URLhaus Database

You are currently viewing the URLhaus database entry for https://amautatravel.com/cgi-bin/WhWIic/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2103612
URL: https://amautatravel.com/cgi-bin/WhWIic/
URL Status:Offline
Host: amautatravel.com
Date added:2022-03-18 10:40:07 UTC
Last online:2022-03-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-18 10:41:07 UTC to abuse{at}ioflood[dot]com)
Takedown time:10 hours, 26 minutes Good (down since 2022-03-18 21:07:43 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-18eMi5pQUz0LQCDekhVWyGmAJpjfI7n7.dlldll 103f6f0d180ee9dc918237d79ecd84638ec3969a8e709bade6e6a9e6d99e87abVirustotal results 16.42% Heodo
2022-03-18FGZtt7tOv3Xd45bkw.dlldll 1675cd491cfac19ad6a45ad4fd3565d45c888a13fe0c84ae298808aa8b44df62Virustotal results 16.42% Heodo
2022-03-18CVkchCUvwGwmccCXvRGBW.dlldll b53fa38f24092d3523f53c13485ca0d03fbfeb5929c6f6c20a8087de4b90e174Virustotal results 33.82% Heodo
2022-03-18KRIHdpTh3ogYOytP8iZmrMLUp7F7i0WR.dlldll c075475fb539f1a1b4ab836d68a37b7c403f659974ff52efc1077e803c97de46Virustotal results 32.35% Heodo
2022-03-18oxJOYWncSGWqv6ge2fXza4.dlldll 0f2df867b8fa85c1a5f89c45752be889cf6f890b70166b63b0aa47f526b54825n/a Heodo
2022-03-18dHaDQM7MZGOWzLxlA9Z.dlldll abe13cd7c4068fd758063ab23fbdcf8a9bf1f6f4f9441642a9dcfb786c8bfd12n/a Heodo
2022-03-182y7nCBtnNA7NFZAEOY.dlldll 4b53265e4261c7128d1dd6e9ef8036bb6acc40035c7d37884932eed9cfed9029Virustotal results 30.30% Heodo
2022-03-18qCUaD4vYuZKk2oMnETeHSeFn3IN5JfRVrI.dlldll 5b59d5891e381efd72415555a42b1196ef755d70ff66b830e1ecbcd807cad737Virustotal results 34.85% Heodo
2022-03-18TxincBaDatInrYwJMWBYg8Ee.dlldll 03d79294bfde1d3c3c7d9a220049e1873234483335fe08803cababa351c42ef1n/a Heodo
2022-03-189i1LuuZYNN7oFBYXFDts.dlldll b4e57f1d2dbc600b5691fc4b98385706e77513f6fd7c1c4b6f3a9719f487cca2Virustotal results 30.88% Heodo
2022-03-18AQN9XE6JhfiSrYM.dlldll 5e1efa0f6c716fc6c7cad4caa0daae9e98a21a1b90c96e2a1e6cb6c3f97250c5Virustotal results 27.94%Heodo
2022-03-189uMaJb4OXVn3HlZHwWqpV.dlldll 5032eee2b365492c21c3b78fa3b18c681cbd451bc6e9e415f109f3a009bca8b7Virustotal results 30.30% Heodo
2022-03-18Ur9Eq68FJU11TZvCKGQIl4wDB26LKX2O.dlldll ce759b924d7e320c2d7f2846f74a3da97ebefa02c49509918c012e08903ee009Virustotal results 28.36%Heodo
2022-03-18Vfg2t76MSB.dlldll 52f950a6c3f740224185a57346044df7bd0cb3d43a6eb2e5f151d5dd9a93a231n/a Heodo
2022-03-187cRcgvjjsMYdUD9KMUta2HVljzV.dlldll 99f7ab59e661b2c930f78ca16694ff9b79f3ee0ee377f765d7a75715af1931caVirustotal results 29.41% Heodo
2022-03-18dZ2VdCmoj73B.dlldll 112c33df42d3d43aa149ba94a1cb4485e88e1361d9b6c80eabf9a929c0dfe3a3Virustotal results 26.47% Heodo
2022-03-182RcdgvJt2D6sqeVOQpbwdKLl6.dlldll d303983f013d721e360c85bcefbeef762f3deeecc416c26570dabe2b95ab07caVirustotal results 28.36% Heodo
2022-03-18JspRSEh5qc0c8SzcSHxAzCcwWNyKKZpPSk.dlldll 9a9f108b1a8d3189527b4167ba1fb8508320ffb3e968cc01ffba81a0d001afddVirustotal results 26.47% Heodo
2022-03-18ZDe0rZuCJ.dlldll 2e02733830d79de188144e8bcd2dee36009a86519a763d8f9299d1815bc7eb1bn/a Heodo
2022-03-18YxJSS8OtC5CzSHpBqFPghprWO0ON.dlldll 1f09cad84e44fcc4628a8c84bdd95d5bd4c2999d1451b09ebac27ffe0e183b12n/a Heodo