLhaus database entry for http://www.toplevel.com.br/medico/FILE/8yrua11933006500180481h7soysxzpzyexior/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:535170
URL: http://www.toplevel.com.br/medico/FILE/8yrua11933006500180481h7soysxzpzyexior/
URL Status:Offline
Host: www.toplevel.com.br
Date added:2020-09-16 17:44:06 UTC
Last online:2020-09-16 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 17:46:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 39 minutes Good (down since 2020-09-16 21:25:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16BAL_795996065409.docdoc 6d27f5af653565630751a1ab0faa64d0c28949cfdceef04b4c543a0b4a7666f3n/aHeodo
2020-09-16DOC_72594638.docdoc 1ecaceaeb20649c823b3a63accf639925ba8e4c350b2509496c04dbd622d5d4en/a Heodo
2020-09-16FILE_CB1685977886LO.docdoc b2bfefad5d4d6a3dff230f61a9c4b055d5ae4b37b8fecca5550317c89f615504Virustotal results 25.42%Heodo
2020-09-16BAL_4Y9TT14RLK.docdoc b3f921be965718a9741b8f63d9b29dba0345f98cdfda7a0cabae90ffabc8043an/a Heodo
2020-09-16REP_MC7879930059UJ.docdoc 73158e3c574c5cfbe98520ebb3b8c4270609205751d997b87414e5a43980f960Virustotal results 24.14%Heodo
2020-09-16INV_BTAIAO7NNYM2L.docdoc 7cad27b68df51d87f204a171a2f75a578b52e11f339a2bab138c6ada02b5a196Virustotal results 25.42%Heodo
2020-09-16BGBS_VBJ_090120_JUN_091620.docdoc b4cce609ab6c293e6ad8ed80364498a96ac56579987b2aa30c0a6d05df102435Virustotal results 38.98% Heodo
2020-09-16BAL_OW3516985941FD.docdoc da87185fb8a79bff00dfd7aa5d3a7798054a8b1c882b4a25180cbac2b863f2c3Virustotal results 40.00% Heodo
2020-09-16U_9266077270.docdoc 679e5f33c444b178b0da6da41a58b4590f05e7c464293e3b1d8f858dbe157124Virustotal results 41.07% Heodo
2020-09-16BAL_4H2APMWUMHPFMD.docdoc 9c5ec196eabe90d83815fe7015b5334c7fd6bbd350de085a69e022a0fc32ad8cn/a Heodo
2020-09-16DOC_PO_09162020EX.docdoc 89e280d00eba5184867b52270ea583f8bda9161dcb52921411e456747741e571Virustotal results 38.98% Heodo