URLhaus Database

You are currently viewing the URLhaus database entry for http://anb-product.com/wp-admin/GLmco-g6dy07MZAAM18fS_FtaDhQDbu-HPk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:179499
URL: http://anb-product.com/wp-admin/GLmco-g6dy07MZAAM18fS_FtaDhQDbu-HPk/
URL Status:Offline
Host: anb-product.com
Date added:2019-04-17 10:10:08 UTC
Last online:2019-04-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-17 10:12:02 UTC to ipmanagement{at}amazon[dot]com)
Takedown time:4 days, 22 hours, 18 minutes Bad (down since 2019-04-22 08:30:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-185156742-IJ-20190418.jsjs da6a4f6736fdc27c2450111f86b6c1d87ef69cd8544465381870accb54f1d852Virustotal results 8.47% 
2019-04-18444951927-PQ-20190418.jsjs 3f746e4a3ef98b041e6d69b9adae787c2b351e24ec3fc8cf150ddeaa44a4f293Virustotal results 3.57% 
2019-04-187720166158-6-20190418.jsjs 73da7ffa3619e3e8afbc2334219f1bd4be18b4128d835e2dfa9db8e3a9e239f5Virustotal results 7.27%
2019-04-171529535891-2-20190418.jsjs 8b1b62324101cb93445ff7f6901e29fa08736ccb407948111e8babc53f3baea6Virustotal results 5.17% 
2019-04-1734845248459-UB-20190417.jsjs a0658a5b7ae031632d05aa301a55fddeaf02d97e90f79d18ded020999f9a5679Virustotal results 11.86% 
2019-04-17770781502-D-20190417.docdoc 26ed293e598bbbc392e9a279ca16107df3cae693344100e53b0b6868f3eab1c2Virustotal results 19.67% Heodo
2019-04-1776573736-YU-20190417.docdoc fefb741d83c1183de4d36cd09ce6d8f0d8cdd650bb81fe850249dae9875477c4Virustotal results 22.41% Heodo
2019-04-1707559058110-JR-20190417.docdoc f6339ecff9972ad336d7f8205dca001b36969fa1fe9a0096ee6e4e0adc896b61Virustotal results 22.41% Heodo