URLhaus Database

You are currently viewing the URLhaus database entry for http://ajhmanamlak.com/wp-content/rcz9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290098
URL: http://ajhmanamlak.com/wp-content/rcz9/
URL Status:Offline
Host: ajhmanamlak.com
Date added:2020-01-16 15:29:14 UTC
Last online:2020-01-18 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 15:30:14 UTC to abuse{at}hetzner[dot]de)
Takedown time:1 day, 16 hours, 20 minutes Poor (down since 2020-01-18 07:50:21 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18kF4i1rj5.exeexe 9b183c153166d005c277d09cc1f8e1923d0ca47c2db14b937c51606d81509cf1Virustotal results 12.33% Heodo
2020-01-180afbo7xwHa3uU2Ni.exeexe 68e699b962af409b5e0cec19f0670991fa5b2dc59672c91cdc4f7a59c037dbf6Virustotal results 9.72% Heodo
2020-01-18dKs6lC.exeexe eca289591a6c69e6a5a410263ea6edb7d64852619f5d2d6b7589b9c604e1d066Virustotal results 10.96% Heodo
2020-01-18rT.exeexe cbf4d162acf55c6e5bdf5f80b313487426ecc6066306236cf8a95f7995b40d6bVirustotal results 8.33% Heodo
2020-01-185KwEOWzZUsJdl.exeexe 224f60574f2611098fc6793c43fcf5e2a4054e9e6ccdb7e8954e0d6c580478c6Virustotal results 7.04% Heodo
2020-01-18NdC.exeexe 5572cb7226550216cd732c254eeaec8ca7c65fcd9e5b122f5edfa25ecbdf2e00Virustotal results 8.57% Heodo
2020-01-17WuDoUGDnYn5b.exeexe 024c315b15a1a1876ffea2adc9de974bf1c67dfc265fd823290b7aa3e6694ee4Virustotal results 8.45% Heodo
2020-01-17SJKZnpgftO.exeexe 760eb5a791d7527b7ea5612055eb50a5725b98af259c84148c516a3ed2375b52Virustotal results 15.49% Heodo
2020-01-170uiHclz.exeexe 0b4e357cfbccdb27fa4013ce14d556f8e168012752893485bbb76ae357879340Virustotal results 9.72% Heodo
2020-01-17ka.exeexe 47c3f56368c4cfbba9d73681375d06be2419e65e78a07c8b10d671207bcde2f3n/a Heodo
2020-01-17iw7b2teGpW7nN.exeexe 24706454a2047b3acf8571621b4d413c99d8dbc75c226016393cbd361bd2615fVirustotal results 15.28% Heodo
2020-01-177lfrX0V7kZZ.exeexe 337f652e34905559e06786fcba363cd7f951138e58f4f282f978fd5ab2cbc51bVirustotal results 13.89% Heodo
2020-01-175gPow.exeexe 97487bf287c0f2d575c790167c373be029b14d7a1d8a3a2ff6d87bc2bcc80d5bVirustotal results 11.11% Heodo
2020-01-17TOT.exeexe 18aba06fbfb1d0cd45e4554aa56cf918cfdfac590bfbd40728b0f6f8fdcad3fcVirustotal results 18.06% Heodo
2020-01-17nH6L4D5OP2teBuiP1FTA.exeexe b9dfd1a839cd05354c35bd22f46b0df6599183b08d6ab8ad87faf36cc2bac0c4Virustotal results 16.67% Heodo
2020-01-17MncTIMPCQzAioxCnkZHg.exeexe e3fe5625f05c35e9dff4f630bd578c6ddb0aaaff7c4aa0c5c0135fdfd1d4ce1bVirustotal results 16.67% Heodo
2020-01-17rrbGMP7jiZ5D0zp.exeexe fbc8815df7ed52578d3b0df17948172fb6f26bcab87fea2e762bf204bec54bcfVirustotal results 23.61% Heodo
2020-01-17RzLf.exeexe a6f6cb73b53733d9a63acb967bd03b36be93f7ecb55ee7283e0f2894550ba40aVirustotal results 25.00% Heodo
2020-01-17tHYmdH4zWkXQpL.exeexe fe6b3c11879bbfa61714c884476c9e03d2445957e30d36ea1492a9b3357dadb1n/a Heodo
2020-01-17qrXOnDYVqo.exeexe 06018c6503ea6cbac91572051c153ff2016c69a1089b43061fa9f7ec78a2c31fVirustotal results 19.44% Heodo
2020-01-17qv.exeexe 6def02d1280903eecbf1776f36eb2d6aff460f0b0b48a01e80ab05a36bacc9b1Virustotal results 20.83% Heodo
2020-01-17SobS5XXNNcs3NdpgG.exeexe b3e2fada8c31f52c2657c8a4ff0f63af7f1f5a1e788d14b9426cee389ce71198Virustotal results 19.44% Heodo
2020-01-17z4PBs.exeexe c64b34d2f1b0ae083b6bb3457c6f0a8e8360cc9e8533460b9e70932d01a75288Virustotal results 18.06% Heodo
2020-01-17Q.exeexe a39906f3efa59ed011ae37b19d39a01197b5b7614e17aeea548f6d11a61b6285Virustotal results 18.57% Heodo
2020-01-17lTJoO3lcX9r.exeexe 48347031adcfae3101eeedc80b303174df3b74e0aabc9c911a03e3b6560f4fe8Virustotal results 15.07% Heodo
2020-01-16UHrGObQVm63Y5sP.exeexe cf346d6aeeae84d957303473a35ec051ec9f7477d195ab797e11843750446649Virustotal results 12.50% Heodo
2020-01-165x93VImha.exeexe 2f017705c139aede645b6149196f5bef5e1ebaf6f63841329d7f4785d23e954bn/a 
2020-01-166lv4i0EZbeS663.exeexe 5f4bf7c51f9c3aabace037baccf1fd7d0446cfdadde40c713b1addc1a487228dn/a Heodo
2020-01-16VJ4BrEkXMPOokut.exeexe 19f4bdba534dc51ab21fc9c78f974ef4dd5877917bd98287d2c066636355668cn/a Heodo
2020-01-16af1S.exeexe 4efc13c3e41a1e96ed32c5ed90b42a8d96dddaed9317b2bc66038d09eed5862cn/a Heodo
2020-01-16P87mSTGCRzz.exeexe 1fff2de5a03d6b560fcf0dc1cdd3405cc3fc4b7d1bc515118dcfd0c09e52f597Virustotal results 11.27% Heodo
2020-01-16bOe5ZSKwn0VB.exeexe 93dec745111d740453a3159afb1888e3f145938f2a193b078a29854adbc54706Virustotal results 12.50% Heodo