URLhaus Database

You are currently viewing the URLhaus database entry for https://halaamer.com/sfiq/QmwA-c9iqwiZk5nnGD9O_OJTCwKmIj-1u/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:178948
URL: https://halaamer.com/sfiq/QmwA-c9iqwiZk5nnGD9O_OJTCwKmIj-1u/
URL Status:Offline
Host: halaamer.com
Date added:2019-04-16 17:44:03 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Not blocked
AdGuard :Not blocked
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-16 17:46:02 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 months, 17 days, 21 hours, 22 minutes Bad (down since 2019-11-30 15:08:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-11-30n/ahtml 80fef63a4af3394287fe0316780f7f6198df0397ed8dcb9639e73e8da19661ban/a
2019-04-1775578639_2T_20190417.docdoc fefb741d83c1183de4d36cd09ce6d8f0d8cdd650bb81fe850249dae9875477c4Virustotal results 22.41%Heodo
2019-04-1785949364_VI_20190417.docdoc 3550884afe09106b97b5b292849c061da9e51cf6c5502e8b80a2bb669de9aa07n/aHeodo
2019-04-1703371247-O-20190417.docdoc c1b0c4f67991d3ab081a20b0d018ee2bf4d310e751b44625ee47be0f9e9265bfVirustotal results 46.55%Heodo
2019-04-1778785227893-07-20190417.docdoc 323153d98abb66d7f847dafa200187b6998dfbec52a13bc8e5db2f22f1cb2240Virustotal results 47.37%
2019-04-1721032082285-8-20190417.docdoc 37d515986ced4f9c7d52fe88dceced589f05ba0e858497caa70ceef805f6171eVirustotal results 42.37%Heodo
2019-04-1770182643-S-20190417.docdoc dad7b2ea595c513712858b7af93d5799ba9ea2029568b03ca100e39b48875a26n/aHeodo
2019-04-178610278-R-20190417.docdoc f630bfbe4b3c8275ad01aa4c5b0cb0997e7af5947b64dad6351672a6aa578c39Virustotal results 42.11%Heodo
2019-04-1706052531311-LV-20190417.docdoc a145da157680d560fee76c85a1a04c2ec90f8f45e8e48a5afb2ce39e2d4dd525Virustotal results 37.70%Heodo
2019-04-173979021561-0Z-20190417.docdoc 277f3c8d2bebb7ba81bc20c3f884f7ba97fa475595a794b701718526c739aa05Virustotal results 35.71%Heodo
2019-04-1715637261-74-20190417.docdoc 36a99335c6d27af2f6e4b23062c90335dae2d995592cc45eb67dc1a3e47b39d6Virustotal results 35.09%Heodo
2019-04-1789858139-M7-20190417.docdoc fd6b351aa651a795ccc36478ab92b5fb40497dc6e48bc99f46dcc8ff9ef8fc49Virustotal results 32.76%Heodo
2019-04-161093289_EW_20190417.docdoc 575dde62d6879599051db95345289d694bf6500cf6e0200fdbd87665498ab758Virustotal results 31.58%Heodo
2019-04-16511033351_6_20190417.docdoc a96996cf8b9f60a7cf268b030e84e316e1d3e25c4f3d290c918c059a541368a1Virustotal results 29.31%Heodo
2019-04-168923609760_8_20190417.docdoc 3df4fa5753f11923542f444cc8f1944b2a3a1e091e558a6a2a1c5a24e3492785Virustotal results 30.00%Heodo
2019-04-16171320916_7K_20190417.docdoc e779fe9a8d830df1f5bfacdb244e642cd2e0a7df9e90098f251416c08dc0e6b8n/aHeodo
2019-04-16824740524_J5_20190416.docdoc de36dc4b54247a8172cda67b22d570a1b6c67b709c2d0ef6ebd9d3878d87dde2Virustotal results 36.84%Heodo
2019-04-16352478241_9L_20190416.docdoc c5fd770032c9c4c15559f6fe81f54b73588ad35bb8907d68a0585ec4f004fb68Virustotal results 34.48%Heodo
2019-04-1674838824-4-20190416.docdoc 3e5a613d76696cb50ffba9d7e6c0fd8fff94b51c9702fdc00548ca08ad03f6e2n/aHeodo
2019-04-164336464_A_20190416.docdoc a505fc37d8eb990b3d8567df5fa28f8c217fcbf0ad2b69fbad4d3090b1c3927fVirustotal results 32.20%Heodo
2019-04-16756872109_K_20190416.docdoc 56459d52dd7a5f3045b96edabc33e19ce54b76ecb8c499d406acc77a1823cd91Virustotal results 32.20%Heodo
2019-04-1611302323751-6X-20190416.docdoc 362667f98d8010c7e4d3fd6b093da15e86fc826d9039878c94f2359f94b7167bVirustotal results 32.20%Heodo