URLhaus Database

You are currently viewing the URLhaus database entry for http://guarany.net/zefiro/docs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:534086
URL: http://guarany.net/zefiro/docs/
URL Status:Offline
Host: guarany.net
Date added:2020-09-16 16:14:14 UTC
Last online:2020-09-16 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 16:16:32 UTC to abuse{at}hospedagem[dot]net)
Takedown time:3 hours, 23 minutes Good (down since 2020-09-16 19:39:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16AFP_090120_UGZ_091620.docdoc ef3f65e79357e42b0a2783f79e3a8c53a2b789aa8960e3927d59be3a509f9250n/a Heodo
2020-09-16YO_08ZKL7I62ILI9.docdoc 9ca5390e9af21757dc77575f56e9d0528c527843951ae719c3aedd2d8680ce7aVirustotal results 39.66% Heodo
2020-09-16FKXN6BEQXVNKTV9.docdoc 8807b5e5fcc84574f25c3cc1fd79a2b292b7f7037cba0ed308a05190ce462002Virustotal results 38.98% Heodo
2020-09-16FILE_PO_09162020EX.docdoc 679e5f33c444b178b0da6da41a58b4590f05e7c464293e3b1d8f858dbe157124Virustotal results 41.07% Heodo
2020-09-16BAL_63383177.docdoc b2a8ffc1f00ac5b5f607e6a6e0327888e9578b9e746e49ffd390af493f888136n/a Heodo
2020-09-16FILE_5821935633837914759682.docdoc 89e280d00eba5184867b52270ea583f8bda9161dcb52921411e456747741e571Virustotal results 38.98% Heodo
2020-09-16POF_090120_LMZ_091620.docdoc 4d88090314c39059da536bb37270cdf7ffadeeda4ea768b55dcb9f2b807586f4Virustotal results 38.98% Heodo
2020-09-16FILE_52287628.docdoc b9a6ff1bdbfdc506e17b3e590738e75cae3ce59614c8a77074df2b1d2abc3801Virustotal results 40.35%Heodo
2020-09-16FILE_PO_09162020EX.docdoc 1507825b3185d4763904f53704f18fd1157aeb1eb25ec77e5643e8a48173e53fVirustotal results 38.98%Heodo