URLhaus Database

You are currently viewing the URLhaus database entry for http://amaga.de/WordPress_02/http://attachments/Knd9uXzSwtr75bbNb5F/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:451938
URL: http://amaga.de/WordPress_02/http://attachments/Knd9uXzSwtr75bbNb5F/
URL Status:Offline
Host: amaga.de
Date added:2020-09-02 21:10:04 UTC
Last online:2020-09-04 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-03 08:43:42 UTC to abuse{at}strato[dot]de)
Takedown time:23 hours, 46 minutes Good (down since 2020-09-04 08:30:02 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04Attachments 2020_09_04 QY330.docdoc a44af5b41212998f1fbe2710a20194236275ea73fe20d136c36ab549738d00ean/aHeodo
2020-09-04Dat-1494.docdoc 47942152b879136b37f93a091fdc0995ae8dc63870ec7644620fc97205c8aa51Virustotal results 23.33%Heodo
2020-09-04DAT-2020_09_04-86350.docdoc 8dbc5aa0e47afc92f01ac0be897f8cfb5650e25857c1c7bdaf605dfc90a0d5f5Virustotal results 23.33%Heodo
2020-09-04File 20200904 HUA3990.docdoc 970e16cc8aabea583a577bb3ca6a50b795357231ff02822fafb8aa7dd143667fVirustotal results 22.03%Heodo
2020-09-04Untitled 20200904 M89620.docdoc 2be118d48f3e89cf53df13c43a01cdea40d8ffc9ed68e343636386badff6200dVirustotal results 22.03%Heodo
2020-09-04List_2020_09_04_1280074.docdoc 987e6058bcbb6e6830567bcbf092de202f9fc61bc7b1a6f282f6ee741685e442Virustotal results 43.33%Heodo
2020-09-04Mes-QGN929.docdoc be658261ea85360800d4b052f23fd96dbadfe7171d308a38dba22b5fe4efadf0Virustotal results 41.67%Heodo
2020-09-04MES-20200904-AI364.docdoc d310bc1324e7bd2e09dde5482cc4390a66257737f2da4ce7c2bc2f05d04663d7Virustotal results 43.33%Heodo
2020-09-04file_028798.docdoc 4abe421f4bf82588ca7772c685416eab8133054e1ae9fcedc245167e272b6105n/aHeodo
2020-09-04MES_2020_09_04_3570.docdoc 03cb9a738ad3ba7f5744d092532b2e578e9ade9b376af945fca5faf115b06c4bVirustotal results 40.68%Heodo
2020-09-04Dat ZQ57037.docdoc 0ff1c95a7d850d74903fb10610c4d99e54fd900d51cad0f2deda82e1122f403cVirustotal results 40.00%Heodo
2020-09-04inf_20200904.docdoc 2fcecf7ef769ae49ecdf3905e7c5e7aad9a7f0ac4279fe518ed0108f25a0ec79Virustotal results 39.34%Heodo
2020-09-04Attachments_20200904_ZZ00434.docdoc 6bb0dcdffbd9df010a6d7951c4a8ecb8596b694a6b4f59c866f30a012bc325f5Virustotal results 40.00%Heodo
2020-09-04File_20200904.docdoc b928a4ea1aae65b1c3ee2634f0d4d3bba7d8f0d7bd647c3befb30ba0f8b6a1abVirustotal results 40.68%Heodo
2020-09-04FILE 063488.docdoc 6c3530951ad2bde0a96b5bda4698fb3638e360f5176d3f6aa4f9ea0570a3f45dVirustotal results 40.00%Heodo
2020-09-04List 2020_09_04 RI186845.docdoc 886d63b614006458acc2c30f3864476e896c318a90248243fabf63f0e992f712Virustotal results 40.00%Heodo
2020-09-04mes-20200904-6523.docdoc 352ed1583217d011b59331d9df7069fb05bffbee3823ffe2603a5cd74f16b850Virustotal results 41.38%Heodo
2020-09-04list 2020_09_04 4384.docdoc 8d774a00099efb6bf180d96ed66c4cc234169be46bd45261c06dd8500e0a8481Virustotal results 40.98%Heodo
2020-09-04FILE-20200904-3572914.docdoc 113f271d566b508aed976158e057211703fe30c314960665466fe58d9e08e50bVirustotal results 40.00%Heodo
2020-09-04mes_20200904_96570.docdoc cbf75dba4c6b4f8cbcfb647112f9a0a4f8efb293526aea73ffebcd800379e08fVirustotal results 40.00%Heodo
2020-09-04Untitled_115760.docdoc 595e8a24f2e5e51e56138296f7c6cd58e709e8f532dbacc38ae66f462e0e071dVirustotal results 40.00%Heodo
2020-09-04Mes 2020_09_04 403048.docdoc 9cf29b7fcce905e807fd1e4493af36f7f0e8618912601f1a85cf52af6d38d6b8Virustotal results 40.00%Heodo
2020-09-04Mes-36513.docdoc 41b51c9c72e134b6a5183ee31357d58d19e875c56db068adc0b5f8a3d12bdc3eVirustotal results 40.00%Heodo
2020-09-04mes-2020_09_04-4193907.docdoc 9fe427f893f6601d49765213f47af2ea3766457661b26cf705d4f30c267f3a73Virustotal results 40.68%Heodo
2020-09-046994-20200904-68790.docdoc daa812c082d4d470cfad19c540bfc6ea7adbcd3859273af885dda81d2722e1e1Virustotal results 40.35%Heodo
2020-09-04rep-20200904.docdoc c9760ed3a6abb462e2d429280f83f0e912114c2b1923fa1fec74b3ee350afa78Virustotal results 40.98%Heodo
2020-09-04INF-20200904-B94836.docdoc 0bed9ceb6c02ac01c38804705e397d72379abfba81c416c2deca29e08e32bd54n/aHeodo
2020-09-04File_587.docdoc d6da8adc7df4680bdfe56aded8385d20e63b8af6ac83ff2abdccf2910232809bVirustotal results 40.00%Heodo
2020-09-04mes_2020_09_04_XK80605.docdoc 05fad6322a91dea215be2ca369db898c378e92eed38030f6dc4bdca1eabf3836Virustotal results 38.98%Heodo
2020-09-04Dat_20200904_4053.docdoc 39f12f314a1431044af9b7061ac6b7b2d68e29927ba8650ecfd4a5a41337922cVirustotal results 36.67%Heodo
2020-09-03doc 20200904 TT22555.docdoc 5b1c5637bea570eeef52ff79044a41de92de4e33ddffcde3b3611bee6fc8e5b1Virustotal results 36.67%Heodo
2020-09-03MES.docdoc d313ce8483aa86f33b4fb8f8eaf32cc9162fea1ecd980baf5fb9ae5ba1e2024cVirustotal results 33.33%Heodo
2020-09-03REP 20200904 822.docdoc 5870705910f4290f13346efd3c9113483974723cc840cd330844efa6f5b3be19Virustotal results 34.48%Heodo
2020-09-03File_4047745.docdoc 9e3d362ff8dc1daec89813f11f73bac91ac2ee3f97f803fd413522874432ebb4Virustotal results 32.79%Heodo
2020-09-03mes 66478.docdoc 198716bbb4d8d22a81603b2d905312ceae4b0f8df0a17ccda349c44ae024011bVirustotal results 33.33%Heodo
2020-09-03Rep_2020_09_04_DR030.docdoc bf1b9f0a76233f9cc5983b3b48fad1f4edff9c94e363dbab7f91cb8050ab315fVirustotal results 31.67%Heodo
2020-09-03Dat 44511.docdoc 10d9f95cbaae87c8e1ee5a2d4ed21022d9a419859eb29f5cb055497a345006a1Virustotal results 31.03%Heodo
2020-09-03LIST-2272.docdoc eb96e6409fa3b1e2510201d45d3a629be387c1d50ca84645b13d0614702d7c62Virustotal results 30.51%Heodo
2020-09-0394006679_905.docdoc 184ba331ed727480fd65743bfe0cf1489eca3b4d49b68a31b970ee96288c9484Virustotal results 30.00%Heodo
2020-09-03Arc_IHN81843.docdoc 3c9f9e08bf1785b8c6c1fed306eb5e322fb63ea73a8d01a9fc83af4006d64008Virustotal results 31.03%Heodo
2020-09-035246WXA 2020_09_04 342.docdoc 7e3a1e6d36b83671b756096e60fc53cab42b64bdb208c976b889540d6e90bf17Virustotal results 28.81%Heodo
2020-09-03Rep_2020_09_04_SLT724.docdoc 4f5a405c856619a4ed5e618fd60249ffb0ec9437f94ba328f235c14375271a7bVirustotal results 29.31%Heodo
2020-09-03File JTD168693.docdoc 6e09b7ea9721f1af117d11158633cf55d038617f7ac19748f9280bc43c46ecdcVirustotal results 28.33%Heodo
2020-09-03List 20200903 UWA2167.docdoc 473941d39d5c25ffe3ce4b7d3da0b2e3203fc8fd7123c8392d025ea706d45d32Virustotal results 28.33%Heodo
2020-09-03Arc_2020_09_03_J513.docdoc 8ec353b19baa29bb3ebb9f4baa55ac06aa90831fd8b27c1d41ecfdecdcb68a3bVirustotal results 28.33%Heodo
2020-09-03Mes_6680223.docdoc 2bb99d9824b62fad58399309008db0c35224a435f3128a9f1104bae218fff192n/aHeodo
2020-09-03doc.docdoc 54e914ada679af6812636e98ea035a024075eb6c2d3c5691d7ecb4bc6912e3b9n/a Heodo
2020-09-03Rep_2020_09_03.docdoc 3d79b0e046a8c799ccb81e9bac59c0b8f45b767a92e8c32465ebb56975ddbbc5Virustotal results 28.33%Heodo
2020-09-03doc 20200903 2821.docdoc 83a608a684d531170d1d962a923ec80ff882ad17ac5a24ce4477d634e575c74eVirustotal results 25.00%Heodo
2020-09-03NHE841-WG55640.docdoc 689e1b27324a65ca3e5c98ad7cfac2125fcb8d64bfd863fe1f0a26c16f68f9a0n/a Heodo
2020-09-03rep 20200903 1964.docdoc dfb1031ce56f9f39a32ed410629d9f46e753b4e0671d121c063d52a7a23785f8Virustotal results 23.73%Heodo
2020-09-03List_RI18344.docdoc b1c32ab9829ce18688bdc2f48a63f967f67366e2d725ae16bad216cbc79158e9n/aHeodo
2020-09-03Rep_2020_09_03_849472.docdoc 87dc054eccdd1cd6182d372f5fad56aae34971c4a0ab10e92fd242ee82e9c785n/aHeodo
2020-09-03Dat TI19295.docdoc 75e21b06b155b76eeb61cf02a1e3d2ed091b180853d2c6dba9aa7f4afa014aa8Virustotal results 21.31%Heodo
2020-09-030456_20200903.docdoc b9f390e14ff3a741d40f78b33a9e82622638b6a50caa19f042764a40ffea8236n/aHeodo
2020-09-03Inf-2020_09_03-9671.docdoc 1303dae3ca87ebeabf89fa7f128b36a1041846f829eed086f8533d9975990e3dVirustotal results 25.00%Heodo
2020-09-034239-2020_09_03-9986423.docdoc 039593442d9e6207131ebcf1a580c3e5bec865876db4457c1f8caa6947159cbdVirustotal results 25.00%Heodo
2020-09-03inf 20200903 8121.docdoc 4a3bedb4532a6a86ab7b29012a3adedfe19e06aeb7e032dc0514039f3622b6acVirustotal results 25.42%Heodo
2020-09-03Attachments-2020_09_03-REV117228.docdoc c443164c089fb4765ca30a77309a379fa8ee043af4e723dfc4ffc6d977656613Virustotal results 24.59%Heodo
2020-09-03inf-3468.docdoc 68d32abf2673eb48f6df74b063aa17e978d10a50c746d8e0f27ba51c93779d01Virustotal results 25.00%Heodo
2020-09-03Attachments-20200903-674.docdoc afec2bfe8925c1750c88f1532f6c9f067e3751ce6beeca628db4850efd1d7bccVirustotal results 25.42%Heodo
2020-09-03Doc-20200903-QLZ0449.docdoc 4a2ee0cb09dab923da14ab985f65d156e600b82e42b0bb53bf982243bed9400eVirustotal results 23.73%Heodo
2020-09-03MES-20200903.docdoc 431ec558729a17c71ef7827a20d49d5577d19b03f8ccaa3e0615a8db09ed3c54Virustotal results 21.67%Heodo
2020-09-03Rep_20200903_MSZ8809.docdoc a3cb0dab145b2e5b5000b6b134acdb73594fb0bec769212dc3b848b5eb16d284Virustotal results 21.67%Heodo
2020-09-03Doc 20200903 VFM460299.docdoc d78448b6db249a6ecf36f11026d7ba586a6348ce297651d61e1d7e555e07e60en/aHeodo
2020-09-03ARC 342040.docdoc 942091684482d678974c9220ad745980d533bda5f758b93ee3cd5fda40373a3fVirustotal results 22.03%Heodo
2020-09-03ARC-2020_09_03-GG358.docdoc e066308839f458b9477414e501caff74c793580cb0188acb9cc3bd188f5aa215n/aHeodo
2020-09-03Dat-9436.docdoc f61c2ad341e1ff7a97fc114cfd2ac23ae1d962acd6b08143b5325e781291abafVirustotal results 20.00%Heodo
2020-09-03inf-20200903.docdoc 010725a82107c0b0313be31a0051e0639d606503644442a16d8ee6c1f064da41Virustotal results 18.64%Heodo
2020-09-03Attachment_20200903_44519.docdoc 2b4be15f0d85e69f6e3af8ff6a07242ceef68ac071cf2c5b71002187354cb1ceVirustotal results 22.03%Heodo
2020-09-03List_20200903_62188.docdoc ec4e2217ccfa3e601f1227b3b6ca3bc3a9126cad211c5b303d7c9a6ded11b93dn/aHeodo
2020-09-03LIST_20200903.docdoc 481fe8b8e2ae22c0ce4c26fd4575526775f2ef93979eee241eed79d18e69f160Virustotal results 21.67%Heodo
2020-09-03inf_2020_09_03_4361254.docdoc c8a71c528548306c663f2b0c7b602a3d23ca301c9a946f6a105bd11ae7f1b8a6Virustotal results 21.67%Heodo
2020-09-038653415_20200903_G511.docdoc 30bbbd21c90e5f4a8afb756e5fcdefe896745ca4dfa74720c96a5e67acc8ac3dn/aHeodo
2020-09-03Inf 89434.docdoc e62ade83d90089f1e5aa25f31bcc623d5e80d400c9754371e949cf4f99bd63b3Virustotal results 20.00%Heodo
2020-09-03UNTITLED_2020_09_03_LCK86371.docdoc e6a1c45cd63a70584775660392b75daf492da30a18f989cb055e43c5282d8ac0n/aHeodo
2020-09-03arc-2020_09_03-EG69407.docdoc 490fef6aff98d6e725d22acf348a7bc81c7e8b0fc299d29ff5f1f2233725af2cn/aHeodo
2020-09-03Attachments_595.docdoc 15de7545c8d13285e5cb83c314b0f47ad6428d10169a8d82ab09ab7d7b16bef3n/aHeodo
2020-09-03INF_2020_09_03_LYU200934.docdoc 1c19c6f5fb32756be1f03168ae44fdb70cab583db3e7563a5a7fafad95515eb4Virustotal results 18.64%Heodo
2020-09-03ARC_2020_09_03_9994363.docdoc 4a5029949cfff6d3fa6b2c99cccc0629409c47ec3c1998fc74c2af39a84fb774Virustotal results 18.33%Heodo
2020-09-03909KN L43296.docdoc 9e94001ac9d7065f50fcf60e4b510de6b0ac3abfb5cab7e2a609df2cfafe9ee2Virustotal results 18.03%Heodo
2020-09-03inf_2020_09_03_RO1609.docdoc 475d8fda613f9584e77724a38a4bbd51bb5b035c5c29016ea7b91ca4bf188865Virustotal results 18.33%Heodo
2020-09-03Dat-2020_09_03-517.docdoc d742952f4e6160da55a1d1f4851c20d36b539b3bd51eef7c8c3fb43aff4e7e8cn/aHeodo
2020-09-03YAV277-PIK50952.docdoc 4b5032c6627be3ef367a5cc130cdaf96bc98cd65c16dbfe80931517aef1526f3Virustotal results 18.33%Heodo
2020-09-03275AD-2020_09_03-C41038.docdoc 537b13b52bea3093f294ca644caa54d62586885a5ee0302974e81f7a7fcc5c7fVirustotal results 18.64%Heodo
2020-09-03FILE-W65091.docdoc c0cbde26c26008c28e57c09b3755a36c862bf431e69e8a8c6efa181a5c135343Virustotal results 18.33%Heodo
2020-09-03Rep_2020_09_03_159079.docdoc 141021353b7fe52866701e33bda646b1e2fd7951b345a5ace3e5822f9ecfc983Virustotal results 18.33%Heodo
2020-09-03928445 GGN527145.docdoc 7d3613196ebd18433645eed62105fa1718805e6fa0e2196101acec16d984e35fn/aHeodo
2020-09-03Doc 20200903 K0819.docdoc 3eef5b04ad1f0d11509341eba660dd81bf2a215ac7f5da75d9355824da254c47n/aHeodo
2020-09-03Arc_2020_09_03_6554.docdoc cd42e012520f8c3bf516f12cfcb9ee2c25a76234374ba8d699256b085c766530Virustotal results 37.70%Heodo
2020-09-03File-20200903-736.docdoc fc90610a242c7e63c5308bdbe1465659981a65be23ca2ee1d99930fdde9cfdcdVirustotal results 35.59%Heodo
2020-09-03UNTITLED-20200903-F441.docdoc cacf08dc29380900a46bd3ef7a8d9df051aae704102a5878816183cfe16caf1bVirustotal results 31.67%Heodo
2020-09-03List 20200903 024.docdoc 3505f54cbf2ddab863054dc37a1c898cc5ff3f4dc69ef57ca0f8a32a132588e1Virustotal results 32.20%Heodo
2020-09-03LIST SP710111.docdoc 610f9b964005fb3e89a45ddeb0555cb5137065429a651730c5aa68bfb59fcdfcVirustotal results 29.51%Heodo
2020-09-03REP 20200903 JNV103.docdoc aa172b20f6de0d7af9a069bb8d7c11a589e3b2a8d9d67498b0110f69561a10e5Virustotal results 29.82%Heodo
2020-09-03Untitled-D616.docdoc d1736bb7fba0d5f83c964fd5e9c3d2659a1a1ff6eb178441309a83e9fa00ef5fVirustotal results 30.00%Heodo
2020-09-02File.docdoc 91c2f101b7dd73a4e730c57f2c6de87283226393251790c32ac2b0f551812fd2Virustotal results 20.34%Heodo