URLhaus Database

You are currently viewing the URLhaus database entry for http://tfbauru.com.br/cgi-bin/6Rz6fraVUF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:597896
URL: http://tfbauru.com.br/cgi-bin/6Rz6fraVUF/
URL Status:Offline
Host: tfbauru.com.br
Date added:2020-09-22 15:15:06 UTC
Last online:2020-09-29 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 15:16:07 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:6 days, 18 hours, 40 minutes Bad (down since 2020-09-29 09:56:24 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-267U.exeexe 74fb744cf4f40a7dccef03e89144a7b069174a78cbbdf6c9cea4c3a87d201fd3Virustotal results 40.00% Heodo
2020-09-235d3yzdkeeCqC.exeexe 7810e26352d47003d56d46dc767f542e76277ed4961f49c18268ba495d79d43fn/a Heodo
2020-09-23TmGSk30ZurIxhOns.exeexe 876b4bf41937d8fc1087973945333107a21325038c5871210c21e677fa2d970dVirustotal results 15.49% Heodo
2020-09-237hjs6GJ9lmrt4I1.exeexe cfa55e1fe3daf918ac9e7d065f7f0a8e57301b700d8b8df57f8530db17e37ccan/a Heodo
2020-09-23xQUOvGc4nDTx4XdVOPb.exeexe 5db53e3646d292cb5936430d0dce04fb9ec594bce14136db14804df27783cd47n/a Heodo
2020-09-23WvlA1pXGSZ3aG.exeexe 631eb7d2023469d937a9b38b7f60c2a121e44cb4db7ff0951a0baefcaa6e8bf1n/a Heodo
2020-09-23tZVW3zhMdzTiy22xNG6.exeexe 96fb367700ca895613fb73f83773272beca5a979a7905e793c4572dae6926aban/a Heodo
2020-09-23JEiHCItvCzRf13bm.exeexe 0727d784983dfacc783faa78b4c4095eaadfba463b32587466d85681cdad19bfVirustotal results 16.90% Heodo
2020-09-238SL9xkM.exeexe ad536f95ab1be26b19aafa1b700f8cee6bd60fb1324025610f110eaf16c95995n/a Heodo
2020-09-23oeyXdAaIjI.exeexe ee6784a0394e439b8d936885cfae3f7c8dbe2df441c79e5874e1f98a7ee11b2en/a Heodo
2020-09-23XX94lKa41.exeexe 5e53218e72d3cb799d3b011c2300db466073463bea2d6152c1d5d93eda374565n/a Heodo
2020-09-22O2aiiC2F5iNv5b7enq.exeexe 82cd0101f7341f50a59f30800326a6d0efd6463d1a069e599303fd6a0f4875efn/a Heodo
2020-09-223spMnaob.exeexe e1cf07dc72e75dc82d7ddc3b817ff5ca177030d92ee07972ef28828e61501fc4n/a Heodo
2020-09-22ZgfTdr49YDvpp4U7.exeexe ae2cfd339abd9a526ab202058b691689bfe5248037074356df6b18e0b4377f0an/a Heodo
2020-09-22DnA1cQ71sJ0rV7.exeexe e036bb64131d0fdf9ac088ec4f1bff3bda6e19b794e08e0017a06297665da89cn/a Heodo
2020-09-22cIAcrwsQc.exeexe 096da092fcf218978e08a36fcea6a2bdf46e059ad6bfa0f0add3ac18fe135e1fn/a Heodo
2020-09-22rNTDP9RH.exeexe 7a7430902ff7c267512c330aada4ed9d970e57900086da580a8a85e620cd6fd7n/a Heodo
2020-09-22uBAPto9mHH7.exeexe 13e3f211648d8ba3af19df75a296351684227a731731b2843fb8f0d304232bf4n/a Heodo
2020-09-22ywM5gdbAwmSI9r.exeexe 504a036576a6fa11534de1f4fded132061a202c5d045bf82e753aac75e2702a3n/a Heodo
2020-09-22WNGVYRm8.exeexe 66cbf63f7d2f73d5e8174a207664e0c9bb299273543ba33158fb67bafdf714c6Virustotal results 12.68% Heodo
2020-09-22kiZRYxBL7DYhx20lrJHH.exeexe 006af7c46cf6f5e86809602ed212969830db18cb20df245dca877e25e276b4b2n/a Heodo
2020-09-22A2Ru11WY.exeexe 7097c4131ea68a660c5f5b6e71900c46a40515d69ae0a52c9abe35567ce3f012n/a Heodo
2020-09-22sPSPJJOhTTmgPUnNDIZD.exeexe 9c4f6ef5f2e764f35c8b0729a9f24d1aa8823b3a3df41b20ae8ef8437b745902n/a Heodo
2020-09-22FzHm4aX.exeexe fc2d4079b126c1b9c30f3fc01adfd6edbe6d9fe49fb03b5576aa2e59a78eb33en/a Heodo
2020-09-22NYXAN31ZstQgW.exeexe aae25bddcb865af38d262aa26e01e78af76cdc2f782b9633595a7e4e33e99ec4n/a Heodo
2020-09-22FKs6YJR9grI4iZnY.exeexe 0455c921a4ff7cd93f24532e6799ea7c2ba207dc44194c6ea27ef878ae7315e9n/a Heodo
2020-09-22x.exeexe 6307bde48b65e73bffc9ab873085f53a7beb6044cad4de8cf7125b361e6fba4an/a Heodo
2020-09-22AmDR10ScOhqcQTc3GP57.exeexe 689cd648cb102f93cb1fb7372a8a377d5c2c486df811acef0b0cb6b53ef05856n/a Heodo
2020-09-22OEpeJHaE9nlpdF3Y.exeexe a80d177bfe21a5d3a12ced46bb37ca56936343a46faa056624a3cf72c3a2d74en/a Heodo
2020-09-22VL.exeexe e66f471d3e7a50338c9663869fe655b688bd88c2275bb2e9cced563818ae5661n/a Heodo
2020-09-22rlbsGlLtVFFkINft.exeexe c3b8ed01ee78f2f8acea80524fd74dbfd927ea9837779d07cfd6c76b471adf46n/a Heodo
2020-09-22IAp.exeexe c31e116c0fcfcf57f53d7c048369195296796121184bdff7d63c601de1403400n/a Heodo
2020-09-22i.exeexe de63f9ec586ddf9059f93a3d0d04c9b448b97146eda516977aed125847c58d32n/a 
2020-09-22E.exeexe d36b124148daa069213e0a79123e0bb9692fce0d957c17941c59b4cc8b21155fn/a Heodo
2020-09-22DC.exeexe cfc4136182bcd4c247c25181e444f0c7a4edc2e7090850520e074bfab981ca66n/a Heodo
2020-09-22X2lU2pIfkb337olCHUw3.exeexe 67f9cbd12c4f86ef1732a335aa25ed0e051f46140d3c421ee5f1f0da2d600e99n/a Heodo
2020-09-22bRlYSYB6f4Y5cSbP.exeexe ae76d54850f32b770ea2c15f39fc700f5068e58c08ca16a63de6790aa363ffd0n/a Heodo