URLhaus Database

You are currently viewing the URLhaus database entry for https://www.ahmadifoundation.com/wp-content/VbikDMHH91qaVvjurNtrPpR7QI7Oa3RmTCJkh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752328
URL: https://www.ahmadifoundation.com/wp-content/VbikDMHH91qaVvjurNtrPpR7QI7Oa3RmTCJkh/
URL Status:Offline
Host: www.ahmadifoundation.com
Date added:2020-10-26 15:56:03 UTC
Last online:2020-11-05 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 15:58:07 UTC to abuse{at}godaddy[dot]com)
Takedown time:9 days, 22 hours, 3 minutes Bad (down since 2020-11-05 14:02:03 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28inf_1277110565227.docdoc b1de6df6c2b5ac15a030ee3b606165a808dd7fb78a4d22a267e304c2edad0fc1Virustotal results 29.03%Heodo
2020-10-28297260784320767937596.docdoc 4da551741b2fdd1985b8f8dd865cbc2ee100a8d82d80a39e33f56dbda25b4f1eVirustotal results 28.57%Heodo
2020-10-28Attachment_PO_10282020EX.docdoc 86cdca7c9ac7ecd5defa0fb8c374cd773aad5df00d6678e7f5addc0268a097e3Virustotal results 28.57%Heodo
2020-10-28GTY_49324974.docdoc b10f4a4b46a88d8bd137cb2d76eb827b89f16acd953490d55b6161aa0e99b7aaVirustotal results 28.85%Heodo
2020-10-28file_98361787.docdoc ae95832fb60bc0562205f82b20e87746681b63fd589abc9312ca650f0cde8507Virustotal results 39.22%Heodo
2020-10-28Z3BJAZII.docdoc f605f4309f21e3797ba0f7b9440dbd45fb913a363be8a0e774040e92e05418fdVirustotal results 35.48%Heodo
2020-10-28file_AMT_100120_FQK_102820.docdoc a74bd9bb59caf16dcb34bc909644f9b39712ff04e230af2fd8f4838af00e85f8Virustotal results 36.07%Heodo
2020-10-28Attachments_PTQ_100120_OGI_102820.docdoc 0b62b154422aa927a6906a75fdc8edfd4c143365e4b5e4a8ffd58badd6fdb0d4Virustotal results 38.89%Heodo
2020-10-28UNTITLED_489270614557469.docdoc 553f438bc1486ee99b764c15bf3caa7e8fc1b49c48ace061dbd07220a7e56eb7Virustotal results 30.16%Heodo
2020-10-28Doc_091051171.docdoc f43cc95ed3a2f8900938c6a240d69a2de909494821ee8308e740e2cda2fd31d7Virustotal results 32.08%Heodo
2020-10-28ZWJ_100120_WKI_102820.docdoc 1371c2d34a1e3ad727d60804b08ef021e7568a841acc95ce5cf1773149657ea7Virustotal results 29.03%Heodo
2020-10-28List_00378962.docdoc 3a183e3b2c742a3307c322a6e8e75c3741b4b35e456bacd95fead4ceb74fcf12Virustotal results 31.25%Heodo
2020-10-28inf_PO_10282020EX.docdoc 7f286766434b67cb7ea25119d469c086c70807bf665e8e373acb472ec284a72eVirustotal results 31.48%Heodo
2020-10-28F_CKO_100120_QFU_102820.docdoc 56bac923cdfd4440f1cb05f87560995bd487d31fb83f16ba23e935825657a7feVirustotal results 27.78%Heodo
2020-10-28VH_UPU_100120_XFQ_102820.docdoc e774de558ab588e2aefc6661f8ddf20b6a02ef8a6e2c4504a0b03e27d9c19df3n/aHeodo
2020-10-28ARC_JKV_100120_BNW_102820.docdoc a9dab3a7ee17c4e9ebd90271c21ba1f27a69094147e4f37b14e8b584ef3bf74cVirustotal results 27.78%Heodo
2020-10-28Inf_IP7406097926XN.docdoc bc8fc695c99b9f0fca7e18ca67adb66451f6b6b408ba6767bd86db835466f292Virustotal results 24.19%Heodo
2020-10-28inf_PO_10282020EX.docdoc 43159cae0059060554e0c283a577d48c0b825e44856b3afcf24ac2f6ef831334Virustotal results 28.30%Heodo
2020-10-28arc_NE0540827760TS.docdoc 09a4d7f3bbc95dc5b795441093b4f44943d384f0b9087a71ddaf1b55eda16ec6n/aHeodo
2020-10-28UNTITLED_MU7380599664KB.docdoc 42437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17Virustotal results 20.97%Heodo
2020-10-28doc_PO_10282020EX.docdoc b1667802a4201e50d756b921bd73789dabdc6e0ead93ccde248f9634cef63d6aVirustotal results 22.22%Heodo
2020-10-28Attachment_3004166830612945261860.docdoc a30d2b343e3646a2a05e98c5b7f976a1f67e12574ecb880a2a460bec35735f6fn/aHeodo
2020-10-28List_34849617.docdoc 4d2065b87b5e9b6d1f4bc0bb53b3244c9d61eb3fd8c95d64757935758065ff29Virustotal results 28.30%Heodo
2020-10-28Untitled_87960649373201.docdoc 7eb74017c164dd7972d8d6fc795baaf0f0bc4593227af0752e986dc52bcbfdcbn/aHeodo
2020-10-27N_02796365.docdoc 9efa8997bf4ffcc29b996b1a0dd651e92bacb8e79143a0c008cf1eb4a8b41cbdn/aHeodo
2020-10-27file_XJ7HQGKHPR.docdoc bab42b7ee6d4b385f15274f7900f7f2a4d5d68d7f527d20b0bfac926752f9b3an/aHeodo
2020-10-27inf_PO_10282020EX.docdoc 7179df59ef9df561ef65cd5b7036f02fa09b49c0abd229b6a5c4ea270c49d318Virustotal results 19.05%Heodo
2020-10-27575009933044720.docdoc 9e67927cc9cf11b38167386aa1974faf5516155e23095cb9b5a2daf9686957e6n/aHeodo
2020-10-27file_UDH_100120_XKN_102820.docdoc cf37bc70aa99bf4d8ac44a3ded10f1d82deac713ad88ca9aa9f6f550ccf52f2cn/aHeodo
2020-10-27Rep_OFM_100120_OSQ_102820.docdoc 786139fdf387d3068d18ba7eb1f55806ca956cd8834e1bbc350196ede6433fddVirustotal results 18.64%Heodo
2020-10-27Rep_XE4646040035ZJ.docdoc 94510a446cde22ca891a6753fdedb13a499f03851126bb7146e8f9d923f1dedbVirustotal results 22.64%Heodo
2020-10-27ARC_XNWCC2G94G.docdoc 072432dff65efd13b9aff5f11e2110b10d7faec139153eecfc4d332e3e7413e9Virustotal results 19.05%Heodo
2020-10-27mes_MMU_100120_IPC_102820.docdoc adaa6cfe6f38da277ca461fdc4d6c81d643d1c91babe46515180b90cd041fc15Virustotal results 19.67%Heodo
2020-10-27List_5491022399429742186042408.docdoc ef29a8422b09e506af3affcef90be9236f769d51ce6a686df8fb8dfc6fcd1284n/aHeodo
2020-10-27Arc_5182442864.docdoc 12e68ae11d4760770f0cbbbff076d4433df71d8674e10d3875994fc1d749b1d6Virustotal results 22.22%Heodo
2020-10-27UNTITLED_CB4KZLTQI.docdoc c648fbdb326aab7ad03eb32dbe84421e283c66f1f7d21f8cf8a392332669b8faVirustotal results 50.00%Heodo
2020-10-27KOC_100120_DVX_102720.docdoc cb505678e0c2debe5c5b4647af5940e08ffbb2d7a1c73de09136d64560cc0696Virustotal results 50.00%Heodo
2020-10-27rep_45315619.docdoc ac38635cf95cd57e39ddffbf34b5723f519de18d171802bfef7ad76a439a59d6n/a Heodo
2020-10-27FILE_22762048810.docdoc f7496ff4899b8d1febae957c9f03aaaf262609fb62b4588471fd7b15dc107d1eVirustotal results 47.46%Heodo
2020-10-27File_63517229.docdoc 69c66278b808dbebfd0dbcd3869f502a33b285251e49e1fa7f9fb6fc7deff266Virustotal results 50.00%Heodo
2020-10-27file_PO_10272020EX.docdoc 53dfce57e9c5c4d1fa5dbfde99dffd5cccf677f96b297a5a517d86f93cc81bbfn/aHeodo
2020-10-27file_5476359439007222.docdoc 89cb35ed3b6648fb9fd0542fb512693bd9af34ca63e5d61a4b0d5902377132afVirustotal results 46.67%Heodo
2020-10-27Attachments_PO_10272020EX.docdoc d275dfd9deecff34f1d6517f1f94e749e35b61b910fce3a52080e9b413f0968an/aHeodo
2020-10-27Doc_QVQZZ833RAR7.docdoc 7188846dfd580ff0556d07f492f0e53ea9b6d632f54f7749b2d1ce34cdf0ac48Virustotal results 45.16%Heodo
2020-10-27Doc_HC997L13NNPZZ.docdoc 82e13c6c6c28efe1784b06b488b4ef8303c4c9ada6e9f8815a30bea58b19629eVirustotal results 44.44%Heodo
2020-10-27DAT_AN4625929485ZG.docdoc 0d324b35e9e1354566e22c431eb9ee5f36c4ade28ed5acf57bbda93ff7c8c1edn/aHeodo
2020-10-27Untitled_PO_10272020EX.docdoc 22ac8237bc5e3f90f62a2b7fc69ed3ecc6bf52f767e8b8a52ebdee9e4e09d8a6Virustotal results 45.90%Heodo
2020-10-27Attachment_79306539.docdoc 1a085300939d5afedf7de966fc70593f8abdaefad80639cc2153cb93450e1014Virustotal results 40.74%Heodo
2020-10-27file_MA1GJVHD9T5GWMLA.docdoc a0ef9fcda78c9700644ecd5b7f1088a2d3d69402f143c6d597d163ec8ec8f956Virustotal results 43.55%Heodo
2020-10-27Attachments_PP6599707511JS.docdoc e9ed0e2383e743b2c64d4c7a9dfa27ef8352ca6b03cbc8b606f72368c42c0196Virustotal results 41.27%Heodo
2020-10-27inf_XB6539355828KU.docdoc 6fa6e20d7ec107f63284a312ab290e80286e32c497a623e5002f111ce34dee75n/aHeodo
2020-10-27XE2771797411SX.docdoc 017909307178fa381f530ce4b1d2f502314d945f0df267932375e21392764894Virustotal results 37.70%Heodo
2020-10-27CDL_100120_NEL_102720.docdoc 39b408479c9b71f2255dbb68b69c160ba53dde08fdcf127f2ca2598fefa640ebVirustotal results 36.67%Heodo
2020-10-27PO0643484004LY.docdoc 901b7928cfb286b90c7bd949481eeb663937cedfe0dc36b49fd069dd437717c3Virustotal results 34.92%Heodo
2020-10-27HTM_3864014570659978737729.docdoc fc6174141ba2cab4d8889d6e2597578251658388b14ee0c3dc62aaaf6a379df0n/aHeodo
2020-10-27PO_10272020EX.docdoc ece8580e8d356701d4a0c0c5d7d19cb4b5c08ad86d2d06ba58566f1a6c2aef0fVirustotal results 33.33%Heodo
2020-10-27Attachments_KC4523730134IQ.docdoc 63b071aca88485607c94bfbc6f4afaf604a04cf316431cc9375016c853cb363aVirustotal results 33.33%Heodo
2020-10-27Dat_04094661.docdoc 56c2cef0eede6803ac93b690989ddfe5728039f73ee3f2667128ff8812054a6an/aHeodo
2020-10-27Doc_PO_10272020EX.docdoc 9a25919303a6d0b1210df01ae35bc7d31040fb1463dc977b75c5f7f11170a42fVirustotal results 37.04%Heodo
2020-10-27Dat_XVP_100120_KCK_102720.docdoc d0b2630b796df661789e540ba6ca88de07b43f58bebf9f911c9985b4c4cdd0a0Virustotal results 34.43%Heodo
2020-10-27Rep_FH8956241649QI.docdoc 0806b4f4bc6745b9b67d121826f3f542a390abaea7666810393645f17136d396Virustotal results 33.33%Heodo
2020-10-27arc_779846428171.docdoc 5d4c60d9b990c131c7a7bfb79f8e1d1f7229e05ab56217a8d185b0b4494cd633n/aHeodo
2020-10-2770654129.docdoc cd1e0a22c855d17c145a7577ab2ade765735a6eb768de6b3445d724824388dcen/aHeodo
2020-10-27DAT_YEA_100120_NGF_102720.docdoc 1775a89c8013b60f9d0c4049675feb67fc007e0995b58d5a7b8221d7a4efaa37Virustotal results 32.79%Heodo
2020-10-27UNTITLED_9896445064.docdoc 7d2f13626cd91555d5f9cbdef3a3c17f832e03fc8dc38afb61822dfa3aa37649Virustotal results 31.75%Heodo
2020-10-27arc_3699814276592561836.docdoc 2e645bb4982ac3ce6f30a2fc5a13d0a55dfdbe4c11decc1a5dd1f9a3136390e4Virustotal results 35.85%Heodo
2020-10-27INF_33588605.docdoc 4d1c9d926e790dcba4a18230f0ef11f5550dccea472300ac8d5cedb064e6e573Virustotal results 32.26%Heodo
2020-10-27LIST_IPD_100120_CMB_102720.docdoc e39636db1ca1665b04dc3b74b7598403e6152847cc90bb4472aa13bc93e70b62n/aHeodo
2020-10-27mes_XG8499622330ME.docdoc 4d55ddffa3d513e115000683cfa2fb1e2b738298d58e3b6dfaa8f66feb1351dcn/aHeodo
2020-10-27Mes_20708714.docdoc 8f323b8ed745f486d1959a02ec0b57609d3461405014d5a1885ddb8f9d171118Virustotal results 32.26%Heodo
2020-10-27Inf_EV2683194969YC.docdoc 3d3018783ee56f8fe4b38d613ee7b96aa6424bdf12d3bd7c3dc618c6bb38dcdan/aHeodo
2020-10-27ILZPJMXJ.docdoc 115c98911b958fcf8e3c9300eca7763548205c8fade900f66be4d241ed54c99fVirustotal results 31.75%Heodo
2020-10-27INV_XP8128512051LU.docdoc e25c57f78caa61c0a27f7f7877e82bbd48ba6fc490aa904b851bbf4b7a42ac5bVirustotal results 31.75%Heodo
2020-10-27DOC_PO_10272020EX.docdoc cd0b23d03029fe913a9d2f52d14b0703f4a6f6a4cbda6744a455fca3373d3ca2Virustotal results 35.19%Heodo
2020-10-27REP_PO_10272020EX.docdoc 0bce545acd6f37453246cb2ce9c6ef9e85b7c6c02676fed1a2bfd42934be9c03Virustotal results 40.74%Heodo
2020-10-27FILE_20411539.docdoc a9670ebc9a9410fd8afc7de53381f501601ca3566f19e9177a79ba8a1b6b93e6Virustotal results 42.31%Heodo
2020-10-27LX2698440166BR.docdoc 86b0701737b73d1713cc04f83dd9e1d5d8dcee914c007cca4d5a6a1870f7b067Virustotal results 41.67%Heodo
2020-10-27BAL_38424122.docdoc 402bcaa8f052d8cf5d7ebef47283ea79c68151fa78bfad0611e97530423d3b73Virustotal results 41.27%Heodo
2020-10-27BAL_49082248037306693693905.docdoc dcac3f433bca625d1c831d29f00d254dcc6740ca1779ebf9f6483ab6fe431c21Virustotal results 40.98%Heodo
2020-10-27BAL_PO_10272020EX.docdoc 6f039a653dd4edef8c16347acc26f36a9b283bdeb9c8fb6ce48faabd9f67f5e2Virustotal results 51.67%Heodo
2020-10-27DOC_CB5833398127BV.docdoc 1b90906d6146b886c419f1c0529e6a929d80d41ff661e6c9a5dcf28f6062a9e0Virustotal results 51.85%Heodo
2020-10-27X_YB3930824994UB.docdoc 2015896f02bf0d7ea83f6b6c3e731cd5f4004677e58dd2a5f658a848cd1ff322Virustotal results 39.22%Heodo
2020-10-27FILE_SW6136324549SH.docdoc 4fb9d273bb087c7c0ff482f77af8b41047e57e10e452d9d4b873e89afcfb9624Virustotal results 38.89%Heodo
2020-10-2705806242.docdoc 56672b95281d04830b996e84df9edadf1be30650c9e410f25dd4596927d71d7bVirustotal results 39.62%Heodo
2020-10-27INV_ZDA_100120_RUX_102720.docdoc 44193d99f4f6240603cde0c68693a415a4ada0d769001572a4b84f503df3569eVirustotal results 42.59%Heodo
2020-10-27I_ZEXGH3U9V.docdoc 26086ff8825a2c550cc802f2574dd9a8730c972ed3d1c704d863fc74e8dc082cVirustotal results 38.89%Heodo
2020-10-2752919457.docdoc 5015b3d571a67fc015e9ae62b064f6a8357b86db998aa2fc1eafe6bfd053ee44Virustotal results 39.66%Heodo
2020-10-27DOC_VZN_100120_XTT_102720.docdoc 9c6f43dcc3bd1778ac7082fcd98251f2ebbc67b02f5d6e41ab97c2e8924a4e17Virustotal results 38.89%Heodo
2020-10-27P_62904342.docdoc e955daa4404b745ed6c72a2e99899af5ad6b133c5b24f5665d4649cdcff05fe2Virustotal results 38.89%Heodo
2020-10-27INV_81290085.docdoc 284ca49487afcbd5dc06144fd8a4b4ebaf8abc174a9c0c609a5073f4925ec19eVirustotal results 39.62%Heodo
2020-10-27BAL_61939492.docdoc 116159cae06790df3ca134b52e8a6ea44db0737400131f10067ed11842bedf92Virustotal results 37.74%Heodo
2020-10-27PA24ZMJ8K3ZFUVN5.docdoc 277c9a5a3210a4fa589ee6ad368ca72eb54f66de900e476082a8167f6b3ba55bVirustotal results 38.89%Heodo
2020-10-26PO_10272020EX.docdoc 99f4e6496067c7a7b9d8cd390470315cc63c4f3adb23c3d885b886f9d86786edVirustotal results 38.10% Heodo
2020-10-26REP_PO_10272020EX.docdoc 071e87ed49b3bac25514270814dd2f066a3a9255226b419bf6a25da73a8a07ebVirustotal results 40.00%Heodo
2020-10-2690990448.docdoc 7569ec933b0114593361c66c86f8317cdb131aece55945e0634987155a0d0ddeVirustotal results 37.10%Heodo
2020-10-26REP_8267235006089447433993.docdoc c8ec858c06478f6261eadea96e71a453f5176eb9b07c801ad5d84bde75ccda10Virustotal results 37.04% Heodo
2020-10-26FILE_B0VBN5RE.docdoc ced763c7a4e419e5fe3cc06d5ef0e01adfdbc0837028a48fef7f0d26db8566d4Virustotal results 37.04% Heodo
2020-10-26REP_73683661.docdoc c989f9fa249c44f5aa5e7beb1781d22d20154daae1750c5f321e00f739a742a9n/a Heodo
2020-10-26FILE_CR17Z8WUZ0UO5S6R.docdoc 58dd20d9c3e38a8115434572a1975f207290cb2340b203ffaa6d3b08fa95da9fVirustotal results 38.71%Heodo
2020-10-26BAL_PO_10272020EX.docdoc cc341e2451041bcd6d9dedc66abe480900021abc803788e2d56b701edee7e044n/aHeodo
2020-10-26FILE_5623370982.docdoc ee772f42c7448d3ac4ff12c2d97d108f98bf7594684a45f8b3632ceeb9744a70n/aHeodo
2020-10-26BAL_PO_10272020EX.docdoc 5a852301fc77705feb086249753d26f6b2b8cf5f8fedd64ef0fc246e842af909Virustotal results 40.32%Heodo
2020-10-26REP_WRJ_100120_VBE_102620.docdoc 4c22a2bdba84f5c8604dec8bb09846167e68b70dac6ec6b641a70fc41de2c1d5Virustotal results 39.62%Heodo
2020-10-26M_36479020714.docdoc f83783eda067f6e1b71d589e230f6aa844b2410c42ce2f20a60f9b32960852a6n/aHeodo
2020-10-26TS0089214834LD.docdoc e8caccd0e30b68aa3a338537f9164503821ec1089daf287db3acf97ec74e59f3Virustotal results 38.10%Heodo
2020-10-26J_8JF1WH2EXJ1P9IDU.docdoc ebfca25ac5a8d600e73ba0523100c430e2b6072247e42a91c12ba2e1d718c4f4n/aHeodo
2020-10-26INV_72927041.docdoc 98bdd88b97a27caa11e39dd7dee4d2e510ba8b38e1e7e13e5efb7ca2fd538679n/aHeodo
2020-10-26DOC_18075845.docdoc fc96bc46b69a1ec2ac6829d22a21628bae8d3b2f8b64e2d97ee087ccdce4de14Virustotal results 39.34%Heodo
2020-10-26R_94962790100857940917242.docdoc fad47e8ab42aab56d8198f885e7943c5b9f9c86bd8983e3ddd4dcaaae8c36f2cn/aHeodo
2020-10-26FILE_AY0124547050RM.docdoc 0ab03990f76631ea9155550ab1ce403dbcebc068697d78958d1e6fbb587c2639n/aHeodo
2020-10-26DOC_EH6XSAKSM1AAXR.docdoc 350f692b235ca80d3ca12562b2b358bf46423ddee94c82c3d2b510dc024f8925n/a Heodo
2020-10-26N_1078283505977602279316.docdoc b437989edf4f8d24be3eae161cc269bb040b2c9c8ee043f06ce2dcda6c8553d7n/a Heodo
2020-10-26TAI_100120_LHZ_102620.docdoc 5b2357476ae913debd4a8f8070c64177c73ae8d6791df39981393094316384c8Virustotal results 38.89%Heodo
2020-10-26CX2YD3QJEKFXIV.docdoc e529a4a29bd2eea46256907a9cd8c49dc7323451f15432d425ae0bdb0d1154a4n/a Heodo
2020-10-26DPU_100120_LZT_102620.docdoc b55a1feb8b061b47a19b6e7f2c2aae56995e52c78a8110006c35d5f1f98b6ce9Virustotal results 37.04%Heodo
2020-10-2612LA510DEY.docdoc 37f4dd3b5a31b3ba6764dafaab681ff67536907fc23b83939939f6c7c58ba82fn/a Heodo