URLhaus Database

You are currently viewing the URLhaus database entry for https://augustaflame.com/xqwlsa/Document/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:287419
URL: https://augustaflame.com/xqwlsa/Document/
URL Status:Offline
Host: augustaflame.com
Date added:2020-01-13 21:25:34 UTC
Last online:2020-01-27 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002242950 created on 2020-01-13 21:26:09 UTC)
Takedown time:14 days, 0 hours, 43 minutes Bad (down since 2020-01-27 22:09:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-15C_SP0058423012FA.docdoc 240874ee9ec4803722466934fd13b8f2aa21172a9600a3eef907a1a3be05ed68Virustotal results 34.43% Heodo
2020-01-15RP_77647847.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43% Heodo
2020-01-15DOC_KVZBWED3C8LZQQ.docdoc 746e56dfeb31eb76ca54c4260082c53e799a6cb532561b12c98ee1496f3055f4Virustotal results 32.79% Heodo
2020-01-15G_4055936779790382644322234.docdoc 29c3272b13b9045f8f9d5f1b4692709d88452e9bd66c99249a0ddbb31929f896Virustotal results 31.15% Heodo
2020-01-15ST_IH6BZH99W1J4.docdoc 287ae14e3b1562662edbf0da35eff337a49d911c07fb02c48b681dc3cb8aa7bbVirustotal results 33.33% 
2020-01-15HO0502669082PN.docdoc 406d79f865f35a430a3f1fd8693cc48c262626550022635b1aeeb0e4c39711b0Virustotal results 26.23% Heodo
2020-01-15RP_RH9168792238ZQ.docdoc a5001616f388e579c0c397706d68640fb254f2c426ef92e7140e736753c0455dVirustotal results 24.59% Heodo
2020-01-15REP_748517028473339748925145.docdoc 4f0095c259ca3e1e3f0cbbf9295f33bbeefdf8271b1f3d8b97ee9ba5626eb8e6Virustotal results 21.67% 
2020-01-15PAY_NK0845801811GR.docdoc b07666a2622dbfb1e66370cbafb9829f66d7699864c127f13b0f48534bad819dVirustotal results 21.67% Heodo
2020-01-158448002613.docdoc 4b32ae8462004858fd613381fc35dba30256aa30a4e78721ea4118d32a7e3812Virustotal results 25.86% Heodo
2020-01-15KM4609945828DH.docdoc 2ca72c2d3e5cfb6ea6d21e71bd79055a1018f327fa309037316a83bba6dee090Virustotal results 18.03% Heodo
2020-01-15R_PO_01152020EX.docdoc 9982b18660c6aa9b8419bd84843d2d578fd2afb2516782ac69f0e7f8eee4efb9Virustotal results 18.33% 
2020-01-15C_QUZ_010120_MFJ_011520.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15FILE_ZB6639624166RY.docdoc a7d4e714a1656fa280fa345e1956d3b62141ac7b29d8fc4563c85a5616f886aaVirustotal results 37.70% Heodo
2020-01-15C_486249149099454.docdoc ae2b60bc60bafedcd6cc4203ad3d1c94bc0d338f82bb7aaa4174ca4702b90922Virustotal results 31.15% Heodo
2020-01-15FILE_27234284.docdoc df43d3ce7f6999c2b2173ad2778f9d7c6986c745ea29d67f8b6dd3ed56269ce7Virustotal results 32.79% Heodo
2020-01-15V_WI3269104681QL.docdoc 958b22bd337775f2226fecdcadf9125b8bbcad2518c23d026fd87b0714af1b63Virustotal results 31.67% 
2020-01-15PO_01152020EX.docdoc 678c5ed922797efdaf2fd7c86cfbbdbdda3f748143606d1167925c17d6cf7994Virustotal results 31.15% Heodo
2020-01-14SW_74689658477636103074.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23% Heodo
2020-01-14AP_PQ8716523894AS.docdoc e8e877eb89bc1a478fee7e89597bcac889a3776e27aae4692b63920428f58e53Virustotal results 19.67% Heodo
2020-01-14RP_673700765.docdoc 8cfbeba4189d63e24f257f8d06ae7e8d2f9a54c9fbbd30e385380d356c747c7dVirustotal results 19.67% Heodo
2020-01-14INV_JM7475390429GY.docdoc 5f7898df4f7baa0100b513ef0c2717daebb0f7f506ace5962944f1cc4a495449Virustotal results 17.74% Heodo
2020-01-14RP_OOE_010120_DRC_011420.docdoc 8e692b7b8ff448a117327fb67e83c83e4b0c7a5d20eb50e42a85c8944463de29Virustotal results 18.03% Heodo
2020-01-14ST_ED0BD5X5O.docdoc 9ee85b399435a194b9b67f49143134a823ef4dc87f95970c3516773b340fe9afVirustotal results 18.33% Heodo
2020-01-14ST_21677599540625493297.docdoc 55d3e4f88e1e918a7c0af795665baeef8f3d5841cc79383fd1f20a5455bcc317Virustotal results 18.33% Heodo
2020-01-14INV_PO_01142020EX.docdoc c7e5c2e41fc8b40d84f2e7f684bac7b4c42dad55376bc17289d12a82122005feVirustotal results 18.97% Heodo
2020-01-14O_92146746.docdoc 4e1c36be80c8d49de9d619166b44e070c37538978fd2b281547e1ceb47c90afen/a Heodo
2020-01-14RP_31663988214.docdoc 5b16a018d91f6cc000c6bb710abccddf54f581e3c008ac6b050b3717116e6639Virustotal results 16.39% Heodo
2020-01-14DOC_PO_01142020EX.docdoc 68d4cf5b4876d3a27666509c2ec491a54651c4096c311fc641a51d38c9999777Virustotal results 16.13% Heodo
2020-01-14FILE_053223675.docdoc 59ec07d0dd1c894db31fb29b24652db4caca79e3bb4975d2edf3d3e3e5784920Virustotal results 16.39% Heodo
2020-01-14INV_13095122508659747476.docdoc 751310818624e4c28ec4b15b16a51e5fc23becc210661ea972c09d8c5196eac0n/a Heodo
2020-01-14ST_RRM_010120_WGN_011420.docdoc f8e9758d488a0f17ee9781763287d1451d2c8b0e8bc7faa5f44d861d5a5aa79eVirustotal results 42.62% Heodo
2020-01-14ST_NB5160876357IK.docdoc ecbb7b6901541ceae9e44d3e383729ebb32c5d2bcafb035e9931ffce46112622n/a Heodo
2020-01-14REP_47221767.docdoc 56f51040d9c1665339529cd8bbf3f85c264d4996df08e6b388ae9fadcd88aa87Virustotal results 38.71% Heodo
2020-01-14BAL_L9O1S0O5OG5DR0O.docdoc 7b1a3d9aa0ce52fb438355535ff9009fbe3e6c832fabe5895c4f03777b14c1bcVirustotal results 30.65% Heodo
2020-01-14REP_PO_01142020EX.docdoc 843b38010b78f69a9c7531e95d13d1a0bf81b6ef0cd05136b7962bcf1211a13dVirustotal results 27.42% Heodo
2020-01-14BAL_M5QOFE0JM6.docdoc 1843eb2b424df29991df3fd7ff4ee6658f540134ce196e1b150162ce70952fa1Virustotal results 25.81% Heodo
2020-01-13BAL_PULJ3B86DBL8M.docdoc 016a75e90b2cf4d7420e77b47fcfd13dfbcefe6e778b3f56aadefc6af411577bVirustotal results 25.81% Heodo
2020-01-13PAY_32098831.docdoc 0c48d70e7811f76eb907d4323c589c5280233638670c29a6cf16d3f62dcfd4f9n/a Heodo
2020-01-13DOC_266374905111213113.docdoc ce456dbf668e7694d5d9da6e6c9f5b7da4a59e42bd97bcdab90d35bc177027can/a Heodo