URLhaus Database

You are currently viewing the URLhaus database entry for http://ftp.cgmma.com.br/erros/RikCkT6uYJR1l3aIdQvlJuY6Zlko/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120609
URL: http://ftp.cgmma.com.br/erros/RikCkT6uYJR1l3aIdQvlJuY6Zlko/
URL Status:Offline
Host: ftp.cgmma.com.br
Date added:2022-03-29 21:51:07 UTC
Last online:2022-03-31 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 21:52:07 UTC to abuse{at}hospedagem[dot]net)
Takedown time:1 day, 22 hours, 42 minutes Poor (down since 2022-03-31 20:34:52 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31TH-70391576416884.xlsmxlsm 36b9445ba8e049935f86955d9c9251334fa60c940b28d69da57f97926e54211fn/a Heodo
2022-03-31HPA-23695787.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31DJL-3091312699.xlsmxlsm a657d3b4f65b1da6a9b498efd74772a6b8c393555587694e5da423b8e108ae2en/a Heodo
2022-03-31OP-31407030.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31DD-02720660.xlsmxlsm 2550670f68b05aae7f04bfed13c37b7f3ee48a1677ac9eef2e7c3c0a88aefdffVirustotal results 43.55% Heodo
2022-03-31CLP-482761017679.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31ZG-390638971.xlsmxlsm 5285de9e0e5323564d48a5d9fc627190ed9bae90f9c0e818958768b0d7c856b1Virustotal results 36.51% Heodo
2022-03-31AJG-417617484128308.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564Virustotal results 38.10% Heodo
2022-03-31DG-895563842949.xlsmxlsm 168a9aa1b5fa37a354fd6ccba71dcd29cbcd503a578504c69feb38bd84a8a691Virustotal results 42.62% Heodo
2022-03-31EY-20767867.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dVirustotal results 37.10% Heodo
2022-03-31IU-00810218.xlsmxlsm a33fbe4216b549013effb9933214b20529eb07c263c60ad3aae902c1be45369bn/a Heodo
2022-03-31MW-9824795.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31WA-56582326.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-31FQF-6656390.xlsmxlsm 7bd47c2f3e932a049d450f5a54be51e401ea041d669c7df91f71b903358f99d9Virustotal results 39.68% Heodo
2022-03-30MT-15824034.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cn/a Heodo
2022-03-30VR-904125863574830.xlsxls 34c12fb797211966f38e1025e683ec8ecc00b70e39d5f463213f7b09eea896c4n/aSilentBuilder
2022-03-30PY-5071491935167.xlsxls bc8049d90da2c6ed214cd043d2d754a1f8fc802010a6367d5cac254aa1853a67Virustotal results 26.67%SilentBuilder
2022-03-29n/ahtml 1cc83cc509fc8492a5cbf60f7908faa766a11790d15365768565e0c274a248f4n/a