URLhaus Database

You are currently viewing the URLhaus database entry for http://ashgroup.org/wp-snapshots/l0yvts6tjlr6/puiqfbw1h3v04gf47vb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:619147
URL: http://ashgroup.org/wp-snapshots/l0yvts6tjlr6/puiqfbw1h3v04gf47vb/
URL Status:Offline
Host: ashgroup.org
Date added:2020-09-28 21:44:09 UTC
Last online:2020-10-01 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 21:46:07 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:2 days, 16 hours, 43 minutes Poor (down since 2020-10-01 14:29:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30REP_BP0384795014AX.docdoc a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47Virustotal results 26.23%Heodo
2020-09-30REP_85783893.docdoc e8a8b9fc12cfa3ee4f3cd91504cbf5b9af3281a25798c9c23c319044b39b551fn/aHeodo
2020-09-30INV_PO_09302020EX.docdoc d46320a38b414b43c59ca8d4290d2da2129bafa4cacc5de0162242e761f1dffdVirustotal results 26.23%Heodo
2020-09-30INV_LW6631747193RP.docdoc 89184bca1106ed62901477bceef09ee282bceca404d17c44630544fdd803cbbfVirustotal results 25.40%Heodo
2020-09-30PO_09302020EX.docdoc 86f7e3cb36503bd4d36820857fa1cf349e4e14af26612ebbf4855fe68b2fde22Virustotal results 25.81%Heodo
2020-09-30SFNFLGF.docdoc 05917a3d7daf2bc7de49c374fe7ec364e19f2aa1b60480a666ed224053f0fe1dVirustotal results 27.12%Heodo
2020-09-30REP_1345319674700300849219743.docdoc 6a8c20f078785ffb74c4a5cebe9fe37cac8d5e8b01641fb56a63499cdd7bd0ccn/aHeodo
2020-09-3064436670197061056454750.docdoc e0598f2efbf03596b6fc2d73a58184b9a4d4277d2fc01322308e86a132582e2dVirustotal results 23.73%Heodo
2020-09-30M_167993858.docdoc d206f9b0e7b447444d1f5d592716186fac89b660509dc88efa51a5701e795a77Virustotal results 22.95%Heodo
2020-09-30946047497.docdoc 0d76776775bf2a2cabdb6e870b77c93df8a87261dff0fe4186297a4a70d37b0aVirustotal results 22.58%Heodo
2020-09-30PO_09302020EX.docdoc 583be8560739028b53b2363adc1a5198c194b0ea7abb706f3dd49e9a170d7f79n/aHeodo
2020-09-30BAL_LXT_090120_PDR_093020.docdoc a4764b420e55695dd9b02d5ca980f126958001ea30e96a74b2e9321661bf38ffn/aHeodo
2020-09-30BAL_74846987.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.22%Heodo
2020-09-30217824130858330575812.docdoc 110b8287dac073cfd63cca6a49c82963d72e5883bd93e56f99445993e41bc097Virustotal results 22.58%Heodo
2020-09-30221928123201120.docdoc ba44584c1f1d349168d9003b0bd7fcd9d738c17877427c3f02ad492598d5c637Virustotal results 22.58%Heodo
2020-09-30INV_00966812.docdoc 19d2f19f8fb5285fb364123fb36a69d0bb65beb57b8bbf7d47364b53b6e60317n/aHeodo
2020-09-30ERH_090120_RTE_093020.docdoc 06f0f241e0f9d72b7bfa912752c572cef951ebe5403388f20bc330e2dbda3c5cVirustotal results 20.69%Heodo
2020-09-30REP_32363008.docdoc 13d2b3475b4383e26dba14d71c6977c5eaac45d957a98cd70218a93fb28ca36dVirustotal results 20.97%Heodo
2020-09-30FILE_6824687101752875462706997.docdoc 19377355e91331d5f2438275b1af46c6f266bd250c9e6a421feb6deaa86f7cadVirustotal results 20.97%Heodo
2020-09-30FZJ8C27DEZYB.docdoc 5bd1dec77e268f1da221047d95d57981748b9f359c04a76b1b80de3a2144c67dVirustotal results 21.31%Heodo
2020-09-30DOC_9448492048849270005.docdoc 420c99cf0d5ca3e0ddb053ffa31741bebe9dd69fb61224c8c741b7ec01e85e96Virustotal results 20.97%Heodo
2020-09-30C_976606868802479037.docdoc 0008ec3cdaed6559d71c8368c3edff8fd35d8f85816c950e8a8cc049ee6bc812Virustotal results 21.31%Heodo
2020-09-30FILE_PO_09302020EX.docdoc 0a2e10583a6c70298eb3c353e0a15ebd98c8a9ae09db8e6cc9cef513e39c95dcVirustotal results 21.31%Heodo
2020-09-30DOC_NT0888702763MH.docdoc 5535272f513a3009b7bfb9a6614f96d6d4ed1c65fcfd7c416583ff2f35173267Virustotal results 21.31%Heodo
2020-09-30INV_66867853.docdoc f753b7a2b5babbf0b90ff334a9ef900a447d43c76c85cd43aed4f4c01db9bf8aVirustotal results 20.97%Heodo
2020-09-30REP_PO_09302020EX.docdoc 24e3ba16d86892e3c786b97123151b7a2294602a61bafd3c546475d0597a2a37Virustotal results 45.90%Heodo
2020-09-3094678799.docdoc 8c898e6465f4f641ea5dc6095375eb50772f4b2d7b0d50f197f74567af847cf8n/aHeodo
2020-09-30DOC_EVG_090120_XIH_093020.docdoc e9ea0a15b6b1599685f85932e8f8621ebe49b8a64c3376cb3819d4b9f5b536beVirustotal results 44.26%Heodo
2020-09-30BAL_6BHPITCK5.docdoc 16570616ac7a29eab86f3d418f18b67750c4deca1c01529454e5f1a591e6fc6dVirustotal results 45.90%Heodo
2020-09-30WW2816548222VZ.docdoc 1f7fb407f4aa9c2e8d59826ce97d6fa642f0103b0c140bb54dc65cbe8f8c92f4Virustotal results 45.90%Heodo
2020-09-30REP_PO_09302020EX.docdoc 010d313ef5a6680acc6fcdaca0eed3e19f256a23cac861684466d6e7f7138030Virustotal results 41.94%Heodo
2020-09-30GL2048968227HX.docdoc 0bffbb268223d255d4ebdcee53bd0d8e990843600bf96f811f47a550d1e366caVirustotal results 39.34%Heodo
2020-09-30REP_396855406.docdoc d8f8b40e6c0fff5344fce0199e4fd683f50bc846af26963d53ea1554aa202e61n/aHeodo
2020-09-30DOC_RZ3915708967VJ.docdoc 31096733d8d5f5ecff8a6a1f0bbf9b3af3fb5f1e8f0b509b342a38cdb0a01b43Virustotal results 35.48%Heodo
2020-09-30REP_XBP_090120_TJD_093020.docdoc cf47fcf596bf3abee5508f311666cec1399ab7e9b1f1632056db94a3e3a54468n/aHeodo
2020-09-30DOC_84336815.docdoc 8649c9f23563646d5b0033bb729307388ddb4396da639cbf0385c08ec0a01cffVirustotal results 32.26%Heodo
2020-09-30TA_IK6219505533CX.docdoc c23dbe57bf9ad222746ad89939427a3fec7c2b13f26a03922e9450f6d07ea0cdVirustotal results 31.15%Heodo
2020-09-30BAL_PO_09302020EX.docdoc 5620011cd8bf0acd1f3ecc32958d26a9f38c982b191406bada41f3db5a9250e5Virustotal results 32.26%Heodo
2020-09-30PO_09302020EX.docdoc 5fce7635748a17b0553d34bb396757644f6ab211ed7865fcd3ecf8b5f1014b29Virustotal results 30.65%Heodo
2020-09-30SR7347654202PB.docdoc c7e94b09a7bf83d363a7949d7aef5bba5516bd5b0e0c149bbd1dc341b9cd5180Virustotal results 32.26%Heodo
2020-09-30BC5461147772NY.docdoc 587adcb5768ec9aa8b3be79e9ea740bc5052b9d0f09d4b2854fac3ff667edd4cVirustotal results 32.26%Heodo
2020-09-29INV_DTX_090120_SUV_093020.docdoc 6596f751d97b234516bc66104d96abd644a86657c7c981f245101bb9bba1c004n/aHeodo
2020-09-29INV_BL9960939284PX.docdoc defbca721d5850239ce954155a629ed1728ce578781b3e387d8c6305144f0838Virustotal results 31.15%Heodo
2020-09-29INV_6T4AGYFZUHLRAT4.docdoc a0269d67f007490795637a732bf26ce5976a2b4039df3d784930ef9109697365Virustotal results 27.42%Heodo
2020-09-29OC1A44QJDJL2NWW.docdoc 91d4d101c3e8a665106bb48847dbee3791e2a9a04c0adb2f363ae7767e463337n/a Heodo
2020-09-293513476778298543443.docdoc 16b031e38044afa7252dbfb56c762b3723de1cb4b3535a8c76bd5d4f10a2819bn/aHeodo
2020-09-29156963834795201015.docdoc 97e4792de43a00a567ff58378d7f6e6c3c4463b3fe2a15630115723f57a2aaddVirustotal results 32.26%Heodo
2020-09-29BAL_64937415.docdoc 5560f4bd35a2f200e40eee7a63cb48b4d539e2f6dc8d1d793356e1a6b2b9cb1aVirustotal results 31.15%Heodo
2020-09-29DOC_DT1AFKGJPMYMHGUH.docdoc a1ff4c3cc94952016f96e7696b9d0eff572e92076bc8f88bab00ff2dc752a676n/aHeodo
2020-09-29BAL_YHQ_090120_EHI_092920.docdoc f3bfbdc45f33d12c9a3b74c9524c63fd1a3358ebbfd8ee7a9fb3dbbc14d339aan/aHeodo
2020-09-295612210892789.docdoc 844dc7bc8eab502d43f5eb0a7501fc0b97ed3192fe06e4e2f33d69dd28fb63f5Virustotal results 33.87%Heodo
2020-09-29FHT_090120_IPC_092920.docdoc 4b00a598c3d77faf9cb3fc8f0432a1dbe25d233571c98f35c4cc6660d604297fVirustotal results 34.43%Heodo
2020-09-29INV_PO_09292020EX.docdoc 3bf884e5ad0e7ae1e5bda8efd025ebe7502e8446e0675345a83138de1f052c2bVirustotal results 35.00%Heodo
2020-09-2921898378635291447884.docdoc 15513b191f34ecc5434e13d6ff1294840e3ca161628edc0caa89e89f6988f357Virustotal results 33.87%Heodo
2020-09-29INV_55237861.docdoc cc633359c9ead5109a405c7198a5d2459585c688f6e42c72ed529e48012ecfc1Virustotal results 33.87%Heodo
2020-09-29FC4918892926MS.docdoc 67453aa858ac24a5403b4bd5cc27a734bc73baed1a8d891fcbcf0dafaf280d53n/aHeodo
2020-09-29FILE_VF0127308375GT.docdoc f5952e1591a78ddea08f92a05173c71fc1551946dd158159c60824196fc815dcVirustotal results 29.03%Heodo
2020-09-29INV_ZEVVEWF.docdoc 9ae21072207eae0305ed8609595405bf159e0b6f8122f4cb9bf626743035c940Virustotal results 24.19%Heodo
2020-09-29WDE_090120_SFU_092920.docdoc dade9df0dc4f0946c890687fe36e0d7606ab7e2679a0cfb77ebf88e0881be28fVirustotal results 27.42%Heodo
2020-09-29BAL_PO_09292020EX.docdoc 2c95d5fcdfdb060215112fb122d9315d7e155ffd00e61593df65e257922e252cn/aHeodo
2020-09-29LID_090120_CCN_092920.docdoc 35a7d1e4e7dae6447866f90603a716f6989b46c6392ed7d591476460471cb021n/aHeodo
2020-09-29LP4387317311FL.docdoc 59f15b56958e59270a62cc0cdd726486f7afc4094d189b78461abebb9ba864ddn/aHeodo
2020-09-29REP_PXI_090120_YUQ_092920.docdoc fd01fa376c49cf1089464faa2e699d3ca1d88c79ecfb5e0c8bf39c275ce846d9n/aHeodo
2020-09-2992879753.docdoc 4389a40fe8a20d1e8eff4be2fef943890f835363717a6669ef1ff624b480700fn/aHeodo
2020-09-29REP_7ETTC15GW.docdoc b8ce486a27d2199da8187d23d31051c584a094ced356eca2749361016658a90cVirustotal results 24.59%Heodo
2020-09-29BAL_QLX_090120_OXE_092920.docdoc e70eea5dcae2b820b19bc58b794ff2b23ec6a26d8fa07f05171b1acb8585fefdn/aHeodo
2020-09-29FILE_LMFPTTYL0B22JR.docdoc 14e39acf384b4f3ae83ab61b0768b7ac4869961c6308d694a8455e064cf0358fVirustotal results 24.19%Heodo
2020-09-29WE_49809544593422486123.docdoc 958d53abea6cf0f1aaebf262ad00527d7662a411d70635dffb45d95e2a44c80eVirustotal results 22.95%Heodo
2020-09-2944103686.docdoc a0d65313a8c5c4788cbe425f50f07f9a6ca0bacbfacc94abe3eab4edd1ac6d98n/aHeodo
2020-09-29ZQ_VMQK9MGYVNCT3HW.docdoc 9837d0e98959e8df159836eb545f5246cb56cfc6834a2c5e7165a3d6ab093aden/aHeodo
2020-09-2975817502.docdoc a32651ce03177d2f8041c778caf33bf6e04eea4980f61175dd535d94af5f2562Virustotal results 24.59%Heodo
2020-09-29BAL_37431726.docdoc ac227d3a7a5726f8481ab18b06d8afab6c1d4f31572578a71f4375020fa715c1n/aHeodo
2020-09-29DOC_WLH_090120_UYS_092920.docdoc 2f573426338f3124058f01c5920d41ff9f2b212ee8fdd13cbc816525ebe297c5Virustotal results 24.53%Heodo
2020-09-29R_4MX8B8EOKST3JBLP.docdoc a916028a8065134286abed17393e55e315c9ba012558b7a0875e09ac2ff95e50n/aHeodo
2020-09-29FILE_PO_09292020EX.docdoc 5cc2ba0f2f951a4045c7a3b85e3c0c49e32c14ab752b3e3f0b3bfd09f8a67eb4Virustotal results 50.00%Heodo
2020-09-29BAL_KGJ266B8VIJB67GS.docdoc 4912920161a89e77767bb63e569fe20ad422dc4efb1d8f794fba70345f16be56n/aHeodo
2020-09-29INV_66379178.docdoc 79b121ca291143b84bc1cc6c6a2a5f5f734bd157440ade16df5fd0cf683356aaVirustotal results 48.33%Heodo
2020-09-29YE9897458741PX.docdoc fe99636ff633a694b3154481012964211dd0d673f3035496a7b56890c7a66994n/aHeodo
2020-09-299356832223480740353.docdoc ce63bb03d151320fd8fe4e45c193004bf9bc25d49566a7d8afa665c14f5ad143Virustotal results 45.90%Heodo
2020-09-29UXK_090120_GVN_092920.docdoc 63f795ea1096d9e86352f2bbb2ba0c971a7b61a187e273268a48876faff51592Virustotal results 45.90%Heodo
2020-09-29FILE_PO_09292020EX.docdoc 16b6fb9ec33ddfbfe170b96abde09256746cdc4b02e531d5064454b62d4dc694Virustotal results 45.16%Heodo
2020-09-29D_PO_09292020EX.docdoc 262b1d7db4c435c5a337c8e245fc74ca1420f3316cd2b542789ba5cf8657e1a6n/aHeodo
2020-09-29WDG_44036535.docdoc b2e71daf0ebe60a19e0b62852d7198b9e94b1d5cc89227fed97ae2054e7e3d71n/aHeodo
2020-09-29FILE_29664261.docdoc 04b4ca2b62111893c8b9d72f55fc818d3b9930694c78eeb03336f9911a069f5eVirustotal results 46.67%Heodo
2020-09-29JWF_24559296.docdoc f017fb57e3d63cad2e865981e345ac9c31f64c1114aaa4e21c6aeff31cbb13d2n/aHeodo
2020-09-29REP_XN5639586352LC.docdoc f0b67e53770af42aa08ec513bd9ea60d15d3b506a1d2609e88e0ce31009681ddVirustotal results 47.46%Heodo
2020-09-29FILE_GN5627033297QQ.docdoc aec0879b78a9a099436d59b73582462c6149429a5b11474954ba0fa0b75d7c64n/aHeodo
2020-09-29I4BKVFUG5RX4CMW.docdoc 1b4294152cd807e23b698599e9be39ec531fc28ab159272ea894cc5633ab2cbfVirustotal results 45.16%Heodo
2020-09-29PO_09292020EX.docdoc 15d3403b8d1d07b8b635e79f0fd458c3961ef5b48d60d19b6596c9c1028a2662Virustotal results 45.16%Heodo
2020-09-2919385579.docdoc d3b204a9a314a83910394cbfc8ce9a3ee143f7dff5fb09a1f17b138bd042f27aVirustotal results 42.62%Heodo
2020-09-29RHX_090120_CKG_092920.docdoc 70ea160fde803539083eb208609b17b5910f502f8bb0a3e36e053ece5b214df2Virustotal results 41.94%Heodo
2020-09-29DOC_7X1XRNP3LNDSX.docdoc ccc18b91da784754f83482778c7bfc1de931b4416de9957b6e7b61b25d8d43caVirustotal results 40.32%Heodo
2020-09-29DOC_XCR_090120_IST_092920.docdoc a973fb7943766b57cd43a3411ebc0e4f2526142e27a0c7e259a0fdabd30a5596Virustotal results 40.32%Heodo
2020-09-29REP_41031544109562238.docdoc 4c4e1aed7c1838c659246b58c102e3b76d81af472ba0ea11e3102e7f31aa12c3n/aHeodo
2020-09-29Y_157829123614410991581.docdoc acbe625125210f292986e1a32b358fc608504c11aee463f05e4ea2b4ecac55acVirustotal results 37.10%Heodo
2020-09-29EC7942464267GI.docdoc 8d59fd778e28d2031a7419577a57bcbbfab3de3caef805c35e4431f436328d85Virustotal results 37.10%Heodo
2020-09-29REP_OQ2495607668NR.docdoc b74254f66908c1f19454f3a01f443968483b4835fcb9952d5ced94e754c9f312Virustotal results 38.71%Heodo
2020-09-29PO_09292020EX.docdoc 3282dfbfe42f2f929d4e24a4b8c1613f9da3bfcc2e228a3692a931afc3178189Virustotal results 37.10%Heodo
2020-09-29FILE_WE6846787193EZ.docdoc 62d1a0ddc98b6e9f6f22539f196550672415057298dbe058673fd5fc8bab7bbaVirustotal results 37.10%Heodo
2020-09-29BAL_54949556.docdoc f84be91eaa46a92cbd5d01beea7f41b3b0422079aeb425f74b2322266934c301n/aHeodo
2020-09-29RDNO_EBL_090120_FIP_092920.docdoc 6f7ac22d800aed7da1b89ca41cf9288d41ca2d701f2bc69f206bed6bf832fa7fVirustotal results 35.48%Heodo
2020-09-2923738441.docdoc d44b534f8c20e7e7c7fe8d7434575f4fbfe7a42960fe2afa6e940537a8d10c2eVirustotal results 32.79%Heodo
2020-09-28UWWH_PO_09292020EX.docdoc 44131c8de1ff671fea937fba153e30d90d47589f2bc9a1c31bba2f8ba1bd4b66Virustotal results 32.26%Heodo
2020-09-28BAL_O0YNWTRZ2C8PA.docdoc ad162ea344a884fdf83bc38e367c4c69d56e4822fa123d56a21b6661c38cb3abVirustotal results 32.26%Heodo
2020-09-28FILE_DC3K7B5.docdoc 5511a4406f3aac11acd3a67d5b5a567088a88e946caf868616b1de1bc329b09fVirustotal results 32.26%Heodo
2020-09-28DOC_AIJ_090120_SRZ_092920.docdoc b2228c113565358749244babdf08ab1a60ce07c476644361178fc7cebc8e9423Virustotal results 32.26%Heodo
2020-09-28INV_KK6295025527JQ.docdoc 451729fa901b1712cb373d4055fe571d1dd1879d5bb44f2b34dcd6b0a6f81e95n/aHeodo
2020-09-28REP_254728001245.docdoc e5318ab47f585bcfd94d4c242e2b2977c8b23359fd96c94325c0f2e5a87ab674Virustotal results 30.65%Heodo
2020-09-2811019752.docdoc f1128b4b115af957d794812accfa22e05ddd588d3fd52e5c72ddc7429468142dVirustotal results 30.16%Heodo
2020-09-28PO_09292020EX.docdoc 929d7e6048f9e35070989f784268013a55e08fca900478f5303eb8255879e5c5Virustotal results 29.03%Heodo