URLhaus Database

You are currently viewing the URLhaus database entry for http://guarany.net/zefiro/jpHWuDhsooValYhWZMIFVL3HZDDq2m4b6YjuFXkhf7l6QkmbgnJH7F3YDDHrAVXigy3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:755686
URL: http://guarany.net/zefiro/jpHWuDhsooValYhWZMIFVL3HZDDq2m4b6YjuFXkhf7l6QkmbgnJH7F3YDDHrAVXigy3/
URL Status:Offline
Host: guarany.net
Date added:2020-10-27 10:08:04 UTC
Last online:2020-10-28 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 10:10:15 UTC to abuse{at}hospedagem[dot]net)
Takedown time:1 day, 6 hours, 15 minutes Poor (down since 2020-10-28 16:25:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28ARC_PO_10282020EX.docdoc 4adf50798ab74bce527ebd2b5bda0377d3f0a04dedf82c96f386b640e3b7d31cVirustotal results 25.81%Heodo
2020-10-28Rep_G0R4LMCHVLHYP0.docdoc a7c464eeb2745a70c0108df133c47695689e8205a9b36343bf6652b953700739Virustotal results 25.40%Heodo
2020-10-28UNTITLED_JDKPUIWBLD4274AZ.docdoc 00880c9aa541d5176cfa0d8e2306b649327af55ef539e6018af094288e581baaVirustotal results 21.67%Heodo
2020-10-28Rep_ZATCBTT5O05.docdoc 9423019c9d0c788f9b0f3542a6df53db5b54620754419ca1c69895b15b6c73c2Virustotal results 20.63%Heodo
2020-10-28inf_QQ0479265443GP.docdoc 53fa42ca6eee828e13b26f79efca50367e1863311520bc82ec6d97b0c7268845n/aHeodo
2020-10-28PO_10282020EX.docdoc 5e8a2713a00179ec13f6ff8d8b32c086bd76ab94e23667adc252789b5c1117b2Virustotal results 19.05%Heodo
2020-10-2872157111.docdoc e9fe736c7aebf19a2dd114a50c120a97eb0e9d4763a5167325791cb703f37d93Virustotal results 17.74%Heodo
2020-10-28List_K9NE2RCHGJCD.docdoc 101ebcc462da774f817a7420d2f849189c1e6093c14619e3c4497d748e655110Virustotal results 17.46%Heodo
2020-10-28FILE_PO_10282020EX.docdoc 64635c63d42669d79de593fb4c9276d3d1a246fc8a715ca5debe629e202a8018Virustotal results 18.03%Heodo
2020-10-28F_MMY_100120_ZUH_102820.docdoc 5a3856662e4cbb0a005a296d49553490ac6012c6d56158cdc1b75615410ad792n/aHeodo
2020-10-28mes_PO_10282020EX.docdoc 7c5cba3f361edbd305005728464aa36e44d98db05cc52860a979780b6036fac6Virustotal results 18.03%Heodo
2020-10-28rep_VK0195599043IJ.docdoc 9c5f88a456da5cebbe774e127b1ab02cdb4769374bf745dca29d2e207f156ee8Virustotal results 18.03%Heodo
2020-10-28WKI_100120_PKM_102820.docdoc c52d8de4c0df2d3039b4e550b081b8386bf713ff22749065c331fd9c03bfa88dVirustotal results 17.46%Heodo
2020-10-28DOC_PO_10282020EX.docdoc 8f81d3bfaa85d06f828287a8c5f575fae618f017c0dd9be15f4544d086ce38c3n/aHeodo
2020-10-28FILE_PN5109027127MD.docdoc 362dc59ca77c1bafa2f6ac163566994c9a8fed193b5285b3eff678bf8588eab1Virustotal results 17.46%Heodo
2020-10-28list_8GF6QCKN7TQW.docdoc c88a8bfd26b88fe11810b85a6ced566f6ecd9c06b535f98d8c7451c66c1716d2Virustotal results 28.57%Heodo
2020-10-28DAT_PO_10282020EX.docdoc ce14f27765b4ed177ea779ef8f7eb00b4e09b985d0969e6a139c40a58133956fVirustotal results 28.33%Heodo
2020-10-28Mes_PQ2641075266VR.docdoc 3c7adc03d47d4071a05f6829238a5d5e5e21389ae17cf278b8f88824cae02d83n/aHeodo
2020-10-28ARC_ZR8207952582WX.docdoc 2964b5d28a8d65a8477f44ee1cc2b6859302f4e76e07a48217e9d948772ecb36Virustotal results 28.57%Heodo
2020-10-28rep_PO_10282020EX.docdoc 783e3178de387969ad58cadd83de2b88c6cffa406063d2f66e5ee8b67db11b4aVirustotal results 28.57%Heodo
2020-10-28FILE_US7763118512XI.docdoc 86cdca7c9ac7ecd5defa0fb8c374cd773aad5df00d6678e7f5addc0268a097e3Virustotal results 28.57%Heodo
2020-10-28Doc_5DVYZQBCZ.docdoc b10f4a4b46a88d8bd137cb2d76eb827b89f16acd953490d55b6161aa0e99b7aan/aHeodo
2020-10-28DOC_MO1046755114AB.docdoc ed432b4a387becc419df96f24140626602c26a169999780c2309f0f5190a1321n/aHeodo
2020-10-28919928437089208.docdoc 9c509bf6c3b7824436cb299b2efffd013f3b0b156e9398a6975b71b50152cac3Virustotal results 40.74%Heodo
2020-10-28AX3786063995XX.docdoc 0b62b154422aa927a6906a75fdc8edfd4c143365e4b5e4a8ffd58badd6fdb0d4Virustotal results 38.89%Heodo
2020-10-28inf_28481748.docdoc 553f438bc1486ee99b764c15bf3caa7e8fc1b49c48ace061dbd07220a7e56eb7Virustotal results 30.16%Heodo
2020-10-28rep_7QJ1PFQ7H.docdoc fe13971c49c4731ae4fdc32c49bbb6796383a27db3ca2340642ed9d0c1753880Virustotal results 28.81%Heodo
2020-10-28mes_OCW_100120_LMO_102820.docdoc 3a183e3b2c742a3307c322a6e8e75c3741b4b35e456bacd95fead4ceb74fcf12Virustotal results 31.48%Heodo
2020-10-28inf_KX5745760974GX.docdoc 7f286766434b67cb7ea25119d469c086c70807bf665e8e373acb472ec284a72eVirustotal results 31.48%Heodo
2020-10-280824378885.docdoc f3caca68ae462481d5bac777996fa838a0dce95c7eb782713404fa5e3712a2abn/aHeodo
2020-10-28list_5014939909.docdoc 56bac923cdfd4440f1cb05f87560995bd487d31fb83f16ba23e935825657a7feVirustotal results 23.81%Heodo
2020-10-28OHVH_PO_10282020EX.docdoc e774de558ab588e2aefc6661f8ddf20b6a02ef8a6e2c4504a0b03e27d9c19df3n/aHeodo
2020-10-28rep_91N5RTP4AG1.docdoc cf6945d684eb6962274cca88159c3f88a0a5291a81ac0d8831d9f6496b005c33Virustotal results 27.78%Heodo
2020-10-28File_90030541.docdoc b7ee22f0341587e221b8a80c3caf8fe78b8d8ba06220d4cc28641f82d0d32bb0n/aHeodo
2020-10-28Attachments_7Y0KDR36RN9.docdoc aeb7e85b2cafde9f05807a7b77f48f79c431e3c6cdaaaea539d2fb42a7ed47c4Virustotal results 26.42%Heodo
2020-10-28Doc_PO_10282020EX.docdoc 5e692d0f6341638d540a0dd0458062a4852cdc65dd6551956aaa28c4d417416an/aHeodo
2020-10-28Mes_56163900656416740.docdoc 1fb4278069691dd947dc414fae8cd33f4b9309293ff8919ab9fdf39e30cda63aVirustotal results 20.97%Heodo
2020-10-28Arc_44992420.docdoc 2474770e88e989b790cd585fe0e234558dc6ce20bc8ddaf5a4e1f5c0733bc09dVirustotal results 22.22%Heodo
2020-10-28Attachment_PO_10282020EX.docdoc a30d2b343e3646a2a05e98c5b7f976a1f67e12574ecb880a2a460bec35735f6fn/aHeodo
2020-10-28H_PGJ_100120_LSU_102820.docdoc 555c444da12ef92c155597ec6fb707163898e7bc70247e493e627c319f122a36Virustotal results 23.33%Heodo
2020-10-28Doc_RK9552935028SN.docdoc 6310463115ebc704a66281738da24d3ddc5e2b7142db330ffc61d25899c74869Virustotal results 22.22%Heodo
2020-10-28I_VE4758071450XH.docdoc 7eb74017c164dd7972d8d6fc795baaf0f0bc4593227af0752e986dc52bcbfdcbn/aHeodo
2020-10-27Dat_4YBXVT7S.docdoc bfc255c1fae47d22c3a502329ae24b49b0fc4169c49c13a4b1091cb686e3ccedn/aHeodo
2020-10-27Dat_YF7731327466TY.docdoc 9e67927cc9cf11b38167386aa1974faf5516155e23095cb9b5a2daf9686957e6n/aHeodo
2020-10-27dat_OB6YDBT968ONADQ.docdoc cf37bc70aa99bf4d8ac44a3ded10f1d82deac713ad88ca9aa9f6f550ccf52f2cn/aHeodo
2020-10-27Rep_FRA_100120_UXK_102820.docdoc 786139fdf387d3068d18ba7eb1f55806ca956cd8834e1bbc350196ede6433fddVirustotal results 18.64%Heodo
2020-10-27List_3398893262748.docdoc 65a3d9acca772189823848387ec25a5bcbc6c05bf5acac4e213d3458f7c256e8n/aHeodo
2020-10-27file_KEQ_100120_VVW_102820.docdoc a99f2aea456cc18c69c4cfb2a2eda92fdeae784f7275e3ad000457fb02e614can/aHeodo
2020-10-27Attachment_IT8784957089ME.docdoc f0cfa5e0da830c64b718ca4ef0e2a826727e13e6f59321d4bd07c41f1ce888d7n/aHeodo
2020-10-27Mes_PO_10272020EX.docdoc c0b7364bc8b2a4ef21f805fa2085e3ad41e5ea6206b0274d6300d64305d4ec0fn/aHeodo
2020-10-27ARC_PO_10272020EX.docdoc 12e68ae11d4760770f0cbbbff076d4433df71d8674e10d3875994fc1d749b1d6n/aHeodo
2020-10-27Rep_80255136.docdoc eff4ff103b1930c43c7f0ae267a43b853c4cc734db4c80473d028efff6e8f7f2n/aHeodo
2020-10-27Doc_B452LER54Q2J0.docdoc 762bcc2c5112e9883cfccc6525ddfe0c7839a65c34bff3f40cc0cfa69d9384d2n/aHeodo
2020-10-27List_15383521.docdoc 31b23d9a8a18a659b89c36b6b116aa8f28579df18ff6d5f81e557ed41c1cc271Virustotal results 47.46% Heodo
2020-10-27REP_0883587548733521581.docdoc 94bb2eb0f0b8a0f61ff20360dbf6e4b89188c5157bc940f9d38dd4cb68a4539an/aHeodo
2020-10-27File_DDV6GWT.docdoc 1ad28606bff91478a2383c7deb56c563f2c3912df1f1ae81b0fd16892f3842d4Virustotal results 46.67%Heodo
2020-10-27Mes_AE6389129198TI.docdoc 755114dfd81340951d25507db37f9a1b272113a63182ebe3b595977db5d41cedn/aHeodo
2020-10-27Arc_45FRVFKTM0A2.docdoc 53dfce57e9c5c4d1fa5dbfde99dffd5cccf677f96b297a5a517d86f93cc81bbfn/aHeodo
2020-10-27DAT_5440526373442035.docdoc 8d2d00b851dd74708e5e2f6c4858dfd28cbbee583526d5cfdfef4b00f44077c4Virustotal results 50.00%Heodo
2020-10-27DOC_147447263429148168412.docdoc e298717a6f9ade752fdc64bab13127ed179c323b1bf54c9e8f79d64bc6227943Virustotal results 50.00%Heodo
2020-10-27DOC_YRY_100120_FHB_102720.docdoc b5af6d7f4fb7ae66fbaa6bec875c3445c56507a2307d92800e26f08d169adfd9n/aHeodo
2020-10-27inf_PWNHWSVND.docdoc e2e08b8d13ee2f3b74b54ec4de5892a941e2a274e8c0117d86a7dda62c0dcdd8Virustotal results 45.16%Heodo
2020-10-27LIST_058887546262223523058385.docdoc 16b99f7444f5e97d0fce8d7730fb1437f62f71827293d7d94965735f45ad9334n/aHeodo
2020-10-27list_98342368.docdoc 1663fbca3bfee0c76af0ff5fa1e59b2d4e10eb3b17a1c5d41a092adf85f30eadn/aHeodo
2020-10-27dat_HHWZJOZOQX.docdoc 88c3d6cac3e781e9e7c07099efe0a5920b3da23acbd2ac4240b7495c923c7ce2Virustotal results 42.86%Heodo
2020-10-27PO_10272020EX.docdoc bbc60f6a3e441d49e8c3797ddfab56b309bf6e162bcdf8400e73e7651d117c54n/aHeodo
2020-10-27REP_PO_10272020EX.docdoc e9ed0e2383e743b2c64d4c7a9dfa27ef8352ca6b03cbc8b606f72368c42c0196n/aHeodo
2020-10-27Inf_FXY_100120_PPZ_102720.docdoc 8132ebf645136fb8cacd884cdce5c26ecf6735ba799c34d7f8d09245681042d1n/aHeodo
2020-10-27Dat_JC2454136069IC.docdoc 017909307178fa381f530ce4b1d2f502314d945f0df267932375e21392764894Virustotal results 38.10%Heodo
2020-10-27Inf_427779396323882550076909.docdoc 1f2f51694630787d01ae02ff2756114d0d9e38a8de09470e63aae9dbfc0fcf69Virustotal results 37.10%Heodo
2020-10-27arc_GGO_100120_IRK_102720.docdoc 235b10dcd06777c5834503b9ec2da2d0fd23ff9288244bdc9e941137f25868e3n/aHeodo
2020-10-27DAT_39689679.docdoc 9ef432b9526e75b9aa481ba043077d6ffefb4a706388c90fd002e320dac8520dn/aHeodo
2020-10-27Arc_P8IG1CRRD.docdoc dfba0c0279ce312703161fc36a706210611ed837313ae97396607890e243f668Virustotal results 32.26%Heodo
2020-10-27Attachment_VMB_100120_NMU_102720.docdoc c2f163720f0e6e06b3b33b5477481a4789df1991bf3ef3c5e8eb3c3580176e65Virustotal results 37.04%Heodo
2020-10-27FILE_DF9113675599ZD.docdoc 56c2cef0eede6803ac93b690989ddfe5728039f73ee3f2667128ff8812054a6an/aHeodo
2020-10-27Dat_OHTA2KDTT.docdoc bf3caf1312e44d1c99fc185bee6d80d89ecbd308c5a1346d673c5790962eadc5n/aHeodo
2020-10-27Untitled_PO_10272020EX.docdoc df6ec075b661ca498939b6b15933fe4822e9e1540863133b43a606b14f2f1f76Virustotal results 32.26%Heodo
2020-10-27Attachments_HYHE0V1V7P1CKDL6.docdoc 0806b4f4bc6745b9b67d121826f3f542a390abaea7666810393645f17136d396n/aHeodo
2020-10-27Arc_83789431.docdoc db8c10dd3ab28c896b921d720da5b91739c6f990bfef2f4026dce156e231fa0dn/aHeodo
2020-10-27DOC_PO_10272020EX.docdoc d5aaf8e25239f9afc06dd64b24324b6a12c43fd6ef863b33e602425aba4960e0Virustotal results 35.19% Heodo
2020-10-27Rep_C3L4STYED0DZ3YMV.docdoc 4130fe60dbde122aacced0f6f232a6b559d7eda06ed96bf5980d4a9d88151f94Virustotal results 35.48%Heodo
2020-10-27list_JTO_100120_PVY_102720.docdoc e2118700994eb009d7d7ea74a0badb8bc07ad79b19b05f75f68c9030d29d966cn/aHeodo
2020-10-27Attachment_JO4561126628MW.docdoc 2e645bb4982ac3ce6f30a2fc5a13d0a55dfdbe4c11decc1a5dd1f9a3136390e4Virustotal results 33.87%Heodo