URLhaus Database

You are currently viewing the URLhaus database entry for http://www.amatasolar.com/sites/https://public/j2s6c9RFYGCiK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453304
URL: http://www.amatasolar.com/sites/https://public/j2s6c9RFYGCiK/
URL Status:Offline
Host: www.amatasolar.com
Date added:2020-09-04 13:23:22 UTC
Last online:2020-09-08 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 13:24:02 UTC to abuse{at}siamdata[dot]co[dot]th)
Takedown time:3 days, 20 hours, 39 minutes Bad (down since 2020-09-08 10:03:43 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04rep_20200904_MQ037.docdoc 4ff12f48cce6bd43cadbeb06f54c727fa688da49d56903348dc190711e4d0891Virustotal results 28.33%Heodo
2020-09-04inf-415.docdoc 60417a3fac59e91bb0031c7e6fc97a808021296c159f11631bc3ac3e34ec5603n/aHeodo
2020-09-04list_V77529.docdoc 3616487fc9577f23d340266d9936a2e2553b1b9c340d3217345e74a4af603666n/aHeodo
2020-09-04REP 27955.docdoc ac6a5c2f72c10af857d73db327000d07f01f791fe6638c339362584fe1293a4fVirustotal results 28.81%Heodo
2020-09-04dat-20200904-883604.docdoc be6a2393d8d58557a21737649e0977851d793862f1b80f1d27a1ee2ee70b3154Virustotal results 30.00%Heodo
2020-09-04Mes-2020_09_04-W65883.docdoc dee17f41722ce96f3e95ac1ed9a43b57ddfef3fbcf6ae699f9adf0bdbdc15debn/aHeodo
2020-09-04DAT_968901.docdoc 07a163e438bc23f4ba37b5191bd5bd2134b87c7fe63924af48c3601f222bf676Virustotal results 28.81%Heodo
2020-09-04mes-2020_09_04-SDJ787336.docdoc 794287d8176f07c6943cc4ca303d03de2ec84b37ff7262e148c0451087177c86Virustotal results 27.12%Heodo
2020-09-04Untitled-20200904-8945.docdoc 1c3e3bdb04dc52f5610c1079242b43b61f136a2a328a6813fe492e4092cd6e4an/aHeodo
2020-09-04file 2020_09_04 196.docdoc 4f1efb479047eb160b579acb41f5f020b5c98546b837d8f74862d98ffef4840cn/aHeodo