URLhaus Database

You are currently viewing the URLhaus database entry for https://nonprofit.goknows.com/wp-content/upgrade/vamz5-y2oljvu-lktd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178277
URL: https://nonprofit.goknows.com/wp-content/upgrade/vamz5-y2oljvu-lktd/
URL Status:Offline
Host: nonprofit.goknows.com
Date added:2019-04-16 03:25:06 UTC
Last online:2019-04-17 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 03:26:03 UTC to abuse{at}amazonaws[dot]com)
Takedown time:1 day, 17 hours, 25 minutes Poor (down since 2019-04-17 20:51:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-177615280004DE_April_17_2019.zipzip f46073ee6c1d6f187b3ce287351a159069d1decf7ea1535e183b85db2d590a8an/a 
2019-04-174200444689DE_April_17_2019.zipzip a0e3c40413dfa118c47d2538d7681fec2f0bfcfc89e279b9dc45b02f3dfd2c09n/a 
2019-04-174486882017DE_April_17_2019.zipzip 029b533f57ef69f041dc322152172e865cf51e5778433c0dd733074e062b3f83n/a 
2019-04-179214587950DE_April_17_2019.zipzip 75a8f812f57feae6fbac3904fe6d10d8f5de4fcc15c1efe65e04acf9ff30639en/a 
2019-04-1756005274133DE_April_17_2019.zipzip 8490565fa760441e134b03ef0f21098bc6ccc45c3059bada786d9fc050b49be0n/a 
2019-04-17684734207164DE_April_17_2019.zipzip 5e8b6a3b908a2e98153eb722815ebc984f027dd688f126d990739acd88c02b81n/a 
2019-04-1705589532632DE_April_17_2019.zipzip 6a4ee5a7b39e4c79ce5edeb175fac4428478d9c5c21ecb65f6b12eb7a447bbb2n/a 
2019-04-17123516205257_DE_April_17_2019.docdoc 694b037147343d3a34387a156a549013867c1f5f92fc3b6376447e2c5ac0401aVirustotal results 20.97% Heodo
2019-04-177338568601_DE_April_17_2019.docdoc a5c7ef873c4dff06978f874ee497b2fd958b56e263244febc3b7e53eaa27517bVirustotal results 22.81% Heodo
2019-04-177608823748_DE_April_17_2019.docdoc 71da59481ca34680c6459f5947bd9e90fc7ecb570e040045c5d200bf313d5e12Virustotal results 22.03% Heodo
2019-04-1775140268011_DE_April_17_2019.docdoc 642fe50465ced7e3d59a39e5776dc37e4c500a5cb9363d0c1ca2a7fdd72fa359Virustotal results 22.41% Heodo
2019-04-173296834705_DE_April_17_2019.docdoc 566c79acc5b6aca21ec8ad0859b2f53a1f0d4a00e793b4e6cba5fdb53cb2bafaVirustotal results 22.41% 
2019-04-17197285595977_DE_April_17_2019.docdoc de05a81b032326fc39700039304035f207e806048aa3ac35707e297ae623cf2cVirustotal results 22.81% Heodo
2019-04-1798247300638_DE_April_17_2019.zipzip 7e420f08a74875be62a4e981b1dfd9a1f8cf48af976a389eca26543d4212f6ebn/a 
2019-04-17355218004735_DE_April_17_2019.zipzip 184425d3956d2e1a7512713c92f710e41ea00bccd76e4583a11ad1d94dd985e5n/a 
2019-04-17346350237784_DE_April_17_2019.zipzip d0008d0eea2ad2a80f82f6ba6b9dcf5457250bd79b3284b2308de17612a02720n/a 
2019-04-17730971507805_DE_April_17_2019.zipzip 6caa9f7f4352901ad68339b50e7d3d78b4dd06905466eb039a96dca7c892427fn/a 
2019-04-1779578563826_DE_April_17_2019.zipzip e9206d3e2d1a0c859f38dff5417aba41038320c862729f3baac243186395fc67n/a 
2019-04-17880566972649_DE_April_17_2019.zipzip f962506fb0b3c8146c17712b89906ffd5020a28a203f4e3748fc97640c2814c4n/a 
2019-04-17032838961542_DE_April_17_2019.zipzip 17c50a9484fccb641e1fa38f3782a125b181c6f0babedbf6949dc5218a6d1a87n/a 
2019-04-176967285827_DE_April_17_2019.zipzip 250332d7f75dfec6315e3c0272baf286e55821d42d43120f05b33a5ff8c22c1cn/a 
2019-04-174966925892_DE_April_17_2019.zipzip c87ce3f47612fdc19dd1ececdf80585f53d2f70d29b5af2a73a271547d6f51ccn/a 
2019-04-1704750607519_DE_April_17_2019.zipzip 73f0c6566fdd57967642e75fbd8afaded4dfc801e24c233a1511ab84ce92ce01n/a 
2019-04-172012416522_DE_April_17_2019.zipzip 859d405d35f0ab2e96cbe02c8688a046d79ee75283e165407604aa041cea8fd4n/a 
2019-04-179167634071_DE_April_17_2019.zipzip 31cb8e3f899d975c769959bec2bb95fade27c13b6a9a7c572d929e73a005a4d5n/a 
2019-04-178857761226_DE_April_17_2019.zipzip e901574656e3ff5f3230ba034f783eafb8a148cbc8d81c4d62aa72457862bfbcn/a 
2019-04-176541304058_DE_April_17_2019.zipzip ca64525b9c3044a73500276c416f52ac0c33ac0f1a2143ec00ab1f4198bacab2n/a 
2019-04-178009921933_DE_April_17_2019.zipzip 66887b7b1247f1c6457f869a624facd8e50fb190936375becf739b72178cbca0n/a 
2019-04-1742019871097_DE_April_17_2019.zipzip e345ec518ce144a66ffcb9685b4dbd15727430cf8a5abe2553b777fd328fc4c6n/a 
2019-04-171853826964_DE_April_17_2019.zipzip e13148166df4a688923a7686e050baaeec7f2294ee0584d886b375b1909c9b17n/a 
2019-04-17117927059091_DE_April_17_2019.zipzip 8364dc80af77f01a5e624fc5687a3e4672c4fca9f043afc14b249e80d91e27f5n/a 
2019-04-1689074465090_DE_April_17_2019.zipzip d3382ba092e0b19cccd853380452c9e87e2c14491ce66df7a95efdc1c43ccafbn/a 
2019-04-16892993042001_DE_April_17_2019.docdoc d335a1d0c38e751f9376bbe88c7b18ab19c9459773a6951740a6782676e3834cVirustotal results 26.32% Heodo
2019-04-1645777017448_DE_April_17_2019.docdoc 318647298c1370e2a454acf4afaed6bf692d1bd51759b4a7e0e78e925148f1a9n/a 
2019-04-1696104302086_DE_April_17_2019.docdoc 4b1ccb75644b61d0f3c1df18a238066171bf3f3b8ffbdce21a963a032676bb61Virustotal results 24.14% Heodo
2019-04-1639526126938_DE_April_16_2019.docdoc 3824b2db3b14d88a11d155d0894a6af22bedb3bc12a029f9563344208354aff6Virustotal results 35.09% Heodo
2019-04-169172223007_DE_April_16_2019.docdoc 4f9800723d9da1abd4a9270d2ca1608a8540cbc15ddaa67f2b8a18aa2d75620aVirustotal results 31.03% Heodo
2019-04-1688771213528_DE_April_16_2019.docdoc 141e277b2165595334f404edd83397057b2a4ef8a52eb8edba79203f0aba44d9Virustotal results 30.51% Heodo
2019-04-1671370686196_DE_April_16_2019.docdoc 33eb8eed7c8660a54e9b99e8b8719fa1a83484d5ba41805f1767cd8605d28fa4Virustotal results 31.03% Heodo
2019-04-1656729208646_DE_April_16_2019.docdoc 033fa72fe48a853b99e41ed7467c1ccc488d5abe69dff887b8a6b7b2c5a5452fVirustotal results 31.03% Heodo
2019-04-16738035506909_DE_April_16_2019.docdoc 7fae139edf9512b5788f271e05878e6d556721b4eddd8f556096824c3b9bec69Virustotal results 31.03% Heodo
2019-04-160390287371_DE_April_16_2019.docdoc 7147bcbc0854554068d051c589da76772d019dd8f1d56ee17b6ef90ba54c2706Virustotal results 31.58% Heodo
2019-04-167061057474_DE_April_16_2019.docdoc 020ed32f0c3de6a24817e3326fe676c4e07896c71f9474db5b9948847d8e2873Virustotal results 31.67% Heodo
2019-04-163992196245_DE_April_16_2019.docdoc ebbd8471022a4d525eb5bd3537e6a1688980bcd861300807f5c4a14ec7ea777fVirustotal results 30.51% Heodo
2019-04-1609148009954_DE_April_16_2019.docdoc cd9387ca69fa3aa30380f5e513313980b26805181f235dea5596a7d9b6c21c41n/a Heodo
2019-04-16515821716857_DE_April_16_2019.docdoc 6280cad89edea53c8bd3f428396c3a736f6d67e6f8279026effbbc8f27c35035Virustotal results 26.32% Heodo
2019-04-16216048028859_DE_April_16_2019.docdoc 48c513176b0c56e199f567a5fc4309950fc2a2c9f09365dfa7d879c94d57be8bVirustotal results 28.81% Heodo
2019-04-1638574132316_DE_April_16_2019.docdoc 714cb052a43db82cd36d3b516b30ce2ed91bb5a3041c2721a8cc04d4060429bfVirustotal results 28.33% Heodo
2019-04-1634670023875_DE_April_16_2019.docdoc 90c260b2469174d1c60fca12bc1a31728a1219a71c5f27a5b1cf21db2271f123Virustotal results 28.81% Heodo
2019-04-1649820739503_DE_April_16_2019.docdoc c40f3f595365f71600c24ebe5c2fd245bb7584364c4b2f3f294e1dfe675891bcVirustotal results 27.59% Heodo
2019-04-163053975715_DE_April_16_2019.docdoc e0bf4c6aeb567130478fd998b9bb45ca8ce6d76520107e2088d4c6cdcbff90c8Virustotal results 28.33% Heodo
2019-04-1695303609023_DE_April_16_2019.docdoc 1073385d94089c725063ce1a488c157293e6aa8cd6574597042ad5d5f9f6004cn/a Heodo
2019-04-16021756935997_DE_April_16_2019.docdoc cf34076fe15384682ff04d5a15a94d36af4ff3dee94d651c33c4b4c60731ed88Virustotal results 26.79% Heodo
2019-04-1696848338998_DE_April_16_2019.jsjs e328f1a48cce3e9220c38d847ccea9f81b6135d120bd76b224c4be21405f700eVirustotal results 9.26% Heodo