URLhaus Database

You are currently viewing the URLhaus database entry for https://aramcotools.ae/wp-includes/31574374417/W5I4MkCWqlb6uRwp5p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:751666
URL: https://aramcotools.ae/wp-includes/31574374417/W5I4MkCWqlb6uRwp5p/
URL Status:Offline
Host: aramcotools.ae
Date added:2020-10-26 13:00:06 UTC
Last online:2020-10-26 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 13:02:03 UTC to abuse{at}a2hosting[dot]com)
Takedown time:2 hours, 24 minutes Good (down since 2020-10-26 15:26:29 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26REP-2020_10_26.docdoc cb0f9c9bcce4f520c871ab095423cc91154f163a2c86e88aef0e63466974ea0fVirustotal results 33.87%Heodo
2020-10-26REP_20201026_A936588.docdoc e8931527bc1c4fd0c45a9162060a6bf29a0d06679916d892cfffce7882a1481en/aHeodo
2020-10-26inf ZRD9720.docdoc ff68589efb48ed334df874116da99513e4be8d9b93dd70073f912a46f1c7276bn/aHeodo
2020-10-26Rep-20201026-596.docdoc cb7ba7a31e5fb8bae2b722fa5deb8ada4ba392a89068d2ae985850a4470f2e45Virustotal results 32.79%Heodo
2020-10-26file_2020_10_26_SVJ22944.docdoc 5ed48d52b3361971f8fd0a9853c6a6850c0f012769a71d3f68e2808845ff1f09Virustotal results 32.26%Heodo
2020-10-26List-N09646.docdoc a9aa803b3c3f9f462ec1bd17a2380b956e9872f917bf9a7232c1a96c6aba68c0Virustotal results 31.75%Heodo
2020-10-26Untitled-JT1084.docdoc d1abcf7be3ad51873e8f18e2f2d07487da68b9450943ee963efc561fd680fc3dn/aHeodo
2020-10-26Arc 938.docdoc 5bdfa0c917624bd7de8b3378352e10dfc48b33bd79c14f27cc5b3e9dfe1d1ed7n/aHeodo