URLhaus Database

You are currently viewing the URLhaus database entry for https://getwood.pt/ot2lu/WNae9Bzh5NlAK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1919441
URL: https://getwood.pt/ot2lu/WNae9Bzh5NlAK/
URL Status:Offline
Host: getwood.pt
Date added:2021-12-25 07:34:16 UTC
Last online:2021-12-27 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2021-12-25 07:37:15 UTC to abuse{at}ptisp[dot]pt)
Takedown time:2 days, 2 hours, 26 minutes Poor (down since 2021-12-27 10:03:20 UTC)
Tags:emotet link heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-25Y77016793004.xlsxls ad703c5d173ecc9110d797f3272128d0bd21745acd34d207171021b8f448c5b3n/aHeodo
2021-12-25N181751915131M.xlsxls 8f88a28c7f2df1bd6f098133627ff35d04c6ad34062a69b07d6ec70fb8853752n/a Heodo
2021-12-25F04818174354B.xlsxls ae5fffd3376b48104fce4b5b7d2e560121fe0fadf87af15fb7b817ef722a2e0cn/a Heodo
2021-12-256213826.xlsxls 7e13df6bb49cc4fe531e1c7bd93e2edfaff9c7640f7aca6dfbd8a58c61859194n/a Heodo
2021-12-2565731975265.xlsxls daa68e5e2f2b4e276da3555000b36a79550ff35a611976ffcdbb026a3efba7b9n/a Heodo
2021-12-25H09316984048449.xlsxls a56da39c9dc097c0ce0b9f4b152eaf51130ee318b41ba18cc4d30c5fb82df45an/a Heodo
2021-12-25I4763741682.xlsxls 8b99666a8dcf18891e3e33f1f5e1ebc076e8785ab2341561aef9234363dd1dc2n/a Heodo
2021-12-258122278Z.xlsxls b065259b68e96859cdcbb55267d6c383f3c2e8d402bec89dbde0140297f0ca9dn/a Heodo
2021-12-25709072604569832.xlsxls acdf5002ec4be1d844d1d4dbfc55f317f00bddf3f5e1be17a1ff9467fe0368acn/a Heodo
2021-12-25B23760576739228.xlsxls 632b61f81c01d6135b1ffa49ef4a4ea84de9f9bd4276e8f95432d73494453924n/a SilentBuilder
2021-12-253077975521H.xlsxls 8b2064c83ef2072bff59d157b7f91ec7c495104914b59a7a198fa5f4a68ce1b4Virustotal results 31.67% Heodo
2021-12-25I44523747668.xlsxls 34290b3ae2a956806dc148aece513c9725dee43e505a78c16258027559f730b8n/a Heodo
2021-12-25P2184894028.xlsxls 1775e7aeb9267cddf4c8e559ebc41acab8d179f455585755b1367e61256a0599n/a Heodo
2021-12-25I0749015912621941211R.xlsxls 08ddd0481e5d8832723d76e74f6a28e6e41f0e6da6461e861dd66e026928e9d7Virustotal results 33.33% Heodo
2021-12-25M43374183761039Z.xlsxls d640ebdaaace549312d95a4167f80ca760b80bb315e64a8c64df46b8a138708cn/a Heodo
2021-12-25C8513763176.xlsxls 3376e19217606a18ba6d654812ead2af32fedd5aa72442b859aff27886551aedn/a Heodo
2021-12-251654602601086557.xlsxls 360d25029702893dd622b095661272c41893845441a5ee85119b97517435c265n/a Heodo
2021-12-25P43786314805063110U.xlsxls 834b1c1fffb6970a71c8b2b95f85a403122ea56f2c4d5425ae6ed56b59f776a1n/a Heodo
2021-12-25907321216374225V.xlsxls c3700ae6cb069ec98acd080a0051f4bbe8bf2b869cfe616be4344b9f1506af84n/a Heodo
2021-12-25509356454.xlsxls f61a8e096979c8bba90fe19423377e9eba4b24587977e4a77d8e87fe45239c15Virustotal results 20.00% Heodo
2021-12-25I385567320069Q.xlsxls 5f8a6b7049df4182bacef894f204054ddd268ade96b098bdf9f4e5545b861182n/a SilentBuilder
2021-12-251663765569295.xlsxls e7adef6649e8c908d91ef57cfddb2cda91bb34bcea31f626734ed30de0de2186n/a Heodo
2021-12-25B885605348661917660473.xlsxls 4f53b2aeba2d6f846f1c9a8066efc63aedaf6b213108ad80e27211255a861ba2n/a Heodo
2021-12-253791840772103985.xlsxls 767312b89f882c00b45884b8901831ec45fdb8c03d73d9be10ce4f6aa2a764d8n/a Heodo
2021-12-2583600316F.xlsxls b760933090f11cf4e5819480a57fac195060a494fa8c570174c64b8689164a18Virustotal results 31.67% Heodo
2021-12-2512592580452976206797T.xlsxls 203642f63c7b2d39cc134797070a502a04d76aae58d190c9c6b5437e15774172n/a SilentBuilder