URLhaus Database

You are currently viewing the URLhaus database entry for http://amphy.com/sys-cache/u2lxfd9s7t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:499182
URL: http://amphy.com/sys-cache/u2lxfd9s7t/
URL Status:Offline
Host: amphy.com
Date added:2020-09-14 16:24:33 UTC
Last online:2020-09-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 16:26:39 UTC to abuse{at}ovh[dot]net)
Takedown time:18 hours, 5 minutes Good (down since 2020-09-15 10:32:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15PO_09152020EX.docdoc 807bf4c0dd85eea9b4ea5c41fab297064a1a79599cf41ee23eddea254c4f5692n/aHeodo
2020-09-152239057761780544650.docdoc 7432c22b6a99281670f18f32f78f9631d8b04c2715337de620a57debec0ce02bVirustotal results 45.76%Heodo
2020-09-1595104801.docdoc 11457a99a5505f705c398e4e05548708cc0ca4e18748421ea1374c0f410eb5abn/aHeodo
2020-09-15DOC_532021438360300845685.docdoc 221d824e80d3e36d5d0f52d1a0160382272e6d733a596f2eef49140f3823ad4bVirustotal results 47.37%Heodo
2020-09-1527778339.docdoc 3101660852449fb80ba31c9c0dbb29ffd2c33de28fcf1e2080b3ec6594f4f963Virustotal results 40.68%Heodo
2020-09-14N_RW4963162026YK.docdoc f4b770344e78791146677dc8e1fa4d56fcb574605948de9381aeaab6a0b9bf74Virustotal results 40.68%Heodo
2020-09-14BAL_X0687SN.docdoc b3c6abf670480a16083371fbbe54e43aae5e790eff0aa861813e51e44ca2c975Virustotal results 25.42%Heodo
2020-09-14DOC_DQ8447442962HK.docdoc 5e9694ee68dfea978dbc805fe72b5788f079caf4dc6e7cd66c811286bf943772Virustotal results 38.98%Heodo
2020-09-14DOC_TL0749140072ZG.docdoc 693f393b73fba1545bbfed68995e08a5501d14fbb9904c4411e27245b75aef91Virustotal results 35.59%Heodo
2020-09-14F_C8RQRKH54WD7.docdoc 4d58f9bc9cb9c71282fc9003acfff87afebaa80186b02cbd42d663d20eb5c43aVirustotal results 30.51%Heodo
2020-09-14DOC_R8VO78CFS8BBG.docdoc 52cacf28b237a0c90d4a49fd44192565cda0c2ce66fcec9e082fc36bfd4ba4f4Virustotal results 28.81%Heodo
2020-09-1449143199.docdoc 5b34fdfd16c49176f9e6e5cdeb255aa73c18c4ef0648c89118cb1b17b52c8f13Virustotal results 31.03%Heodo
2020-09-14K_NU9375095564EB.docdoc 44cca8cba5ff51e2195e4c42279930fec3adf0cec60c38f0827e18f52070cd95Virustotal results 29.31%Heodo
2020-09-14144665169976761481825657.docdoc 52fc0bc99c65b0394f76bff61aec92b537d81777782b346228008e19424b4642Virustotal results 27.12%Heodo
2020-09-14803811902047219353371.docdoc 26f08e160cfca8f495a847e27d56a77374220ca6245eaf0ae508c37fa408c910Virustotal results 30.51%Heodo
2020-09-14REP_PO_09142020EX.docdoc b5098ef2dd14c5067783d680242e7f0ccddcc4e2cf980639a3b3f0a03b6b1045Virustotal results 40.68%Heodo
2020-09-14REP_I9WLE2AT2.docdoc 9c0736822b16dccce2ff3c10aa4f76237572ee96ad1573858b1cdcab41fee505Virustotal results 28.81%Heodo
2020-09-14H_11700648.docdoc 3e64b6ff86edb967541e4c0b1dc3667ccbd807e99af91d16f9682597b1352ee1n/aHeodo
2020-09-14BAL_F0N9D26HG8WCUT.docdoc 5d29d4ae2581a27221609c7e3877aa9139dd44042bcde1fb62d7e901d285e4f4Virustotal results 27.59%Heodo
2020-09-14REP_PO_09142020EX.docdoc a153e7d47a196c8848cbd1aa6b81d15adb43a1cc0c6402dca515ea34723c0ca9Virustotal results 27.59%Heodo