URLhaus Database

You are currently viewing the URLhaus database entry for https://jvmahlow.de/wp-admin/ZWfaMcJmjYmgfATQmTZQGPGEYjjEJB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:190538
URL: https://jvmahlow.de/wp-admin/ZWfaMcJmjYmgfATQmTZQGPGEYjjEJB/
URL Status:Offline
Host: jvmahlow.de
Date added:2019-05-03 23:38:01 UTC
Last online:2019-05-06 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-03 23:40:03 UTC to abuse{at}ripe[dot]net)
Takedown time:2 days, 8 hours, 35 minutes Poor (down since 2019-05-06 08:15:24 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-04Document_28320632173US_May_04_2019.docdoc 9547c3f40f790fab370c5620245c7736282c4931b82100c519746d8f3b072bd8Virustotal results 33.33% Heodo
2019-05-04Document_21342788356US_May_04_2019.docdoc cf3d4fc7080d12f23a1a7718b0fdbcb958eef9121a01f094080652c4c5af354cn/a Heodo
2019-05-04FILE_836583043974US_May_04_2019.docdoc e46ab44563f129dfaae10e440d99832bcc0058052c2f8452d4e22f76a86619f9Virustotal results 33.33% Heodo
2019-05-04INC_2244769511US_May_04_2019.docdoc d58c1fce018c99965fb2c06ef7c4c3e92be7290f9338741e652b99394eaf8d19n/a Heodo
2019-05-04Document_0885750750US_May_04_2019.docdoc 57a5bbcdb5c82c0ec00aa7171455f15b71140821c09c757cc99cce411dbd3cffVirustotal results 32.79% Heodo
2019-05-04Document_03996913615US_May_04_2019.docdoc e35c59d2dc2d98f655064a3efc2e7a994e4efe4628f60a06e84fc079d8c2fe91Virustotal results 35.00% Heodo
2019-05-04DOC_261905874227US_May_04_2019.docdoc 41455b1035cfa169e177dfc169342186b612047c266be25ba3e8d7475879f99fn/a 
2019-05-04LLC_3742935094US_May_04_2019.docdoc f29605f7da73e128b8c8a3b3c984b6d2fad00a690d29fe40e88712fa1cd4c943Virustotal results 30.00% Heodo
2019-05-04FILE_7848156608US_May_04_2019.docdoc e0de872319d3b08cb7322884af7dac8f10632fec564862c9c6364ff2c01a07bdn/a Heodo
2019-05-04FILE_256799134651US_May_04_2019.docdoc e308c87030596d6f208f7166d05482820d0218e2d2f2dcb4d2b95044022583d4Virustotal results 31.67% Heodo
2019-05-03DOC_60074319954US_May_04_2019.docdoc e5aa5b51397436303dc0f190a2c8ff026d99e7c36c728ed657cd284eb62c623cVirustotal results 33.87% Heodo