URLhaus Database

You are currently viewing the URLhaus database entry for http://cfcalda.com.br/Cebalrai/1980039_806941/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1977587
URL: http://cfcalda.com.br/Cebalrai/1980039_806941/?i=1
URL Status:Offline
Host: cfcalda.com.br
Date added:2022-01-14 23:49:04 UTC
Last online:2022-01-17 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 16:12:22 UTC to abuse{at}locaweb[dot]com[dot]br)
Takedown time:2 days, 16 hours, 37 minutes Poor (down since 2022-01-17 16:27:33 UTC)
Tags:ArkeiStealer link doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-15yBIis_0499.xlsmxlsm d8c07f93d53cd970c597ff94a8dc92c5b0e489a7e0489883fc86a4bd6d261f27n/a Heodo
2022-01-15JNK-21918.xlsmxlsm 40c5e372942e0b9b1ddd00e203c67676f96fb761373fbe9bf108613a593ee57bn/a Heodo
2022-01-159432379030323439.xlsmxlsm 522526a909c7830228db68321ae6698da4f7d3db52f9056a5d69620954d47b89n/a Heodo
2022-01-15GSMSV66.xlsmxlsm cd6f78b09ca63f714facbcfe21b27fd3c031242e28acdd1bcf6156719b76a9f7n/a Heodo
2022-01-15zpojm_002.xlsmxlsm 1e26e9f4adb67bd88974704cc63f90f195aeda22dfd68e4d7eb9ca4ece0d1d63n/a Heodo
2022-01-1529564620263.xlsmxlsm 295b5684fd4d6da1bb6287b0bade91c880432d8d299e7788a254c9c9738dfcffn/a Heodo
2022-01-1594034KAPQWVY_002.xlsmxlsm 6c4e9288c11bd332eca6874187898648c605529694355f2a945ddfe0aba788a4n/a Heodo
2022-01-15m_76.xlsmxlsm f598b21f793991155297f197efb6282ea424e9c846ed97cb61f9e2e2321ef57fn/a Heodo
2022-01-15Fk_5271999.xlsmxlsm 9324abc8d81187724943e9372969e0559ecc4f2f9f976258bd59078bdb74e9d9n/a Heodo
2022-01-15SE05217051.xlsmxlsm 97a7bf62bcd75bff44e2ec53cecbfb4be386b7ef16c983ca0c5ac1733810f284n/a Heodo
2022-01-1521375320898.xlsmxlsm 0045b20232732fb2c4598671f7d31824da64275a796b6da748355d3aed6af989n/a Heodo
2022-01-15B01873.xlsmxlsm 87a3b24117e7f39be9bcfdce77aeb0bdc0bdd0c7a6b6a508d4252d8d547f68c3n/a Heodo
2022-01-1538-03095.xlsmxlsm 92b75d16d13348770c16fac4253587736d813b5be5efc510d13adbe505c3019dn/a Heodo
2022-01-153023443966.xlsmxlsm be5993172db9a317aa35439a8c21a5ff4c2a5f6ce238a32d71ebbff993a2e7bcn/a Heodo
2022-01-15O_021739.xlsmxlsm 6160bd3b3820942851b4c56066611bd4c01ac70d8a520be8e9abff7f3aff45b7n/a Heodo
2022-01-156565CDJIPVG-79497.xlsmxlsm 100411c1d9d483e285fb39e5aa3a00df0433e418629428d90b9f9a7f9e393735n/a Heodo
2022-01-15870851_85.xlsmxlsm 62339184034e6ad69c9803d78caf51eb93963736899000a79763942bdb54b751n/a Heodo
2022-01-15F_74.xlsmxlsm 5be4fdc379541be75fda56d996fd5380b4f68fc14a295a5c39baf258f67636c1n/a Heodo
2022-01-15DYT_5.xlsmxlsm d60a0d354b47db9947cccf869113e1fc3db29e6dd52da4de97e3f597c8413126n/a Heodo
2022-01-15DK08565306.xlsmxlsm e54c7e04ad7a623d9ef4cf30a5c8cd0eaa26f3a162d3e64bb39e9c755d8f839bn/a Heodo
2022-01-15l_4901.xlsmxlsm c1a965ede59ecf82604f9e28dea05524ca8c4c5f826c417c629bfbd5cb21602cn/a ArkeiStealer
2022-01-15OIPV-09522945.xlsmxlsm e869f1f1c15fc3635f603c1f201e91c4d4fc67e27d48fa526512922a2dfa61acn/a Heodo
2022-01-152225-69320151.xlsmxlsm 88184fd50c3237c5420e39824ef12f6d3ceac1fbd74e9e7875c4649b9a8452bcn/a Heodo
2022-01-15ol_076124.xlsmxlsm 9f593a4d8c3165dc5052f06fac8f6bc92bfe45012131fc75cf27ec63ce1f3adfn/a Heodo
2022-01-15OKF83.xlsmxlsm afde85c0f3400cdd70d59c378196695e4b64b7b6b559a7d481e1679f0dd8ed09n/a Heodo
2022-01-15y_02585192.xlsmxlsm aa3502e81f27a2ae1486354bd438bb082e23fdd08f5e35defe7a676ea7631c7fn/a Heodo
2022-01-1587606MXXMIXPV_218224.xlsmxlsm 865eb35199ab84b4cefee238e23662fcde705cdd1f89fa2e8adaeb2cd4fe13a0n/a Heodo
2022-01-15YSNI29647370.xlsmxlsm 65e1cc84b8a1679ab3c2e79303871473cc6de700c9557e8f61ea1cf619652e66n/a Heodo
2022-01-1596528927.xlsmxlsm 5f18c310f5253557bd4e3db65b76f929de0a63e9228508432f417be214cb1c6en/a Heodo
2022-01-1598339-46423.xlsmxlsm 18407ac6698ef4bcd8d03f4a6e0934e0f737014d3da7b8b9f9573aff85531e86n/a Heodo
2022-01-152373-9529.xlsmxlsm dd2c0fe2695c9a23678226e60228715951f3a61a3ee3dd18d36c9fd420c88647n/a Heodo
2022-01-15myNusL_31768201.xlsmxlsm 7b13a221a0b62f54ec6947573c797094f113558c1bc574b6bacdffe3061cf72en/a Heodo
2022-01-153419XPVGNSIPA2537587.xlsmxlsm d0209810287321712b7d094dce723b36cf1fdb8258c3b3c41b49b7684f854983n/a Heodo
2022-01-159365961_80.xlsmxlsm 45196a61f96ae34e0ca6711e70e1412b212242e79d3b0b7a32541cfda6938eeen/a Heodo
2022-01-155757WRL_808.xlsmxlsm 6b905847ed946ae2b8b8e9425995c2ee708464f8c6d0a0c2f5282dbcc79012d8n/a Heodo
2022-01-15988IUWUEXMXTE29682.xlsmxlsm d956d51c896100523138bc649194b56fea4da4499f148db37930b4b2aee39101n/a Heodo
2022-01-15Fke_9.xlsmxlsm a74e56368e271fed755aa1071a1286036351e04358f0707a7f062d2d18457874n/a Heodo
2022-01-15pFjlt_7.xlsmxlsm 44b990e0cecfdbce9a3071b4b5a23cb9bfd7fbccb6fb5eb267b229a822c932b0Virustotal results 35.59% Heodo
2022-01-157751536180940725.xlsmxlsm 62ee016f8e7b7c66a4b5ce151a267bb09faf53130401252a9f11a024c14f6e13n/a Heodo
2022-01-1524780NDFTASSRT-8459742.xlsmxlsm ebeda5ef741664330d003f71df80ea940d7bb7a7389f4a4ec325eafc01b34a00n/a Heodo
2022-01-15SYZX-153.xlsmxlsm cbabf31062db7ba965fddcf8a0309fd8f045f20c5fd0baf6d086f52878f0ed03n/a Heodo
2022-01-1572293_10375567.xlsmxlsm d90488474a115987753f7d96f2810900bd6abfc52ac05aeed67710e18e0314adn/a Heodo
2022-01-150476_3138.xlsmxlsm af74adf2376ab0a8fb16735d44fc3e72bc4480a91b2cf9de85cd2f9ab7fe1fb5n/a Heodo
2022-01-15fDgx_242.xlsmxlsm 55609e9411de2aa6dca0995747f89cc0b89081e6722e497433da8f8d02e9a2f2n/a Heodo
2022-01-15hlo0349952.xlsmxlsm c909891cc6ab3148cc2e5af0f42b18f4fea635079447729eba2203ffdbdf32d4n/a Heodo
2022-01-15L66210.xlsmxlsm 7048b590b47e71cb6a20b35c192d264bc4bb1fb4213dbb9a9a2c9748d53af762n/a Heodo
2022-01-157575713_9.xlsmxlsm 1f93c92652672883150a833d6bdfdf434bde9d61121c95b4a0b77740afa8479cn/a Heodo
2022-01-157280078_7390726.xlsmxlsm 2966763dc88ba44de5f3aa8ff82addad4bb4b567bdfe60a067f169098258c418n/a Heodo
2022-01-155013728420.xlsmxlsm 0090643800e1f49a41801bb84916471fe71b2778e2cef65930e5b25b3c62fc8dn/a Heodo
2022-01-15O-95605360.xlsmxlsm 7a75b8d2c5567ef0c4fc7270b77c7deab2f2a81ea2f1b969f66d680a781b5065n/a Heodo
2022-01-15B_17.xlsmxlsm 0400c5d7c8ad85387bca95f3beb4be0b192f8a53aaf64f60e631ac66c60b5504n/a Heodo
2022-01-15CMKFG76796013.xlsmxlsm 3621ae028dccc8403535f79e18471a4de1256cf06f3c96a94be537d833856eb7n/a Heodo
2022-01-15944744_9537404.xlsmxlsm db676ef714ea818edca3ff4a25da38808cbec2a6d7b944a237e44ad29d8932dan/a Heodo
2022-01-15rzri3710.xlsmxlsm 27e87e375006f747c439d7ee9faf69843cc289ff75a5eb062abbea47c57efcacn/a Heodo
2022-01-15bgzH-5.xlsmxlsm 771e8eb9454d09d3f655f55713b1791583aaa6f813d896737b38d1da511fcb15n/a Heodo
2022-01-15308-00999.xlsmxlsm 1f7a5f12dd0eb712be2e7b1743244984f5924481524eb1c67cac97df0c34ddf2n/a Heodo
2022-01-15SBCW-5.xlsmxlsm 3abfe866becd4133977aa353ac9851353631d67be57d77cd85419f68a31b3f69n/a Heodo
2022-01-1514540UEEFD1140.xlsmxlsm f014c3cac6d68176f89eb8ef0db783db62cfc98945c8db91868cd81e7d35d0a3n/a Heodo
2022-01-1564539800_6676784.xlsmxlsm d18ee35b037d473e3ef71c9d7b34e4a758b27a2ac27316621475b6944e5d453cn/a Heodo
2022-01-15359178855.xlsmxlsm 17f92479a5b8f4bd0e4ea0601f49f3d43a2998b0fe44ad764e298f6fd561074dn/a Heodo
2022-01-15HZF-85481655.xlsmxlsm 38e63247da950af1a3a96864cef46f801d99fe847c9cfab2022dd1bbfd969247n/a Heodo
2022-01-154733368URATFQ93.xlsmxlsm 26261f6683880339a902fbe83bf577ff5656ba5e8b1b274c694a8a2f31a83346n/a Heodo
2022-01-156253728_23161.xlsmxlsm 591d03b3f9091387f618bff8ca7227aa4bfc2f067d0998bcdff6eae0100093f6n/a Heodo
2022-01-15K3.xlsmxlsm e62b1afcd868f8c63de24e95a7dfba574753d0994b52a43cf8c5ebfa5307ad55n/a Heodo
2022-01-15WNAM2905.xlsmxlsm cb4c5dbbee1f1653eed8b827a21e3fa88287d21705406cdce8a01c9c656c00e7n/a Heodo
2022-01-1514BULCHSG-8607607.xlsmxlsm 2be1399fea3ddc5100d9db00c032832fc0e5bcb2033f1a733e70fa60b2bd1896n/a Heodo
2022-01-141980039_806941.xlsmxlsm 58c5a6dff8387b84e6a6ca1f13bd70239ba82cf9f620483cf0d28792c93332ben/a Heodo