URLhaus Database

You are currently viewing the URLhaus database entry for http://ashamedicalsystem.com/1dgdm/942YLPAEMF-1800/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1992507
URL: http://ashamedicalsystem.com/1dgdm/942YLPAEMF-1800/?i=1
URL Status:Offline
Host: ashamedicalsystem.com
Date added:2022-01-20 12:18:04 UTC
Last online:2022-01-29 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 12:20:34 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:8 days, 17 hours, 32 minutes Bad (down since 2022-01-29 05:53:24 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-219089_01331040.xlsmxls 64c6ba33444e5db3cc9c99613d04fd163ec1971ee5eb90041a17068e37578fc0n/aHeodo
2022-01-21CL_11892690.xlsmxls b0e9d2148a1c5ad60a5ccbc0c8b753f7c81e298cac18059db3c3ed66a04d4068n/a Heodo
2022-01-2140752830803574.xlsmxlsm 4170fd2e1e20be004dc4fb1490bd16ce9bd092ec9d1048e6ac0a63d10c7ba255n/a Heodo
2022-01-21EET_03647.xlsmxlsm 9bb2ebea9b5a85ffd22e2f2f97a07e9367ddc5ddcaa086c8903c57212273548bVirustotal results 35.00% Heodo
2022-01-21146875027321.xlsmxlsm df43427d915757b0932c26b7029a6f1bd5602383b04d075ce0ad95f40b1c2e19Virustotal results 28.57% Heodo
2022-01-21JEN_67390.xlsmxlsm f7f344862e543ce22b540ef4bbab44ac1dbd786c224550cb5ecbee3380403ab7Virustotal results 34.48% Heodo
2022-01-219893_02.xlsmxlsm eee95e3bcd72a2d0932acc8c6e46e6b0a4d95a39ab028da3b0c11e294e0faa89n/a Heodo
2022-01-21BL424.xlsmxlsm 733af54ba0a2878f86abc471d5388ac61f838211959a4444ca6307819c4860d7n/a Heodo
2022-01-21OGH_823.xlsmxlsm 6b4e80411216eff0629dfc0ce6788afc2578e22f48613a0664edb46f621d746an/a Heodo
2022-01-21RLJ_51.xlsmxlsm 4765164204e734a59822149f062f898117d41dbbb26a969800d8fc36e80a9a49Virustotal results 27.42% Heodo
2022-01-20ilcybwv-81041.xlsmxlsm 97a52b68f8d7ad41ba580f95749d7d810ce3fab98d8ea92461adfee77cfa9203Virustotal results 25.40% Heodo
2022-01-20SLEAU197.xlsmxlsm 782f99cf1c019d48f827fb6d29e75c842fceea0423bbddd81620697d366bfeeen/a Heodo
2022-01-208102745_6192666.xlsmxlsm 200e8f491dade178eca83bd109426425ffe7ca9d4baf974a204e3835c56ceb2en/a Heodo
2022-01-200990-079145290.xlsmxlsm aec2322328224504e216bae76697e68ec37167ececb7693615d72235044bf28fVirustotal results 23.81%Heodo
2022-01-2036AZUXUMGX4936653.xlsmxlsm 46dadb348869cda14d38466d791ebf6c906f5ec26cc305fdca50921785f48b20Virustotal results 23.81% Heodo
2022-01-20532859.xlsmxlsm 6b010b591c50b68c8101ed6ffe62e903c6501ae17d1b430a904288c1391d4482n/a Heodo
2022-01-20zKh-621.xlsmxlsm 5eb512924e585833ee9f0111efd74c3e3ced26d8a78db2b71d87bb6c9f684791n/a Heodo
2022-01-20X-196.xlsmxlsm f3af1bae6675bb7eff796079a60c5a67ec86892f1c09053d2c25fe7d9fcee836Virustotal results 29.03% Heodo
2022-01-20005254380_297906708.xlsmxlsm b1551887350e6e3d73f1d159a97f121cdb3d5b3d9f151de703c313f247958248n/a Heodo
2022-01-20B-232.xlsmxlsm f3f1542a86bb2d668046714e3987278506d3308023b1cb398efa9573d2da7776Virustotal results 23.81% Heodo
2022-01-205488877787370.xlsmxlsm 1bccdaed8a9d03e7c5a5f0ecd9ca25e942077d1be538087e6451cc3030e37b8dn/a Heodo
2022-01-20DDaU24.xlsmxlsm 7429c9e25f9d5b509f78af97a0f595fac9ce8122ad4788c17087360e06521b2fn/a Heodo
2022-01-2003_0820781.xlsmxlsm f48ce531d75c5080dd92c721b92678a75a2be77b9c53d1a33d5539c695d1e614Virustotal results 23.81% Heodo
2022-01-20UJ_659073753.xlsmxlsm 8ca261137fec414bb9066e12a3b88f3872e87a71d57134c1ee8331a7c0590965Virustotal results 22.58% Heodo
2022-01-202626860-669.xlsmxlsm 47b55d5918804812bdc25923b93b4d42f3f5fb005f755266aba09ace6d636e20n/aHeodo
2022-01-209000844-0681694.xlsmxlsm 54dd7b43faf6af4521533712663354a19b6793199ff1fd6b355828448b1cce66Virustotal results 27.42% Heodo
2022-01-20480-6.xlsmxlsm 7805fd902552d2c362cec5d35c3ab11be2ecd01d5932757e4f175b5f9d21ba1fn/a Heodo
2022-01-20004375-07024.xlsmxlsm 2ef3416e562bce54a825d048a989566f6f14e3f396d453e6efab5664d6066b3bVirustotal results 45.00% Heodo
2022-01-20T05427.xlsmxlsm c3f53e74cbc71cf1956d17dae939c2d9f31a1c2e81328a3ca88ceb1e3bf652c0Virustotal results 26.98% Heodo
2022-01-20630080601-71794.xlsmxlsm 24466c9b7124aec9a583ebd09b6df592c6a2eba41701a9f78a6ed1142e708614Virustotal results 25.40% Heodo
2022-01-209412962_3718444.xlsmxlsm e612d546205aa859563388f97efd28b24ac64d633c059f4dc746bff6729d1647Virustotal results 25.40% Heodo
2022-01-20645348FUALGPJYQN29031.xlsmxlsm 46bdf6ee62843383d15200ed9be277d08a6181063bb788c617472cc5e6142fe9Virustotal results 23.81% Heodo
2022-01-20JZ_60487.xlsmxlsm 57933fa64877cd7abbc18abd28ab60ac340b94c4f00445e8b98851108d6706e1Virustotal results 28.57% Heodo
2022-01-207376650-3507.xlsmxlsm 8440eb113e9093c7bb2f228ac7cd77334e4168cbb32dd19d86f2f49cc3466da7Virustotal results 29.51% Heodo
2022-01-2060043-027055686.xlsmxlsm 42eefcfe7fff0afcdc0bca565d1d1dd9cfaae1167d9d0a9ca49e0389d53ed46dn/a Heodo
2022-01-20L527451.xlsmxlsm e4b4b4aeffb795fbbac1cd7bf7465c6fd98c0906401fdb3a90ecca0ce903b3c4Virustotal results 30.16%Heodo
2022-01-2012685_74333.xlsmxlsm 19d1c6a37f4b01531b66ec4b77e6479907d637b4bd18431ace83635eb4d07afaVirustotal results 30.16% Heodo
2022-01-20ymlx_60360466.xlsmxlsm 5c4f33e22f9def7f7fea863e08c38f6a8b4ea9fcc78911c23bb54c4fdf4590e1Virustotal results 31.75% Heodo
2022-01-20MKZXC-763.xlsmxlsm 1b8a7503b95b685e1c29207ac2a9a9d75b188abfc9c492e670eb365377c1ad90Virustotal results 33.90% Heodo
2022-01-2048_873117.xlsmxlsm dfa1de096862a3281db07782e1a8365a37fb07c94cd5b390ea1ba9a0e202d507Virustotal results 28.57% Heodo
2022-01-20MJ_522051.xlsmxlsm 8f1c5f756658a90d9007b111594547d054cfdb487aefa255156d07fddd7ee016Virustotal results 28.57%Heodo
2022-01-20156373859-9668.xlsmxlsm 3b4c7690fa48369fdc9a684e697c5ba23a23d5e89955484364a79fc0e74c99deVirustotal results 30.16% Heodo
2022-01-20838915320.xlsmxlsm 645e264c2f657e1f901918767938090cbb4403348a8eb2a6c4eca245175dbd18Virustotal results 31.75% Heodo
2022-01-2014170234.xlsmxlsm 37c3cbe89b92c8cee51b59711fd9d0f93edbc1de99811347b51cc46ec5eb74ccVirustotal results 31.15% Heodo