URLhaus Database

You are currently viewing the URLhaus database entry for https://amirthafoundation.com/wp-admin/89B6CuGsRr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698961
URL: https://amirthafoundation.com/wp-admin/89B6CuGsRr/
URL Status:Offline
Host: amirthafoundation.com
Date added:2020-10-16 01:19:08 UTC
Last online:2020-11-12 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 01:20:05 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:27 days, 20 hours, 14 minutes Bad (down since 2020-11-12 21:34:46 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17file 20201017.docdoc 294c6f87d8514072c30988bd55dd643c5c018b9f9ae05b9db1a97d034b31e092n/aHeodo
2020-10-17Attachment_W53089.docdoc ea4cb3d56a4e049d8d0e7d1e30ff96c6b4fd216860a4c48ed248940702f3b7acn/aHeodo
2020-10-17List.docdoc c147f6f4d8e08ce92756aea055fb18dc3398e77ce2ba5a71bfa3d6eb5f3de750Virustotal results 53.23%Heodo
2020-10-17Arc_2020_10_17_DB566413.docdoc ccad29eac2b2a4c03fc1c9a9ac36544345fb0a5f454746c05dbb5f02d4d53210n/aHeodo
2020-10-17list-20201017-08898.docdoc 8b3323767793829332133050855ac69ea1a0cd1b5a51441f1baf16d09f47e663Virustotal results 53.23%Heodo
2020-10-17inf-07451.docdoc 203a54f8692f6554ad685a3d9e94ec1f3482366c3c455312540f744cbda4f479Virustotal results 53.23%Heodo
2020-10-17file 2020_10_17 21791.docdoc 559b9d806bede7814d4c85984a6e6815356e1ce8e730ca7907309e03eed5fcaen/aHeodo
2020-10-17Inf 789260.docdoc 674b59aa10f963845214c91833225375d26e69ccece07609e8a5425a8d952346n/aHeodo
2020-10-17MES_20201017_GIX2016.docdoc 49bfab81e7c83836e13d24a1c3e607ce00aa745e850f110ef848cf96ab0b5b30n/aHeodo
2020-10-17REP_20201017_6061.docdoc c64264c7336d7e9f516999fa287be55be63b634b63f5ebbf1bab24e38ada5e8en/aHeodo
2020-10-17FILE 2020_10_17 ZYJ6088.docdoc 1e52bc38ce5e8a3c4da25a7c7e4d8169a31fa22bfdd9e43759ff57d25b40db02n/aHeodo
2020-10-16Untitled 2020_10_17 MN275492.docdoc f248106a010a23404bc680541ff725431478f2a3a368efc846d4bee707af6c22Virustotal results 51.61%Heodo
2020-10-16Dat 2020_10_17 LOK574.docdoc 528b63ef8c44d0a5b08974fb6ad9efa60e0021ce6993d25b30ef1b90c00df222Virustotal results 50.82%Heodo
2020-10-16Untitled-20201017-81878.docdoc e6c583d968049b133209f01abf2a46bfb3fdb4abd68b5f0ef3e74881c438d1c5Virustotal results 52.46%Heodo
2020-10-16REP_2020_10_17.docdoc d546749eeff6828f731a5f79a2352276696d9ce6d5614dc6e9779fa2dbbe6799Virustotal results 50.00%Heodo
2020-10-16list_58460.docdoc c5480c5bcd7c9b06e744ebfca49ef98e45da1200c5e3762d6b47d9825189f3eaVirustotal results 51.61%Heodo
2020-10-16ARC_454.docdoc 5c58c91ffdffd84690c6746f6afc2eaeacd03df2e4a83c6e662755624113cf5bVirustotal results 51.61%Heodo
2020-10-16Doc-2020_10_17.docdoc ee2a584f20b8fae9caa25baa3476b1dae0aac0d511a2a2584dde95eeb42c4d06Virustotal results 52.46%Heodo
2020-10-16MES_2020_10_17_F83144.docdoc 1d74d9c148d2a786425f0447d4415368184fd896521dc5054434c999fce03a31Virustotal results 52.46%Heodo
2020-10-16arc-20201017-8732.docdoc 4c125553bd2edbf5672acedb290d618c67fab2f3b02f055bf22af25030b3cb34Virustotal results 51.61%Heodo
2020-10-16dat 058960.docdoc b015413e8bcf3517a1c413b7e32d1c689a414890a8158ac80e9d53b759cb488dn/aHeodo
2020-10-16arc-20201016-F384.docdoc 14fb23d425064edf96ba4acb656479002d69054eccbae3688760eda138dbb67cVirustotal results 51.61%Heodo
2020-10-16Attachment.docdoc becd0ea41a6c3f2b51a69aa00a1cbebef6693500be304c1930355601ad2972a7Virustotal results 51.61%Heodo
2020-10-16REP_EZH140.docdoc e78b57e96d5a3632c93a56a0bbc199107c194dae316c84dd64473a513a3b6745Virustotal results 49.21%Heodo
2020-10-16File 20201016 WU339.docdoc 35359c56db6c6b554320c0f3f2f1ac6470ee849d0e7bdb20696c529df2a3336an/aHeodo
2020-10-16inf 20201016.docdoc ff2225f50847fbfdff2af9e81b67fc82dc5a26f7c4a78edbe36d775f1c153c22Virustotal results 46.67%Heodo
2020-10-16Dat_20201016_BP65240.docdoc 0e044c945bad69533f1cc676a53ed59d287e4681c239be2a61e9e4c46775da4dn/aHeodo
2020-10-16rep-20201016-4750.docdoc 73af5d8dc838da50fe5bf91e2d5b0c477691b5f53a915e40966cce23390b4d73n/aHeodo
2020-10-16Dat.docdoc bddf126e79e9a62c235c0b9b763a594d8c49fc76d38f39400409262f43373d43Virustotal results 48.28%Heodo
2020-10-16Mes-2020_10_16-TQR296616.docdoc e74ba7fccd951257aa46146461056b2353a80a3ea72b7d5216ca148d2d8d99cfVirustotal results 47.54%Heodo
2020-10-16ARC 2020_10_16 023.docdoc 1393a509d3636597224811966d26db77105cf9e68c236f014ff603742fe1c610n/aHeodo
2020-10-16inf_ZE8177.docdoc b458f12a6949fee524edefc720811a94bcdae2ba4403be20f0b1df513f4c7ac9Virustotal results 45.90%Heodo
2020-10-16mes_2020_10_16_BA844.docdoc 5f2eb46eed34d525d905966e80d1a6ec61d52eaeccf1e48b56ceec4a9b1403ebVirustotal results 45.16%Heodo
2020-10-16Inf-2020_10_16-FZ482.docdoc c9590b8ccebf3eaca2e64fc27644c7e7a3966d001c3168c1f56c9e943bc18360Virustotal results 43.55%Heodo
2020-10-16Rep-2020_10_16-Y529893.docdoc fef1542f85d70667aadc0ed3e4755b0fa709566515c2768f4edd721979046efan/aHeodo
2020-10-16Arc-2020_10_16-WA183.docdoc d382b252799d94951c351f38f54c1154fed8293f5018c4441b345e556f5fc26fn/aHeodo
2020-10-16Arc 705.docdoc 8c0e71b1c34fd45cc827814c7f99dd2914cbe2de12149a0674cfa3855c90acfen/aHeodo
2020-10-16881WS_2020_10_16_954.docdoc 08950bd0b88ee6941d13880b6a594546190c0bb35a72469bef188ecac39a037en/aHeodo
2020-10-16INF.docdoc ce8eeac08f63bcfb0fe4c6574a73f4cc03efd10f02317b4ea6a191b30a12f53fn/aHeodo
2020-10-16UEL24406 2020_10_16.docdoc 6dc2e8f2ba098be7efe15f27abf2844722350272930fa86b350d0d2bfe653565n/aHeodo
2020-10-16dat-141441.docdoc 61cec25d2216c4e765af0a48b89874eda71f82d2e2203b656ca8d697952fdce0n/aHeodo
2020-10-16doc_286.docdoc 3c6c43257610bf585d2e3a5e802fb27c624f8a82fb9491e6efded8b2b49417a0n/aHeodo
2020-10-16ARC-20201016-779.docdoc 5dcbc3ca0de0a87ff5d782320c293502637d846e86c909bf7540a4b25924ef04n/aHeodo
2020-10-16Doc_2020_10_16.docdoc 7866efd7e1341548d5b729f004133719303c3761ff095f569d692b31f64f3e33Virustotal results 32.26%Heodo
2020-10-16mes_20201016_EZS99924.docdoc bbb7624d95e01bc02d79430556247cd0111cf701a4d9a51adee33a487c2c30e9n/aHeodo
2020-10-16file_20201016_1650.docdoc aacd12efd23212b0b9b6324b46e0c5c94877447ecc6f5757f31799e606b7a9ean/aHeodo
2020-10-1680021-20201016-EAV826203.docdoc c6c7afa7966bb7894acb77743a551a1cbc5574c4160726902a71386dff621ba6Virustotal results 32.26%Heodo
2020-10-16INF 20201016 FFF525904.docdoc 3b7f8920c7db99db8aae73225dfd19e4519781f7cb79ba47fba3f0b57cfc8713n/aHeodo
2020-10-16mes_20201016_EV70509.docdoc 23321ef2552ae21809b21f51b4380c31d17917222fe373a59d73500eedd99fdfn/aHeodo
2020-10-16rep.docdoc ad29fba32bbfa20e1769369f3a121ce461433fc55e719db4c522855e858262a1n/aHeodo
2020-10-16Untitled 20201016 4120.docdoc a6091d359b405ea83e58000e282b0bd40824c64d36b4546077d786ff19124be1Virustotal results 49.15%Heodo
2020-10-16FILE 2020_10_16 9881.docdoc 15c9b8c96805cb5eec520765084f122d2d992f581b1e885ec67341e7b7954006Virustotal results 50.00%Heodo
2020-10-16REP_2020_10_16_548.docdoc 8d55bfa88aac7102ed41f043d7266e85bfd3e83d0d8f7d298876419eb1bde683n/aHeodo
2020-10-16doc 20201016 3154333.docdoc 5072f3218fa0300943629458afd87b56759783ef8776b3ca783f282ec185e33eVirustotal results 48.33%Heodo
2020-10-16604Y 60767.docdoc a575516d48e96ddfbaa7108fdf2f06fe978074c0a71ff7162c8631b757b8cdc1Virustotal results 45.90%Heodo
2020-10-16012780 E985.docdoc 996992e84d7b7738fc92c7128d94ee35099ffb68e829cb534597b46b854ce1beVirustotal results 40.98%Heodo
2020-10-16UNTITLED-2020_10_16.docdoc 878bb13d04d93f1209ba23990aef838329f86ff7fbd86d5bc6bd24da81dbf0f7Virustotal results 46.67%Heodo
2020-10-16List 2020_10_16 25128.docdoc c7cf5a3d5d7fa1c15561e9ae23236bca356132e283a8651ce8f9257bdf79f77eVirustotal results 42.62%Heodo
2020-10-16mes_4081720.docdoc 4bcee4209d4076c06692a189497b7953ee701dcbd290530146d15bac6391ca75n/aHeodo