URLhaus Database

You are currently viewing the URLhaus database entry for http://ftp.cgmma.com.br/erros/RikCkT6uYJR1l3aIdQvlJuY6Zlko/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120608
URL: http://ftp.cgmma.com.br/erros/RikCkT6uYJR1l3aIdQvlJuY6Zlko/?i=1
URL Status:Offline
Host: ftp.cgmma.com.br
Date added:2022-03-29 21:51:07 UTC
Last online:2022-03-31 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 21:52:07 UTC to abuse{at}hospedagem[dot]net)
Takedown time:1 day, 23 hours, 4 minutes Poor (down since 2022-03-31 20:56:07 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31AI-9271297.xlsmxlsm 7ca9c48ab76e34256ebad65fa28f1eb8b3da601b413e19e03a1442046b3aefean/a Heodo
2022-03-31CT-56725791685302.xlsmxlsm 75f0362196443080531377973dbab9153eecc5ae78da6a2e94b492580d2bdf7an/a Heodo
2022-03-31MRZ-00120752973.xlsmxlsm 896ef5fb12bd10c84fa96213d6a86aa368388e4806b9c882fd601a113482ff74n/a Heodo
2022-03-31AR-7535568702.xlsmxlsm 36828e7a04990e1d0b2b67ccfa64ea170ff92c77cf92107d904f1e106c1d676bn/a Heodo
2022-03-31ZKB-2826500534486.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31TM-7039440907.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 43.55% Heodo
2022-03-31YIW-89331515.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31BH-436647064475.xlsmxlsm 2e1db4578a7534abbaeb0e65b01b0da5024a9e27d99c3a9b29b03cca35b3a096n/a Heodo
2022-03-31XT-495082566291.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbn/a Heodo
2022-03-31AJG-417617484128308.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564Virustotal results 38.10% Heodo
2022-03-31UV-06281817.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590Virustotal results 36.51% Heodo
2022-03-31RBF-56362546674439.xlsmxlsm 4f1ab8d0a0a6f8a7964b32b8a4bdd94bad95e6774501cf7685028a40efc761e2n/a Heodo
2022-03-31OLX-57336440110.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31WA-56582326.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30HS-934285446.xlsmxlsm f6d9028f6903f57570a969a97a510120fa11d93ce778cfeac61862c36d6b6bd2Virustotal results 38.98% Heodo
2022-03-30KLZ-623965087.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30OI-935653166752304.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51n/a Heodo
2022-03-30VR-904125863574830.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4n/aSilentBuilder
2022-03-3014231757534441006194.xlsxls 00f6421fe8f4847be025bde29b82ccb92d3bb76d95ca4d36c6b87d9f173d3d01Virustotal results 26.67% SilentBuilder
2022-03-3090282215638915557.xlsxls afab90f284e5f643a8fa8a6eafd154175a22394254db310f0dcddc607a5ed468n/a Heodo
2022-03-303565757172960.xlsxls de03ab1d198136ce8f5fba27d87ceed99696fc46da6cb9ce7614b3824e02dec1Virustotal results 25.00%SilentBuilder
2022-03-3002045206293.xlsxls 248cd85fd7e892435c33370e5ac93d3fe53595ae7358e2e12af1e9f453697513Virustotal results 25.00% SilentBuilder
2022-03-3017849784761870414519.xlsxls 108d9a103375064db77c645ed840a5f24d0211c046985fda1898a464c31a742an/a SilentBuilder
2022-03-306132280563.xlsxls b2565c24c9c72461d71c25df5d6ea291c53cd27725217f8c6585653cbdf72648Virustotal results 25.00%Heodo
2022-03-3010891788508767828.xlsxls 82dd13809bbcd68f4c4cb0b98c2c979c8275fd86dfaaeb01eb3c1e17d6a3d990Virustotal results 21.67%Heodo
2022-03-3089286987764578032315.xlsxls ebfa044ba6f3aeb955776b3c5565296472f0f8f6ed2dbb78c25c87f8107de4f3Virustotal results 22.03% Heodo
2022-03-3092565748810278545.xlsxls 51cf8f6f736263047c2f947bf40da516a3cf74cefce2f1aebf9b5a71406b2f51Virustotal results 21.67% Heodo
2022-03-301671286875363.xlsxls d2bbd8120515b265d888b7a8f53e83db7a6b22e79a65a720d69198d989b07a34n/a SilentBuilder
2022-03-305592504849466812.xlsxls d165b715b1c473df33c059be50a8eec754b9dc819ed59230ab9c74e352584753n/a SilentBuilder
2022-03-3080406430545419819735.xlsxls ee0751444c28714ba1f0d4228dbfcee7ee0d8fe35176d8ab8ad52fe2d0eca562n/a SilentBuilder
2022-03-309151943082454132459.xlsxls 15b8f817ad756bd04cd33d34f0a4670b25afa33c7ab59f37b322284809532d05n/a SilentBuilder
2022-03-302916976787380.xlsxls 06ec7d1a1a19dac000cb1932a8aaf93ab8f9133a5de6800f084df77bd90cba5dn/a SilentBuilder
2022-03-3059235583222129371.xlsxls ed919e7317e9edb91eb7468e26cad1b08ecd328cfb669e1fb95bc2f3171b2ec8n/a SilentBuilder
2022-03-301356775645005214.xlsxls f30f9c9233859f2549dc271d14fd86bdebcc72c70e9c51ba4606b75cbf745473n/a SilentBuilder
2022-03-3009249840726633.xlsxls 66115ef823bbc6b8007ee6b6508af174566899af8df63ea1f6707b293153f2bdn/a SilentBuilder
2022-03-304505655091533.xlsxls 7d9969135b930be92c93aac7e3057b98410a43fd0af360ee02b88b9ad570d116n/a SilentBuilder
2022-03-309941450285549.xlsxls 51a8819534ed48bd71579b6e79307358b76ceaae81aafc73cbb8e8b77e977061n/a SilentBuilder
2022-03-30802740246225.xlsxls fcc9433ef4577609340bc031159a9d1329e9f97cd05dc2093d12abe1857691f9n/a SilentBuilder
2022-03-3060374755142091.xlsxls 8fc9e8a1e3d1a19ff9fff8c201ffa5db5b8a718f5c8841dd24bb802739f32d07Virustotal results 22.22% SilentBuilder
2022-03-307245478378.xlsxls 0ef1d87a8603f19dbb5c1e6352e3668afad3b3c384b0d5b3dc198a3b9786a318n/a SilentBuilder
2022-03-30473000029922.xlsxls 7254be738108ec8b2d0ba70621713ce3174ab181e872edff03f9abf160bc1b44n/a Heodo
2022-03-306001624636371.xlsxls 50c3d5a37ccc9d63435cb5ed56e8a758234f55c42f3d8a90c12fdde81ae649bfVirustotal results 22.03% SilentBuilder
2022-03-3049582805175.xlsxls 11388ab6a5ddf4428f702631f9c917387a0e41810a583427274cebbc73845ce4Virustotal results 23.33%SilentBuilder
2022-03-291512230429576.xlsxls 3cd17e7df9642d09bd3d735e259ca8f9c4ff061f1070a601f3e638df5fbe1647n/a SilentBuilder
2022-03-299564031432457.xlsxls d97c0128350e74d1f6eaa63deb4da2dcfc20f1f9d1f8e05a02f32edb9291290dn/a SilentBuilder
2022-03-2929907415901.xlsxls 3e97f09fc53890ba2d5ae2539b5c8df372ed2506ed217d05ff2cf8899d15b8e6n/aSilentBuilder
2022-03-298576690082995590196.xlsxls 6741b0effa1844c85e25015d8c01ab0330e793dc563cfe2977746f5eb7a37fd3n/a SilentBuilder