URLhaus Database

You are currently viewing the URLhaus database entry for http://amautatravel.com/cgi-bin/WhWIic/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2103912
URL: http://amautatravel.com/cgi-bin/WhWIic/
URL Status:Offline
Host: amautatravel.com
Date added:2022-03-18 13:34:06 UTC
Last online:2022-03-18 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-18 13:35:08 UTC to abuse{at}ioflood[dot]com)
Takedown time:7 hours, 30 minutes Good (down since 2022-03-18 21:05:31 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-18eMi5pQUz0LQCDekhVWyGmAJpjfI7n7.dlldll 103f6f0d180ee9dc918237d79ecd84638ec3969a8e709bade6e6a9e6d99e87abVirustotal results 16.42% Heodo
2022-03-18ZTVzBGo59TF3bbax.dlldll 407d06ffe7dc997a77b1d1d9fed6e6ace8c10c10168c38e4ba6d37fc94fde5c4Virustotal results 16.67% Heodo
2022-03-18QKvbRs3zLmsNyG6U9aWDBbkJJ.dlldll b2e065d1d609d4e3f5f9407e9c71495eed8852e5210e8a682825273bbaf18b7cVirustotal results 32.84% Heodo
2022-03-18DcCEMcrxJhjvTKdMJ4k4UxIG.dlldll e0123774ba07aea3d5e3d4930e212f37693130c420006964b63ee048476caa79n/a Heodo
2022-03-18lLAITAWFa8ZPSv.dlldll 74b6342b08e13fc019d5db0ffe4f23804814dd483441b996cf25de31de23e7d8Virustotal results 32.84% Heodo
2022-03-18NN0VFh4sXU.dlldll c76dba138d762bd2300cd92a85642554f3f4b02710b7f35d9fe526a30a96ee1bVirustotal results 30.88% Heodo
2022-03-18g5znzMRwfz1LEHhPgTpStj09Pqxpe.dlldll 3dea2e6afa4382d285a904f22317ddba33cd4b0e76d5d23d3d852da4b633bb46Virustotal results 30.88% Heodo
2022-03-18qCUaD4vYuZKk2oMnETeHSeFn3IN5JfRVrI.dlldll 5b59d5891e381efd72415555a42b1196ef755d70ff66b830e1ecbcd807cad737Virustotal results 34.85% Heodo
2022-03-18TxincBaDatInrYwJMWBYg8Ee.dlldll 03d79294bfde1d3c3c7d9a220049e1873234483335fe08803cababa351c42ef1n/a Heodo
2022-03-18vkwqYTfTS.dlldll 301c112f9581b3e5a935edc3dadc9e4c7f1792b1245376d0e30ebe64fec33bbbVirustotal results 32.35%Heodo
2022-03-180IKVyIVVK.dlldll ea58943995669c4a6d3067fdb8d778320c6d792c2b2dad0a3b8009e44cce85ffVirustotal results 30.88% Heodo
2022-03-189uMaJb4OXVn3HlZHwWqpV.dlldll 5032eee2b365492c21c3b78fa3b18c681cbd451bc6e9e415f109f3a009bca8b7Virustotal results 30.30% Heodo
2022-03-18j8ZoY1KjURRzTv4p7OddLi0Ioy.dlldll d76010ad33b6e41c750c1d95273e5d6330d9b2c07e2b7bcbb9630f1eaa95f4d5Virustotal results 28.36% Heodo
2022-03-18AalUroZ0R7yTpW.dlldll e5b6c06389099b8f35de001e0e481c9afd12f3e1e8107f57079d5e32f87f2d56Virustotal results 27.27% Heodo