URLhaus Database

You are currently viewing the URLhaus database entry for https://www.guedala.com.br/cgi-bin/c349IB7OmLvMgcZEoCe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123247
URL: https://www.guedala.com.br/cgi-bin/c349IB7OmLvMgcZEoCe/
URL Status:Offline
Host: www.guedala.com.br
Date added:2022-03-30 21:04:08 UTC
Last online:2022-08-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 21:05:08 UTC to abuse{at}matrix[dot]com[dot]br)
Takedown time:4 months, 26 days, 16 hours, 29 minutes Bad (down since 2022-08-24 13:34:33 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01PXC-626460313826.xlsmxlsm 8ad8a4352be7c292bc6aff0e00e38f039c395650acffec2cf7c44d28e820eb7cn/a Heodo
2022-04-01GR-8444605317758.xlsmxlsm 3005686dd6b770a4a0af0ba70ec91ea407d32838aa2acea56c5ab75f2a47ff56Virustotal results 46.77% Heodo
2022-04-01RW-47007205937683.xlsmxlsm 5e318e7afaeff1da0ab8f38c466b9fb4e911da7fae7a6eb58cfbab3175d51263Virustotal results 41.27% Heodo
2022-04-01VBZ-5569267856245.xlsmxlsm 0a23b203754e6a043fa99f6cf518c8ffa19a34557a7471edad072d54c4a76dacVirustotal results 42.86% Heodo
2022-04-01LF-017317735.xlsmxlsm 0f6cfe4c94b7444729077741d333e0388edf05a02cd4dc40e515a03f5d4bf01bVirustotal results 40.32% Heodo
2022-04-01FG-7011871073.xlsmxlsm 99717c4eea8cfa905a207ea753e12bcd957f480eda47749d5cd5ae2f362a4f7dVirustotal results 40.32% Heodo
2022-04-01JWG-3794503.xlsmxlsm d058072d305f952c54981e50bbd34cf23dd0386a4924a4bdb8a91f46e0498d4fn/a Heodo
2022-04-01VHZ-741973762073.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01UP-423048197.xlsmxlsm 8090d0b6d046091604553a331f669273c32d27943faae06a33b6ffda57479dafVirustotal results 45.16%Heodo
2022-04-01RW-530898348.xlsmxlsm f316a9b48040c007a792f5b99f7367b7d6996c7db03a377dd159a22db01e6546n/a Heodo
2022-04-01NZ-62299370124055.xlsmxlsm 82484ebe66d4a702e915f98b23d90b6cae0c2a0eedf9de279b5dfe5f18b4ef32n/a Heodo
2022-04-01JFR-0045254077.xlsmxlsm db05585c173bca5c340fd01dffcf23be710be4b482131d5bc16f4eedb265754dVirustotal results 37.70% Heodo
2022-04-01BB-410013931696995.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01GGU-49244198.xlsmxlsm 8e5835d0209196b133cd57a2e62020eb4553f72a8436e3b16f0fa666661e8326n/a Heodo
2022-04-01UWY-472781783730575.xlsmxlsm 3e1d94f17a0b086b807988a4a026e4e5a9748045766df076577d83476aa52d34n/a Heodo
2022-04-01ES-62450194507365.xlsmxlsm f53321cb8389d05b2d4c2f1a82efdf89e8d00a44ed13e02f649c90fb3169a7a5n/a Heodo
2022-04-01EKR-1315870.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 38.10% Heodo
2022-04-01FVX-39084637680571.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01FA-5196960919.xlsmxlsm 9f342795c6ad73cb790eb75a652804c6a00f21b0806986310ce8ac0208d7ec58n/a Heodo
2022-04-01RNJ-986236069.xlsmxlsm c0e952a6f3524c6ad386d70392deb83c2e0677409d38454d38759abb44e2058cVirustotal results 41.94% Heodo
2022-04-01NR-83580329962619.xlsmxlsm 2fff16868f10c6160310b0a347d813df22d0876f07b6d43eef2bf272eb84723dn/a Heodo
2022-04-01CD-073089480.xlsmxlsm ea8981ffdb13c6d1dd874a5a86e7079bb053c862a92849bc571846a6762dc7d4n/a Heodo
2022-04-01RYV-41418526712.xlsmxlsm 68696caf69e14a066ca54423f72a2e7693b03f5ce299e609265a3e72df925abcVirustotal results 39.68% Heodo
2022-04-01AF-8164382928779.xlsmxlsm dcc6409e704780116523a3e6ca35edf1399b381568d26b6d0373d1d9e00be491n/a Heodo
2022-04-01QOW-328310773575.xlsmxlsm 23c128385a0702939e1b4bd33875e38dc27cec42b5561f54859abaa962d2930dn/a Heodo
2022-03-31WVO-615598335.xlsmxlsm 3cea415c72cf99f730ca00ed40940ba35c82dd2582786d91fb329459f88328efn/a Heodo
2022-03-31QO-97394620075.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31LYI-226616887306.xlsmxlsm c7f63ce6becdd48402150d223d11b5fb003ec48c57f2d856c8d979e5b3da4254n/a Heodo
2022-03-31FV-6329875568.xlsmxlsm 73a1d60faa31200f09f2567671137d6b5f9be02a97eec33fc20971d151d5c8f1n/a Heodo
2022-03-31JM-27115320932.xlsmxlsm 0baff6c11648937580735dcff8208034790a0e1ee649431e79b2b6221d825c40Virustotal results 44.26% Heodo
2022-03-31UP-0371421453483.xlsmxlsm 2fa93c2dfef003816d473094a03ffe57ed6fd6cbbd21f22831af88634fc3287dVirustotal results 36.07% Heodo
2022-03-31CDJ-475126999303.xlsmxlsm 896ef5fb12bd10c84fa96213d6a86aa368388e4806b9c882fd601a113482ff74n/a Heodo
2022-03-31ZWK-4760354392441.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31NXA-5219602560.xlsmxlsm fea58fae76c86e5f07c7f8b032f84174206bc489d92c49fe54a5b51d2658faf8Virustotal results 34.92% Heodo
2022-03-31BYF-9541681646823.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31MZW-574125284884276.xlsmxlsm 63ba5c63fa8f569c1870ab57faeeec2933a7bdb28c90458f6c5373f1a71dcef4Virustotal results 36.51% Heodo
2022-03-31WE-91812681793.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbn/a Heodo
2022-03-31EXE-966908751940623.xlsmxlsm c3a5d5bc890f935056c127bdeda35cfcfbb8e292e59774a24ca5611e94430907Virustotal results 37.70% Heodo
2022-03-31RZ-36080679357.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6Virustotal results 40.68% Heodo
2022-03-31JM-5738200737.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31MR-52065740358.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31RH-1986080840.xlsmxlsm 638588dd97949a25ee7322aa73731204406054bf2db2043063ebfdc82d353f65n/a Heodo
2022-03-30IBY-98916040821.xlsmxlsm 3bfd193ea92a687030d7b2fb3354e52980ad28ba1cae92579b53f5473b44f37an/a Heodo
2022-03-30EM-602594250.xlsmxlsm 8eb161bd22ea52d987b19953ebebe364df8a0779ed9f42ad96c6dec32f8cce52n/a Heodo
2022-03-30CK-96301164572960.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cn/a Heodo
2022-03-30HV-591034830.xlsxls c37ffc0e87ede2e654c4112c8d1b9172041a21bc4174b248ee2c81af738bcaf5n/a Heodo