URLhaus Database

You are currently viewing the URLhaus database entry for http://anamma.com.br/wp-content/lm/mhJuqK4kfhG4RAu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:610413
URL: http://anamma.com.br/wp-content/lm/mhJuqK4kfhG4RAu/
URL Status:Offline
Host: anamma.com.br
Date added:2020-09-24 17:50:25 UTC
Last online:2020-09-24 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 17:52:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 46 minutes Good (down since 2020-09-24 19:38:18 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-243460 39609.docdoc ef16ca7f98838032f77c4ce37274671438e7f500526a91c22a2ca6c1e2bcff62Virustotal results 27.42%Heodo
2020-09-24rep-352594.docdoc 4bf4fd8fbc2393d9f481cabefe7bce1b95a3b389d0240ac379990028255e46f5Virustotal results 27.42%Heodo
2020-09-24arc.docdoc cc1178c321ee53394b7dea09acb81d269b879f37e5471cca641c3efbe4e33b0eVirustotal results 24.19%Heodo
2020-09-24mes 2020_09_24 UKE232816.docdoc 4748d811f718783bd0504c198c082e051a61e55c9a003e9e0a53d13feddf9f1bVirustotal results 24.19%Heodo
2020-09-24inf 20200924 TK930.docdoc a7119297d5e0a5d3b6ab6bfdecc15029d2243b433db330c981e01246f23d5556Virustotal results 24.19%Heodo