URLhaus Database

You are currently viewing the URLhaus database entry for http://www.amatasolar.com/sites/https:/public/j2s6c9RFYGCiK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453346
URL: http://www.amatasolar.com/sites/https:/public/j2s6c9RFYGCiK/
URL Status:Offline
Host: www.amatasolar.com
Date added:2020-09-04 14:30:17 UTC
Last online:2020-09-08 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 14:32:14 UTC to abuse{at}siamdata[dot]co[dot]th)
Takedown time:3 days, 19 hours, 31 minutes Bad (down since 2020-09-08 10:03:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04rep_20200904_MQ037.docdoc 4ff12f48cce6bd43cadbeb06f54c727fa688da49d56903348dc190711e4d0891Virustotal results 28.33%Heodo
2020-09-04list_V77529.docdoc 3616487fc9577f23d340266d9936a2e2553b1b9c340d3217345e74a4af603666Virustotal results 28.81%Heodo
2020-09-04REP 27955.docdoc ac6a5c2f72c10af857d73db327000d07f01f791fe6638c339362584fe1293a4fVirustotal results 28.81%Heodo
2020-09-04dat-20200904-883604.docdoc be6a2393d8d58557a21737649e0977851d793862f1b80f1d27a1ee2ee70b3154n/aHeodo
2020-09-04file-20200904-5130444.docdoc d7452abd23b4d0a252d67436bea5f98b177d6d4a707ce10ce71852940cf97a3cVirustotal results 28.33%Heodo