URLhaus Database

You are currently viewing the URLhaus database entry for http://54.167.192.134/AwafJ-uSkG_fPlXdovJx-icC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:121739
URL: http://54.167.192.134/AwafJ-uSkG_fPlXdovJx-icC/
URL Status:Offline
Host: 54.167.192.134
Date added:2019-02-11 15:36:32 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2019-02-11 17:22:10 UTC to abuse{at}amazonaws[dot]com)
Takedown time:8 days, 9 hours, 50 minutes Bad (down since 2019-02-20 03:12:11 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-13INSTR0127256942383.docdoc cb241768197028432198ff735ceb5260da13624748e46b384d75dc8d59b85bb6Virustotal results 20.37%Heodo
2019-02-13INSTR081231038883912524.docdoc e4265a53345eeaca82917dcd846c58ac7d4d6dae1f99055d9415a5a759b5650cn/aHeodo
2019-02-13ACC1993563224559.docdoc b8d030c7d0228870de8bd65d62b13804dee44269065314ccffce1a4bede371e9Virustotal results 18.18%
2019-02-13US5579152977.docdoc e979342ca8e2b6fa4c8bc60fa4e90e6be493ca73c199d04635d8f68423bb7927Virustotal results 14.81%
2019-02-13US1922616069206140358.docdoc 9f51918746416b2d8b1d6062030afc723ea45f65a97b29737aeb7fa0004ebb2an/aHeodo
2019-02-13US3136827936.docdoc 21bb40ec221b915e0740c9505c1ef227f4d17d80b0cd4c4666b68d00e760a814n/a
2019-02-13INSTR59776390141.docdoc 14789fb215cc2d03e2758deeeb8f0e96f64ebd5b097495e32109f93104d18c00n/aHeodo
2019-02-13INSTR7846129120847437.docdoc 8f79767fe9ce914eaa39d59b9909c3be5c026953415c7d8e926f8801414522eeVirustotal results 16.36%Heodo
2019-02-13INSTR82387252456279392340.docdoc eaec15b385dfbd29a26ab5e6f58a85662c3e1c0f3d7c862779836b30083ec1a4Virustotal results 15.52%Heodo
2019-02-13ACC9109595308088725522.docdoc 0a6f9353d2d75aaaba7d92887c17d12f85a069a6445e69c9c573cc271578605fn/aHeodo
2019-02-13US149231390401939.docdoc 276a772e34632e0f02997e45c48dd161335d9c1bc0bf1a98e4117d9aa719ef0fVirustotal results 15.79%Heodo
2019-02-13INSTR9799411899.docdoc ed6b61fd97fcf29a9b548ce5028328766a45b30980f8a24c7ddf201a9fe304bdVirustotal results 15.52%Heodo
2019-02-13ACC9348690454017946889.docdoc 09c144d073586057a18a9c3726acbee30d98f513645c4bb723aab94092120b9dn/aHeodo
2019-02-13JWRZ9018682313.docdoc a32cca9e83cc5f3e7366b9eb313fc5899a8acba8cb34b2ee404763a5952f89ccn/aHeodo
2019-02-13L123819214154522.docdoc ddd96ebe81d58702ea97e05d70d537b7c8fa8338b0333bfe31adb59c9beda62bVirustotal results 16.67%Heodo
2019-02-13924757914425237.docdoc 482290fef437231fd754cf8830a58a327110a9456717b6bcf347f88f980ea550n/aHeodo
2019-02-13ACC47284177935620919335.docdoc 285a9bf1915a90e289f32fe471c023d4524fd96c990eb759f8985a1396d9e8eeVirustotal results 16.67%Heodo
2019-02-13INSTR831867183305829443.docdoc fca9b9dcdd866545b0eadab66438496a43368580f36047c1c4933cc9dd8fc196n/aHeodo
2019-02-12FR3271961496348.docdoc 2a82e054cf0952cba51ff4967636c4d1c8e2360ac42c1eb7413863980426042eVirustotal results 33.33%Heodo
2019-02-12US1444687039295966769.docdoc 1d341d716fe5ce577b3cc061913f8f1dd133263d654d3810764864b389023e3aVirustotal results 34.48%Heodo
2019-02-12US697353675.docdoc 76ba05fb7693e6f73095e182751e2b8ca5383a9ad826a6c233976d45d398bf4cn/aHeodo
2019-02-12INSTR90836362541.docdoc 80b58ec414425dd89f34d2d46622d6707e16c1181c04a86ae18279fe3c9d7793Virustotal results 35.09%Heodo
2019-02-12ACC958994816.docdoc 481931d27496fe2ed1f13af908e7eb1917429c43a7ab2db6177cdbbb5601e902n/aHeodo
2019-02-1298471172423967.docdoc 248bd5ff6a4d44f8e54b69789a8a322e89fece8e81d0b703695198e24b4b18beVirustotal results 33.33%Heodo
2019-02-12US997458626.docdoc 4e41e9af78f6883063e2adb3569a6016e9b3e05e01abf2267426e0c24f97345eVirustotal results 28.07%Heodo
2019-02-12PAY0357697329681.docdocx ceb007931bb5b6219960d813008c28421b7b7abfcc05d0813df212ddcfa5b64fn/a
2019-02-12INSTR940893212752733.docdoc 4ddca771f86a73439df39fbd28da78637fd0012caa3f24efdeada5b7018e491dVirustotal results 29.09%Heodo
2019-02-12ACC576182808648449.docdoc da448702c9a2daf4dc8c71499b878fa36fe07e67e00f4f7e459753e1cac9d608Virustotal results 28.57%Heodo
2019-02-1264835482947445085.docdoc 20d57831a57bca5c48a34e655f3f64dd3b1b44137433508465438e31601f456cVirustotal results 28.57%
2019-02-12ACC9902399738814.docdoc 957aedad03a3358fe4bf1f721303e6eba3b9e29c114bdd96bad73808da71e46aVirustotal results 22.81%
2019-02-12GYX6546844474583786.docdoc 3eeb2bd103fd19d9e5528555be0cff169c33bf513a6bf9708569a37cc6cdbc05n/aHeodo
2019-02-126841817031069.docdoc 8be846317fa0deec67c07cd689b59ba7231c4244b490329e6dd4b74ab9fccc74Virustotal results 25.00%Heodo
2019-02-12US442009319007942.docdoc f025a2e7245bad5d2ca5c61329311ad8d89385275b35910a6e47fb79f2c0c3bbVirustotal results 27.59%Heodo
2019-02-12US1562596630882.docdoc 93e7bab5a87110e1ec49b5e2a40b70eab6c53c4a6f42b63b77d472f52f904676Virustotal results 26.32%Heodo
2019-02-12PAY33885571678048.docdoc 9e500ad2ac11e0f355d7966992ecb085244e777b278f5d8d13568cc4b256e089Virustotal results 25.00%Heodo
2019-02-12US7283176509211.docdoc e837f29478fbb117d9fe612c32c39d435426ef558810aa4ebed6a7a1bb50d039Virustotal results 34.55%Heodo
2019-02-12US282097025054.docdoc 21c6ca0ab11cb70de291b3c0f719ea6e9b5c70297391a4148b06bf66c77c53c9Virustotal results 28.07%
2019-02-12US1356386683495.docdoc b512f47e2fa25638b3ecb8e18f832fb198dc42257ad8a67e27c6c23b9ee33740n/aHeodo
2019-02-111962654073.docdoc 9414679bd8f2f0be79b5e4fb7f1f412c07bd7ee0b6b09bcc34e8eda48e51026aVirustotal results 27.45%Heodo
2019-02-11INSTR95304316796827955552.docdoc 1d76c053f2cef763987de94d262b794b5fa0540feb9f6bbd841739236138ccdbn/a
2019-02-11INSTR472874158508.docdoc d1df17ec2fd32b9514f8874aab3bf4591d00bd30cd084cace80b1c5d1c6d2d6dVirustotal results 26.79%Heodo
2019-02-11US29062130268819861159.docdoc 7c63ca32aa91ee7480e3b29cc4e63cca1f71daf286c2259c9d23a98155064a22Virustotal results 26.32%Heodo
2019-02-11PAY7050253192205676256.docdoc 5d5ba9f5bd3057f7501e53f61e8308d09eab9dbe2fb75ff4f3be5d4b97847263Virustotal results 27.59%Heodo
2019-02-11US392769904451.docdoc 4c1c56bde40e88eb6c18e59119548f37f1546fd0705d5ced00e0574283b9848dVirustotal results 28.07%Heodo
2019-02-11ACC31391013596554.docdoc 5aa756caaf652db7e3fd210d747e3b707109250be6c6ee4bc7d59cfed36e905dVirustotal results 28.07%Heodo
2019-02-11US70971264496.docdoc 58f1428946246a2d964f304ab60a6410d2c107bb65ed24734674bbc2915197c2Virustotal results 28.07%