URLhaus Database

You are currently viewing the URLhaus database entry for https://ahwahneeheating.com/cgi-bin/closed_sector/additional_space/JglfQ_f38Imfb3NaIa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432373
URL: https://ahwahneeheating.com/cgi-bin/closed_sector/additional_space/JglfQ_f38Imfb3NaIa/
URL Status:Offline
Host: ahwahneeheating.com
Date added:2020-08-13 20:07:08 UTC
Last online:2020-08-15 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 20:08:02 UTC to abuse{at}sti[dot]net,noc{at}sti[dot]net)
Takedown time:1 day, 3 hours, 56 minutes Poor (down since 2020-08-15 00:04:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14list GTM15516.docdoc d07ec4fc9657ea145484957e5b68242e719e4a327f4f1c7b1fe940ae182fdc84Virustotal results 38.33%Heodo
2020-08-14file 2020_08_15 089.docdoc a04d9ab1b95d893d51dcecbf927f6f27c97d30ace8fdbaca14c643b6cf9be407Virustotal results 37.29%Heodo
2020-08-14file 2020_08_15 C77632.docdoc e3cfaefd87b2aa287ac22562cc177ec6744c3c9ac27db58b5d2bb7625b694d3dVirustotal results 40.35%Heodo
2020-08-14dat_2020_08_15_6971.docdoc 931d0d50761ef1699cfa6dcbfd7f77082e12083b8dce14a80088a003dd862464Virustotal results 41.07%Heodo
2020-08-14LIST_V34788.docdoc 2d333aea35e3e72761552005c9a0c87aeac00285837bd0c443c08b670d3968cfVirustotal results 38.98%Heodo
2020-08-14Mes-136.docdoc 67362ce243ba2443b124fa28206b9ab3c3915306cbce4b0b7d4b0c99532f6f56Virustotal results 37.29%Heodo
2020-08-14List_20200814_604.docdoc 665456af44fc843e545d1937baeefa7a85f67eaf4b0c1254adf627ceb4024372Virustotal results 38.98%Heodo
2020-08-14list-2020_08_14-H405998.docdoc c74d9497f6e45b986c8d3aa90e037e0bdf572731082d874ca8187cd51fd90486Virustotal results 37.93%Heodo
2020-08-14inf-20200814-100109.docdoc 171778f3f71370ac71991a37d610af0b288786d43479051653130914d8460ba6Virustotal results 38.98%Heodo
2020-08-14Mes_20200814_69993.docdoc 162582c2350c22d014b738bdea37a87272c1bb3ce559c38796b0b850f2c184f3Virustotal results 39.66%Heodo
2020-08-14FILE-LWP994.docdoc 47847459b55ae29a1e2e0f31a8e7d983d004e1e576f9734d7aff55951949af1dVirustotal results 39.34%Heodo
2020-08-14dat.docdoc 6df8558c0950f66047f545eea2121a5791ec751ee9eed445e7e5471ceb63b06bVirustotal results 36.07%Heodo
2020-08-14Rep-2020_08_14-G157.docdoc 42ff2736d6bea5f31eaa0cf531bf67861730ec192bd418caf52c3346eaab02a3Virustotal results 31.67%Heodo
2020-08-14MES E3182.docdoc e30ab117472fe6e748880cf8c3e23c28aeedbf17e7a3abd2c85d4242e16d330cVirustotal results 30.51%Heodo
2020-08-14file 20200814 WR549.docdoc e56836746be09c9508de189be4dcb73b8d44bcca31a24567423635ab94ec1cb2Virustotal results 31.15%Heodo
2020-08-14REP_2020_08_14_SS9641.docdoc f8d9aeff9c3ce77dae1ba129171de9f937a96e0b2428800091c0336bd58ee6a0Virustotal results 26.67%Heodo
2020-08-14Arc 2020_08_14 FTS4187.docdoc 6e679288085db07da2e862c6fb064a2e55217e160f6659bb094c39355f86ff2aVirustotal results 22.95%Heodo
2020-08-14rep.docdoc b8b90fd5558b725027b14645be547cb15a3cfc4014d3a93bc36000bc3ab50b31Virustotal results 22.03%Heodo
2020-08-14inf 2020_08_14 YEF5913.docdoc 84da36749623cdb916e6a186e9627bdd695c58050d3f46488c2688b666bbc277Virustotal results 21.67%Heodo
2020-08-14File.docdoc 973434d578f5a1a1f6d7720ee10452449bcc65565f6af61a9266958f5d6f2c33Virustotal results 22.95%Heodo
2020-08-14mes 396179.docdoc 3d1486ce24783f11fafd7742a4be89b506a618c8d25c948fbf3de40868e22d71n/aHeodo
2020-08-14Arc_20200814_MI03741.docdoc 9e9393a35165f1fb3e86284539bb3a40c4018511f933e8187c34af00790e5a35Virustotal results 23.33%Heodo
2020-08-14Inf_20200814_1706122.docdoc 6af630f2e8eba8699fb72196cd2a2dae2660d9ff10f3899585f70b8a99087838Virustotal results 23.33%Heodo
2020-08-14list 20200814 WD710544.docdoc c09ca830d8e72158e3a845643e41facf35f4022b75b424c044f6ee936abbebf6Virustotal results 23.33%Heodo
2020-08-14Doc-46175.docdoc d6028f2bb96365cce05da417a123515321309850764b2f428a6ef433b865a0b5n/aHeodo
2020-08-14FILE-PWR6320.docdoc 2e4a771ea2d138725a219bb3fd2f1a3d9a7461e0b6c57299989296a6084d234fVirustotal results 25.00%Heodo
2020-08-14rep-2020_08_14-858.docdoc 206574491387efd9c04c688f5cb21867f1dc246db16fed9e158eff7a6f8d519cVirustotal results 25.00%Heodo
2020-08-14MES 2020_08_14.docdoc 5b893ad0bb28ffb9c0e56be94c04c05ccd0d26b7abd8bf9b4a01a228df3b5677n/aHeodo
2020-08-14Doc-2020_08_14-5989.docdoc a2de797ad23c2211a80a0f83b3ee774fa17931ce941a60511d850b1ebd3e4aa1Virustotal results 24.14%Heodo
2020-08-14ARC 20200814 KZC554.docdoc 783a766ff6d8b06f0050f051c16b04cad1298697c81bbaeee5d8fcb014a60a29n/aHeodo
2020-08-14mes-IX322552.docdoc eb8626c09f81f7723ee7afa0cf39e78db7be79b5e5522f82ed7c116eb5fae52fVirustotal results 37.29%Heodo
2020-08-14FILE 20200814 7853550.docdoc 3dd12ed62a3b89ed3d384f1e58d1ec2ecc0901ef17ec4738002d9da80818e148n/aHeodo
2020-08-14DAT.docdoc 29489efeb7ae7bd57c8cbca798da5a97deae5630ec298d8c5c71dfcea1eac7c0Virustotal results 38.33%Heodo
2020-08-14doc_855482.docdoc 5a04c5b9d29cad47ad5b1a17c2615ef48dcb29c7e211f7b9adccbbaeaf8a94aaVirustotal results 38.33%Heodo
2020-08-14mes 6376.docdoc d878e7902f6d8430f7d19f1f9f548c280c1e3789ec3857a5d0c81c9ef2e6edb8Virustotal results 37.29%Heodo
2020-08-14List TFX300912.docdoc fe72004e6a838fcb078f8b14b9e31e68d627ab0aefdf9bd24c5e9db91e96f4f9Virustotal results 36.67%Heodo
2020-08-14Doc-20200814-5758.docdoc 2465fb97adc0bcfd2852bc97bf6a929405c2b0c8abb85b57d294befdefbac099Virustotal results 35.59%Heodo
2020-08-14Arc_20200814.docdoc be002af97ec2cdb43edc083f492340be1995195c05bcd860b3268acb96e2c539Virustotal results 35.59%Heodo
2020-08-14Arc_9442.docdoc a5aaa7a63b5ec81fdfe4916e720a21e4df252c2d3823d6558f0593cb1f4f65a3Virustotal results 36.07%Heodo
2020-08-14rep-20200814-HYU018.docdoc efd285d45835c318c4e079fae4840399a89ae40bf6134dac6cef9e7483e9680cn/aHeodo
2020-08-14MES_407280.docdoc 1c09a7e4afcf582fb0ae2170a0375571dcc9ae463e6c9f29770a590039704a44Virustotal results 36.07%Heodo
2020-08-14LIST 2020_08_14.docdoc 24cffd9cba643e90804ca8b7c8cfcc717ef8ae85ef64485427c51d320333baa2Virustotal results 36.07%Heodo
2020-08-13REP_2020_08_14_Q2537.docdoc 96fbcc6247407284134b11eb29a5cb2dd6c00fdb5f500c58b19be4822cd412c0Virustotal results 36.07% Heodo
2020-08-13list-20200814-02068.docdoc d362ed42b7e6383ec272a65b42e23fa00585b6e65640d3e31552777ea6e1e06fVirustotal results 35.00%Heodo
2020-08-13Doc-2020_08_14.docdoc aa253dd86d00217ef0405e1632fe822af17023b8277078b08be3ecdae72d78daVirustotal results 35.00%Heodo
2020-08-13DAT 20200814 NS902989.docdoc 6186082bcd32e8eb8752a7326d1977ca740de8f69073da700ddc6f508e6c2daen/aHeodo
2020-08-13file 053227.docdoc 8c9ad53dec636d785fb17d8d2e71a59498898c587e80673d8213ce50eb382e3dVirustotal results 36.67%Heodo
2020-08-13MES 7960.docdoc deffa862c9c822b31cd7d97529ca881b817e8ae26960dc40541f212b7ba78ea3Virustotal results 36.07%Heodo
2020-08-13Rep_20200813_U521514.docdoc eb22f6c5bfe1c7137baed590d6ed41fa8a0f4218636ba18a88ae4b4beb8bd271n/aHeodo
2020-08-13Doc.docdoc 5bb4b84296ec60184ea017e657bcea6f6d3acaa986abdfd64cecbbd4ee027731Virustotal results 43.33%Heodo