URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ama.cu/jpr/00YpKFEZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2026003
URL: http://www.ama.cu/jpr/00YpKFEZ/
URL Status:Offline
Host: www.ama.cu
Date added:2022-02-03 09:03:18 UTC
Last online:2022-03-14 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-03 09:06:19 UTC to abe{at}ceniai[dot]inf[dot]cu,grimany{at}ceniai[dot]inf[dot]cu)
Takedown time:1 month, 9 days, 6 hours, 54 minutes Bad (down since 2022-03-14 16:00:54 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-05ai3KFReRu7.dlldll 4c2bdd74646eef5664aa5e0962c09e504ebc05d2b8bea2c9e7202ab1ee7ee252Virustotal results 50.00% Heodo
2022-02-05F6QYpYieG.dlldll 3e4fb2c2a4de74abd0b476776711a808f57a97ec4341f3623fa56732256e7da6Virustotal results 49.23% Heodo
2022-02-05AnIFs0hPO2Rre.dlldll 2b1cf2c41d53bd1a1e9c41cc61a45421ef80dadce6eca9f9641efe2d4948072an/a Heodo
2022-02-05ozfSKEK.dlldll 6643c7cafdc0558e6fb2b3848e5c594ff80759dcfeff6a50707c350c69c7d594Virustotal results 46.88% Heodo
2022-02-05usw.dlldll 9074710b65fe28a347168ffc0c905073a67aa490113bbf2d59b5a75c1dcd6f58Virustotal results 47.69% Heodo
2022-02-05iPqemVRufHq.dlldll e99522a53200d678b22f3de8171accedcfe74b8407bec86b2137f25f40935f49Virustotal results 44.62% Heodo
2022-02-05C0svmnHaC.dlldll 25cc9a1767b8fc32326a6e4766904abe4c41638c723f73893d5e6ecf2a0fcd77n/a Heodo
2022-02-05Ukjer1D5n.dlldll 09a7e5d80d3342d71df5c5c8caab28c4a7603f1b547516d1c03b2f9fd06c34c5Virustotal results 46.88% Heodo
2022-02-05luZdt.dlldll 7862f53cd54d54a21169279d6b4fe5a5cefeed13732bd8a1787a8693ddcd740fn/a Heodo
2022-02-05Utmg91E78zgFe.dlldll c82496c1e7835c708f6c92226524124e70d6e6af163e4f58861f81689a15d1b8Virustotal results 46.88% Heodo
2022-02-05HKA3L3JkGGqDdtfU94.dlldll ba87df2dc4cbbb37002fbca701bc95b94640c441a03866496355c4cd24e2f016Virustotal results 43.08% Heodo
2022-02-05IG5fmbBJ8bUYyy4.dlldll 5fcb4919e160b7f0f0d0f508a37e8740be48723864c8d7efe2d9a32e0ace3c84Virustotal results 40.00% Heodo
2022-02-05mLZa1e4Tx17Z.dlldll b261c6329a93565243b0f48a3f0bd6f7d084e4814d13c821966cd7a6d90b2f9fn/a Heodo
2022-02-04CLSTZm.dlldll aa314ba209788dfaf592e28bb0a785835924557f85044915e110ddec08b13f20n/a Heodo
2022-02-04LwZADepYhjI300WMAc.dlldll 5125f836269535d7c07068244da02909e124690dfb7aaba33edf1f2fccb82e72n/a Heodo
2022-02-04TtznLxYuTs30.dlldll e9d78a2271cf3e41dc84134df1d08322d1b708c31c47726147d69c224139b694n/a Heodo
2022-02-04P3dUmJJMKdxKa6nZ.dlldll 81624b997e83e9bf5547db306fe36c1035875b2d3623d598ff29f60c4890c627n/a Heodo
2022-02-0468bkiKVrOIg0km2.dlldll c1c7bf7337d1d36510e9725abf4450e33caa1a1a2e6833e2c85c2120839014d5n/a Heodo
2022-02-04SFVJNwEx.dlldll 922772575662c9ca6739b1281a349ba0dfc379d0ca3ab1c355687771edfa2146n/a Heodo
2022-02-04Ks0P7Hb7.dlldll ff66dae99bf870d76d15404fabf9d5279d7c1200f8f39bd6ebcb497cb1089735Virustotal results 39.68% Heodo
2022-02-042nkS3Zn01Cm.dlldll a7fb6281f76803169fdf49e21e88545f1c4a6fc57885c0cae70b2504f7e8adacn/a Heodo
2022-02-04wAdmoYnse5AJw.dlldll 9c486d3f0b2a5c346cd66dc70bfd868625ea233f443d9c408e1d8f2c26719954n/a Heodo
2022-02-044ttpad.dlldll f18ae4575aa4ca751171d8c23ce248ae4a53fd3cf08090e7abbc66cb662746f3n/a Heodo
2022-02-04yDsYNLrqOTeYEEin.dlldll 818d29fc5d8196cbddf3c7b20418ace358bf28250b1480683115b5884d9791fan/a Heodo
2022-02-04Gxwt.dlldll 8e0cdc0b95552d13ef0506d1705fb7381ab9cbfd4ce35bdecee79401241dc058n/a Heodo
2022-02-040LG.dlldll b5bfda4ab37c3a14bc70df283e9e9324f38e125e318fd40462c55c41c2354f17Virustotal results 31.75% Heodo
2022-02-04R73oiBO.dlldll c34aa961984e2df0e911b50335e52e36fe1e986ff30f7a53e9c50d960c2b8096Virustotal results 31.25% Heodo
2022-02-04sfUioXSHl5jKFZIR.dlldll 697e6812480c702b2fc49e6e4722a3ce964673fb7b2b80499a96de3c4bec7a60Virustotal results 29.69% Heodo
2022-02-049NabsjvvFFOq.dlldll 97dab46d0c52c38cbc0ed96ee3c69b20539c21251e8a4d2f8134979c7a697668Virustotal results 29.69% Heodo
2022-02-04yyxN0K0OLQcAO.dlldll 34f956f6be0ff33936c1035aedfdc451f1293cf0feb66d8c10eb47f07710aecbn/a Heodo
2022-02-04DcAmYLk5srdBPEL.dlldll ff35f179c8bde0c6952fc50401ec06a1578c38ad5c8814ee99f0cb9fd40e1a7fVirustotal results 40.00% Heodo
2022-02-04QPJmuiiNq7SJJ7sJlk.dlldll 51da1feb7421fb1d4b6cf8155e21977f3383b1f0517a5a30bb597ec0c5653f88Virustotal results 33.85% Heodo
2022-02-04oTVSz66PUvKNV.dlldll 8683d2bbc792a226d1e6a32f792ab28313d1649d11a4b5509dbe6be18c4845bfn/a Heodo
2022-02-04V3OtZL75VdO2.dlldll 22caa98e45d833123457f67b05a371b3f97127823a996172600ec531c54c6a03n/a Heodo
2022-02-047784LbR3II4EnhDN7c.dlldll 6fb424e3f3f728fa42b9b718393f1d3429f651b6589e38cdf11c5023e5254311Virustotal results 35.38% Heodo
2022-02-04ir.dlldll a1a9a709e2123b4cfd1d6df7cde635eae33afe0ed9284923a9c945aab008a946Virustotal results 34.38% Heodo
2022-02-04ZaG33Z1R.dlldll ed63d1d9c06ab121f24a28c65d9311a3d2e7db82d4e9f2f979b707b5c085b641Virustotal results 35.38% Heodo
2022-02-04kItnBDmJay1Ud.dlldll c89e6b5219c6225e3268389c1b17568c39a8749c831d19dbbd9f036e90010307n/a Heodo
2022-02-04bIrsEeeB57YM4.dlldll 677c274c86f5cea310c6c934bb391ef07d6117b23adcd435eab28969fd18f00cVirustotal results 32.81% Heodo
2022-02-04G.dlldll 46017df83072d08e9a2f425e0afbe1b2e0cc8c6008c7e75bc0e4c1abfc54f12eVirustotal results 32.31% Heodo
2022-02-03OlvLgQ4yUHQu1UeU.dlldll c0bf578de1cd5a28bc6808bf8c9751e179916cae6d40c7560c5ff34426c2a6afn/a Heodo
2022-02-03iQtWB.dlldll d39aca80fe6c5ca731ac24fd4736440a0cde846bfba5016679e7d586b5cacdd7n/a Heodo
2022-02-03OTJKksErF.dlldll ce0d48af3c563e4319e62c8b08bc442df54d5753ee8200b39dfbbb52a6e50040n/a Heodo
2022-02-03uQZE6.dlldll 830d95cc7c6cac1f3d6884cd59e9921a92eb4e2ad8856d8c655bab70397ba4a6n/a Heodo
2022-02-03v18Sgyi44BGA0.dlldll bea59407590c141f9c2c7e7b6d7ee623a8f4441e12e7c9f4763482a7f2f43084n/a 
2022-02-03TEM7T3nzC8FLqD.dlldll ac10139c80e0c7bc1abfb54fb08dfef39e94f0bf17d58ff65729605b87fd6973n/a Heodo
2022-02-03eJ.dlldll ad36e64c766918f6f850b68eedcd33ff680da2cb8262246cada097777e601003n/a Heodo
2022-02-037g41z.dlldll ead59dea5f6a2eac72fbd330fec2149aed3eb46e981b2dd5ad3557467bc1c3c2n/a Heodo
2022-02-034TddgMZetSP.dlldll 93535adeffa3ee41697a8befd2c23ab283655426c58288d6689cd222dc279643n/a Heodo
2022-02-03LN1hsteOUsrl.dlldll 342c204457c59dfa89bf82ad084fc583d0ea8541b7259ae840f45d6873956eb5n/a Heodo
2022-02-031OFGxmv.dlldll b4f284526e1971b3628feacd69ad828a877b3a59f26c03551bf3e0e11831de3fn/a Heodo
2022-02-03LC4EYDGTOQZelrNnVK.dlldll efee39985ac3908ebf6936119e78fe6e228d42ad707659e1217c5c09cfb17080n/a Heodo
2022-02-03QY7yntCx2JOv.dlldll f3fce346bdc9f150f8196c951d7e14e402aaeffeb27dbeab03df23784b90ab86Virustotal results 53.85% Heodo
2022-02-034F3zvz.dlldll 11cbddc2f062387987e73925f06423939ef3e56dd7d02fa3f5174ceb3d1fef06n/a Heodo
2022-02-0308a1uJV9xwAUu69ESo.dlldll f91d264cdfab4da08f0cdff835038fc4df461ca2193f81ff2eb03b9abb6a176fn/a Heodo
2022-02-03ETc2.dlldll 5bc8e9c299d206f62565bef8665bbdb61e0be1e62db9531ad2dd50afaa01beden/a Heodo
2022-02-031t2914Knm9Fbh35.dlldll 9093127d488b86a30ad2295bc2ebc52bd4b223539af87b2afa8c125862f8c0ddn/a Heodo
2022-02-030aIru.dlldll 56bd0f403f08c8d57c7194b3a8e324edeef0bbfbf9ec2e658f00f00864e01599Virustotal results 47.69% Heodo
2022-02-03TVXwYPvBu.dlldll 79317616dc225a98585f25465b3813e737642a951fa434af19a1ba2353348e83n/a Heodo