URLhaus Database

You are currently viewing the URLhaus database entry for http://www.toplevel.com.br/medico/RuFF8m0jqCTqU81JIEynpDQgNvyD9JbSYNPS04w833jj9JcAdfZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:955755
URL: http://www.toplevel.com.br/medico/RuFF8m0jqCTqU81JIEynpDQgNvyD9JbSYNPS04w833jj9JcAdfZ/
URL Status:Offline
Host: www.toplevel.com.br
Date added:2021-01-12 16:43:07 UTC
Last online:2021-12-23 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-22 10:51:32 UTC to abuse{at}bluehost[dot]com)
Takedown time:11 months, 15 days, 0 hours, 20 minutes Bad (down since 2021-12-23 17:04:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-11VOR8BK3F6PM2.docdoc 841f665e7fa0dafb08a148c375fc49b0594eecdf01d44cc9b7ea8e6c6b5fe024Virustotal results 77.42%Heodo
2021-01-12I8SWPD6.docdoc 10ca32d172e5dafd7c07e4e27f6c6a24bbb6af319a78a66691b819532b1d2dc1Virustotal results 28.57%Heodo
2021-01-12IGU1G5X4N3DROIEN.docdoc d9942c14d06f8723dec0e7a052837f0d09fe1787cc4a1ea50541e7b024ea61d7n/aHeodo
2021-01-12WG9WAFHUMCCZ.docdoc ea15333718da30cd14831ef2f6e03e385c16f940ec5ff6d912e6d084af7d0c00n/a Heodo
2021-01-12SQBWSQAKSG2MZ.docdoc b3c4491c50e776c893a66adb0e906344dd6d5172d724e8baa4946c5d69480bcfn/a Heodo
2021-01-123FA1915ENTEYHG.docdoc 3fbfae79bf1be85a61f75e7d23e1864ef66662e6cc7714bda2072feae62dd902n/a Heodo
2021-01-12IDWPYSATT.docdoc 6accc97a530bd44453afbef50abb762dc580472d982b3765b7b00454b79619f1Virustotal results 26.98% Heodo
2021-01-12MLZB5C5CS.docdoc 8a99bdffa2f24890df1f03cb50240114f36d3875f55efdd66e96607c9f90ea8bVirustotal results 27.42% Heodo
2021-01-12Y3HIZXBB25999PO.docdoc c2fef4bdc14979551a0b11882260d323a310c23c62b39a6007c07ba5b560c53fn/a Heodo
2021-01-12XI62XE5V5N7CQC8B.docdoc 6bb1fa2cba1d52674b980804939a39bb7dc3a68a364402d393e6a3ae520cdce9Virustotal results 26.98%Heodo
2021-01-123X86RSDSB96H.docdoc 8d32d6bff786b4ce680f4e1c12069b1c2dc67f84ba3dff682f55ef28422fd91fVirustotal results 26.98% Heodo
2021-01-12A8OOMCCS.docdoc 6eb5d45c6dee2a313d3cceec884dcf63f7c15f491b080da54730f54c07d6a6bdVirustotal results 26.98% Heodo
2021-01-12T9XNIGLABAXR.docdoc d31c9450665db61c8e1cb474bdece65637e84661805a8f55665159c77bfdfa5bn/a Heodo