URLhaus Database

You are currently viewing the URLhaus database entry for http://airmidhealthgroup.com/plugins/kh2ld-4d9m-1669/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429991
URL: http://airmidhealthgroup.com/plugins/kh2ld-4d9m-1669/
URL Status:Offline
Host: airmidhealthgroup.com
Date added:2020-08-12 06:48:28 UTC
Last online:2020-08-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 06:50:03 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:9 days, 6 hours, 4 minutes Bad (down since 2020-08-21 12:54:48 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14INVOICE-OS8-897338.docdoc 6a30f23d8d91d69f9b80bc213ba846b5d88c1a71e8d6a4a754a6d41b6f2f0ec2Virustotal results 37.93%Heodo
2020-08-14invoice H7 266345225.docdoc b912946f86e61acf37130b179be53f6dfa2fdd31fa0e158dd2fd19f557aaf059Virustotal results 36.67%Heodo
2020-08-14Invoice I05 752323.docdoc 4398bc31070f761b318b30f297d363b006ed9e84c6af0aa45ad140f57e7c1529Virustotal results 37.29%Heodo
2020-08-14Invoice_LD599_280184.docdoc 532d6be9513e3dea9cfb7040d4e2b0878429f90b84e8c3229ba775ff99dcfbbcVirustotal results 37.29%Heodo
2020-08-13INVOICE XQ21 061765.docdoc 1ffe441dc57cc6d6fab94949536fc37e1ee200c8108f3345a48a04ca268d097eVirustotal results 36.67%Heodo
2020-08-13Inv-MH67-27000588.docdoc 5631e8cae72c63a40c3b2b7558736633f75b424eff6bad19103ca6d559955528Virustotal results 36.67%Heodo
2020-08-13Inv181859153.docdoc 2700c5a0f48e93d064b77b0179fc337d59ed7d100dcdfa5f29c2f1d035e03204Virustotal results 36.07%Heodo
2020-08-13INVOICE2630472017.docdoc 226139f39424aaafeee49dc0a927be5da4a28431b970df629c236c7509680210Virustotal results 35.00%Heodo
2020-08-13Inv-RC052-221093104.docdoc 0dd2a96118f23f2fec5549ff2bbfbda83f954a2522474688ae8db5a35a84942dVirustotal results 35.00%Heodo
2020-08-13Invoice-26-78744819.docdoc ad919d299d8151242bb880dfd8e4f379ee644eb8a6eb799f7dd9608fdbaa84d2Virustotal results 37.93%Heodo
2020-08-13Inv IVL6465 83420586.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13InvoiceZ7077242882.docdoc 576c0497e26b93869620e9bd122a6836001c6ab4128462dccaceed7c2eb22dedVirustotal results 36.67%Heodo
2020-08-13InvI999679066.docdoc bb480394e0201866ae43a5b60c1ec371e3dd37a01e922a8dd5ff68d8cb325f3eVirustotal results 40.00%Heodo
2020-08-13Invoice-8442-509055219.docdoc bae089e182eb3266f7febf0ef17ca827f4c0c1712466e787e3c7d187e433645dn/aHeodo
2020-08-13Inv-PV884-90450513.docdoc d9307573e21fb325573fe07acbd225175cb4268237930af8fcc685c62219e82bVirustotal results 35.19%Heodo
2020-08-13INVOICE-7307-6072982.docdoc b38d736d513ae70545b3d388dbbf8e9e327be6276a22fb4e10422991f08dd1d7Virustotal results 32.20%Heodo
2020-08-13Inv_Y3237_656443775.docdoc 55260af4daec42317640803be79c9cb42f198db5c6194b7346c7c95c610f70f7Virustotal results 32.79%Heodo
2020-08-13invoice-VRI4616-6800624.docdoc 56af09db56d209f8011606b414163770dd7581a225f2a5ea8c16eb6be6afd035Virustotal results 30.00%Heodo
2020-08-13Invoice_WL17_640042943.docdoc e72282cf5896d2a6649446f6023b34c7d71ba08f5be3bb0def9185fa742c3deaVirustotal results 30.00%Heodo
2020-08-13invoice-YFZ7-5424126.docdoc b4bb0ed99478a7910267de0a8b83d95d21e41f8104509a278fd52affedaeb887Virustotal results 28.33%Heodo
2020-08-13INVOICEVQ616303336.docdoc 002e4e23a241c1fa930bf374dd4e1c871a0f19a6abb1fe7e34e0a7dd479a0744Virustotal results 28.33%Heodo
2020-08-13INVOICE-APA8-711293.docdoc 938e03ff3d361fa26c00218160d0ef65786280283d80678e729a73ea503e0d95Virustotal results 28.33%Heodo
2020-08-13Inv-AQK110-7849971.docdoc 52c981dcee0a9c0bc80ec192b453e8af6b01ced6cb3187645687ad0fd1b13221Virustotal results 27.87%Heodo
2020-08-13INVOICE HIA9 831798.docdoc e9bc4332a3fd2de13d8f4d58aaf749131a93e652fd663f83005b1437936a715eVirustotal results 28.33%Heodo
2020-08-13INVOICE H8 4428676.docdoc bf2332d7bb2fe3a48644b9436beaccf7cc4015b5954d8d012f2b095e21023629Virustotal results 26.67%Heodo
2020-08-13Invoice KGB32 9890972.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Inv_CZ710_32929660.docdoc d2cc4f61f498dbddde048bbb918416d73f063a0bb46c960ab7fd6fe671ed9bd1Virustotal results 25.42%Heodo
2020-08-13invoice KP553 203767169.docdoc 906423a8a219d85fee1c58feac18a6bc8689504a672ec96d5df2e61079f60672Virustotal results 25.42%Heodo
2020-08-13Inv_HP1021_383428.docdoc a7cc572cbee2c8b2740405a7bacef386ec4445f20dcba5584955d450c2c8e93aVirustotal results 24.14%Heodo
2020-08-13INVOICE_BPZ0_7709659.docdoc 8d3707b8799040b4d0ae3452f01c096d3658cb6636834e49f602c9f745ccd6edVirustotal results 26.92%Heodo
2020-08-13Inv-R11-677687.docdoc 24fe0e4704e8906e4819aaf88915317509beef8a6bd0abc3c4933cd0d75b7084Virustotal results 26.67%Heodo
2020-08-13Inv YZSF0 0320640.docdoc 642f6238f4c26f7e8829b4739309809c5b2ec80f58e0beb4df4cbfdfd8ebe42aVirustotal results 25.42%Heodo
2020-08-13invoice-U30-78013673.docdoc cdb381f78364b3a519d51aa70490c2a66f26062664a172c82b15f14a70297bb2Virustotal results 25.86%Heodo
2020-08-13Inv VKS195 28506750.docdoc 8313a416feea74f1e4555d53dbb6e2c4e7a831c854f7fa38ea8b3815b3bd124aVirustotal results 24.56%Heodo
2020-08-13Invoice-QXIQ31-08542095.docdoc 701f6714acc1e2c42435c5ca1c3c5919ec11dcaaebe5791bbea60eab5c8327c5Virustotal results 54.24%Heodo
2020-08-13invoice-FNNO70-885057.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13Inv BNAE8 98761731.docdoc cd0aaf460944efd580dcc39bc1dd0460f88f2c3c17e303694ffa1eae5020eab2Virustotal results 53.33%Heodo
2020-08-13Invoice-522-2363888.docdoc 17b6049e45eaf5263f576de1799a8b8ccd0164f7e1241cf72738d56e8793458aVirustotal results 53.33%Heodo
2020-08-13INVOICE UUTD418 559293532.docdoc bd379f0e0dcc9c8c75d70a99df9f95dc56d70fd92cbf446a21dcb7b22ded59f9Virustotal results 54.39%Heodo
2020-08-13INVOICE UUTD418 559293532.docdoc bd379f0e0dcc9c8c75d70a99df9f95dc56d70fd92cbf446a21dcb7b22ded59f9Virustotal results 53.33%Heodo
2020-08-13Invoice-XQOA3-029858243.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13invoice 60 46783188.docdoc e26bbe184e43c8251aee307aa6d392971f7facdda4ce50f9733a966dc7905ff2n/aHeodo
2020-08-12INVOICE-FZSA4-840848.docdoc 5fd1794cc1e685dfa2a1e2594b10d690a59a070a9b8bc9c6c12743efb989137bn/aHeodo
2020-08-12Inv 68 580881580.docdoc e412c6a1097b6fdf1492ad40805d0bbb1df005f870085f3fcb57d30552974cdbVirustotal results 48.33%Heodo
2020-08-12invoice-MAWQ355-59426453.docdoc 92dfce0e83a09bacf5d1ce00c4ef5c7bd7c35bbb27742bc01060cb96511f8156Virustotal results 49.15%Heodo
2020-08-12Inv A4370 62028615.docdoc 5d53ea1eda34e3d47f8a388a248005f39d237681eea6f3155e21220b373429f9Virustotal results 50.00%Heodo
2020-08-12INVOICE_LGC584_41415115.docdoc 24b41c6091602c0f9df9cc64905ce9dac977a04f700ae0607de467c101a093dcVirustotal results 49.15%Heodo
2020-08-12Invoice-46-077369732.docdoc 0c7d085dc88b57e56819a0a9319e1aa089ad9851a0ea21137aab6309395ed039Virustotal results 49.15%Heodo
2020-08-12Inv_XJ54_0312465.docdoc 6d545c7606e9a323f6b3e35d7352e7e60579a17bd7e063ecba5fa44b239ae931Virustotal results 46.67%Heodo
2020-08-12Inv-APE8-4600034.docdoc 14f91992f731d3ada3f75425545f0c7c3315ced9901f504310146165643ce276Virustotal results 50.85%Heodo
2020-08-12InvoiceJJK946821250594.docdoc bbf084bcd83d08a6693798f851e3af34cc7c303afb235c8c25fe237ec00315cbVirustotal results 48.33%Heodo
2020-08-12Inv OBN561 373877.docdoc ca9fe1cffea8d057b906d925c71eedaa638e559cddec2d200ed2ff3cf09ef67dn/aHeodo
2020-08-12invoice-X8-42509388.docdoc 1bf7159812124e19faf31cbed4b558aa9fa78b5f1a0562cad0dac81865d03094Virustotal results 43.10%Heodo
2020-08-12invoiceNTZG9557295346.docdoc 7ddd9bdcbe8ca80a8ffa5bdbf8ad1e388522433cf9925d2686ce9e3295c9bba5Virustotal results 41.67%Heodo
2020-08-12Inv-FY89-4468661.docdoc f30c10c17760141100196b57021e2bed24a5576335a5b58e4c78b65eeb80c4b0Virustotal results 36.67%Heodo
2020-08-12invoice LJ753 839164952.docdoc b2699f3cd54b6953a3eb9e1812890cf40563699a96776cfacd8f81288e962e11Virustotal results 31.67%Heodo
2020-08-12Invoice-WTJ6-607744195.docdoc e57030147f4012a63f88594d6941b5a8def5e07a9b4985521cce552f92f346e9n/aHeodo
2020-08-12invoice_YKF8_86662780.docdoc 4dee1f352c68c877faa2b98a20f494d6d383bdbbdec8367a650ed3b52b9b9301Virustotal results 32.20%Heodo
2020-08-12invoice_RUFA4_6637192.docdoc a4b8da2397aa872bf9a58f4ccc3aac1d9048af566659687b5cd8cc7c1c72b7f5Virustotal results 30.00%Heodo
2020-08-12Inv-GOXF302-614852.docdoc 4b643a7d7cf8515411aea4ce9d9a11893c50ef4b9cf3978396183d562ec90c14Virustotal results 30.51%Heodo
2020-08-12Inv UU660 620470989.docdoc abf3c79157fd476523d528ab58b49382769b7b8b4e4f4fea54da0a1b59acae9bVirustotal results 30.51%Heodo
2020-08-12INVOICE-NTGO7084-117036.docdoc 6610beb62b2916d0194d87458804ec7ae2e18e6efd800866b9d65db7a6e6b361Virustotal results 30.00%Heodo
2020-08-12Inv-JFV38-522950482.docdoc c0e57e90696fc7fc36202118e5d6bae3f85e480418d0f675369f61cd46850d5en/aHeodo
2020-08-12InvTIJ73189581166.docdoc 1af40a543a8e3a920a6db9c8262b3c0cf65edda39d0870d790a9d76c619a64ben/aHeodo
2020-08-12Inv1574212720.docdoc a9bae6fbce3ef6ebff32ad675adac80338a738edb330fdfd1e6dd09f7e35adf0Virustotal results 27.12%Heodo
2020-08-12INVOICE_775_4082911.docdoc 3c56ab23c5ab8dfe63118ca765d541c2776e7636b60323d32a813440d46d3651Virustotal results 26.23%Heodo
2020-08-12Inv532200185519.docdoc 2e14835f7cd7d8bb7f880071df115af636431e09b33325fe63f62df4f17988b5n/aHeodo
2020-08-12Inv_8993_1112044.docdoc 0c8168de8059f07bdf21871e0043fb09e40f7788a4c6028ea4e69db047a17563Virustotal results 28.81%Heodo
2020-08-12Invoice_QC5_438767.docdoc 32750365d68890d9071db244c4b3534a22dc90130e47ca9dfb21d81277678528Virustotal results 28.33%Heodo
2020-08-12invoice_ORRK5_307665.docdoc 3878a507270346a9cb72ef10f715fea30a403ceb12326e565fcf4e03abb874edVirustotal results 27.12%Heodo
2020-08-12Inv JWB1451 5919641.docdoc d8c9580c0c9f2bb8a4e50b71b6bf047c9a5aa42f2fbc76b4315fc8b2bd90fef1Virustotal results 27.59%Heodo