URLhaus Database

You are currently viewing the URLhaus database entry for http://waghmaredd.com/apmctoken/h4l14/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:257456
URL: http://waghmaredd.com/apmctoken/h4l14/
URL Status:Offline
Host: waghmaredd.com
Date added:2019-11-22 13:12:16 UTC
Last online:2019-12-19 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-22 13:14:05 UTC to dnsadmin{at}alchemy[dot]net,abuse{at}alchemy[dot]net)
Takedown time:26 days, 18 hours, 32 minutes Bad (down since 2019-12-19 07:46:08 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-23this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 20.34%
2019-11-23abnvm7ew6bamio.exeexe aaee3fc5c5e3151df7ef982719c2a59b51e27840742b30cd4a79fec98903452aVirustotal results 8.82% Heodo
2019-11-231nn56fh8s0n.exeexe 878743f1a8255a60838afd35cfa7162c6938dd655a107b3bb209c81b1d6d6487n/a Heodo
2019-11-235bui48ebu8sayz.exeexe 892be7a4adc4904716fe56d5390849fe568124e20ede094b09207beafc6dabden/a Heodo
2019-11-22i24gcxn7hs.exeexe c9efbfa91a66e17f0e3876480df7cce2cece323021d06121cde4471728a9c4b6Virustotal results 10.14% 
2019-11-221coobk7zmca.exeexe 3e2a7705c8834b09c8ae8182e650aec67f0877d8292182bc420a914ba89e8559n/a Heodo
2019-11-2264pba1lcs0605ee.exeexe c01392903d2069f0c4124dc1b3c1246ab11ff50ea30723dcc04ded80e0855487n/a Heodo
2019-11-2292cafhiukvm.exeexe 9b69fa63a8be82f9ab39d71b96252fad806655983a911c4234c1326a02272ec2n/a Heodo
2019-11-22iil241wxn0a.exeexe 3bf910917fed20cbe80de989d35b9eef7224d442781f0dac0755e288ff1e60f7n/a Heodo
2019-11-22kv3xbz7.exeexe 1f51869cf375c556bb68787580d095cf0f89e40581b4b3df919ac86d199f8998n/a Heodo
2019-11-22v9sad82n4.exeexe 5e8b4e3cdd2aac64e05c7dceb31bba4b44caf17dba0422830d5f05af6e629311Virustotal results 20.29% Heodo
2019-11-22mgp606.exeexe 8c5f5dc81c352531ac90edf71270fa58e460afd0dbd144ddbfe255ca015e5414Virustotal results 11.76% Heodo
2019-11-22rou17tvqefcgbx.exeexe 6de3e7ccb8d00ab2953f9c71ab5524af242cc31eb1fb3968d7b9651faa0a5cb8n/a Heodo