URLhaus Database

You are currently viewing the URLhaus database entry for https://grupostt.com/Categorymap/INC/FfWccLPLeG0XqS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:750736
URL: https://grupostt.com/Categorymap/INC/FfWccLPLeG0XqS/
URL Status:Offline
Host: grupostt.com
Date added:2020-10-26 08:49:04 UTC
Last online:2020-10-29 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003034688 created on 2020-10-26 08:50:06 UTC)
Takedown time:3 days, 13 hours, 13 minutes Bad (down since 2020-10-29 22:03:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26Attachment.docdoc a71b3a986a9ca1ee5170f891348a8553af640d554b3b578b71bb80eb2e5bf935Virustotal results 35.85%Heodo
2020-10-26doc-2020_10_26-NNQ253.docdoc 5c37b77c7f6e4cedce26a757d3eb71bda296bfc32490713789ef1724b0a38f1fn/aHeodo
2020-10-26REP-20201026.docdoc 499873b64612e9b7ca3b2724e0eb79f68532bdf7cb8527d5b3328bfbb5ebdd2en/aHeodo
2020-10-26Rep_20201026_IF8103.docdoc c854591c30dd20a4c6b14791ce0ec5cf30d24fa0305b8862dd1a10f255b64e94Virustotal results 33.33%Heodo
2020-10-26791AHT-539312.docdoc 8147739aff1074f3aa45f6505332f254c1d2750f1f4cdf2047acc545a8656032n/aHeodo
2020-10-26FILE_F8166.docdoc 5997e3c32bcc3a6e5f160f819589680d30b890f4fe2faef068e92c7deeb02685n/aHeodo
2020-10-26file_2020_10_26_9408.docdoc a9aa803b3c3f9f462ec1bd17a2380b956e9872f917bf9a7232c1a96c6aba68c0n/aHeodo
2020-10-2609852G-2020_10_26-RY640107.docdoc 6e10d04f75eb03084b24cc9c1d08bf78c573375fdf35af45724038245061e11cVirustotal results 35.29%Heodo
2020-10-26ARC XUJ284796.docdoc 5bdfa0c917624bd7de8b3378352e10dfc48b33bd79c14f27cc5b3e9dfe1d1ed7n/aHeodo
2020-10-26File H68397.docdoc bb93640e7a962d06bda3911de02f559229a6bff1cbe867bf5cd47c457b69064dn/aHeodo
2020-10-26MES 20201026 65032.docdoc 81c551477e20018dc6980134d9c3e9f964fd1c50ff65ac4e0ed7e6471aa058e7Virustotal results 29.03%Heodo
2020-10-26list 20201026 N96306.docdoc 7440dda8e555e9035377fc29f2d9172549267ddd4e94229023c0109b5d2d9e2eVirustotal results 32.69%Heodo
2020-10-26inf 20201026 Z7798.docdoc 448ac203510436aa6fb70c37c6bf2d4ed7569e681d6d3f27512fde7a1fd0990cVirustotal results 28.57%Heodo
2020-10-26FILE_XQ86754.docdoc b9fc022daee293920cbd24996a54077b6c3492d2acf2940125d91c00d1a080edn/aHeodo
2020-10-26LIST.docdoc 65b185e47d9fa98e4c806da6b3de32659443f638f9044da783976ad16917d4a7n/aHeodo
2020-10-26mes-20201026-YZD1869.docdoc a95d76e7de33604c21ca0ae2b22b2515d5f809b3431a70116bab4040d8a58fcbVirustotal results 29.03%Heodo
2020-10-26rep 20201026 HG76418.docdoc d6f7bdb1b5ff4287a1bb5679161b98f7941f0091197b37d04fba163501754706n/aHeodo
2020-10-26MES_2020_10_26_999.docdoc 7568f48fe0645ea9cdd165c0432da115295430c4e8064301c518360ad8153dben/aHeodo
2020-10-26INF 2020_10_26 37841.docdoc cdaa8083ad98d4428f440e3983393841a1f33fd12ff7faad18b086ba96ada9e4n/aHeodo
2020-10-26dat-2020_10_26-029.docdoc 7cd78f0dd2838afaf16e0a384bc676b109d168f0897e94118224c33618e8f18dn/aHeodo
2020-10-26MES-2020_10_26.docdoc 65c041247137b7d9c65793ffa57b76456395fe67c3c05c88529df1782f93e13an/aHeodo
2020-10-26TBP23724-20201026.docdoc 9762f0902c126e23616e568584e425bc839fdcf0b75e9fc97500df619ae00c26n/aHeodo
2020-10-26Doc.docdoc 9af2f05de765a45971676b59ecf0e914ab7bd8f58efb309540daa8f547516314n/a Heodo
2020-10-26MES_20201026_TBM49341.docdoc 30bc83ac54af7daaa68b9ddd196573bb37aac565bbc36b08de6b982309510bf2Virustotal results 27.42% Heodo
2020-10-26file-20201026-VZJ857.docdoc 89bf3f020a319d280f23c2d73350b2f27605753475a51c10ec6dfab4393a5a40n/a Heodo