URLhaus Database

You are currently viewing the URLhaus database entry for http://ahmadifoundation.com/wp-content/VbikDMHH91qaVvjurNtrPpR7QI7Oa3RmTCJkh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:758743
URL: http://ahmadifoundation.com/wp-content/VbikDMHH91qaVvjurNtrPpR7QI7Oa3RmTCJkh/
URL Status:Offline
Host: ahmadifoundation.com
Date added:2020-10-28 00:59:07 UTC
Last online:2020-11-05 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 01:00:13 UTC to abuse{at}godaddy[dot]com)
Takedown time:8 days, 13 hours, 48 minutes Bad (down since 2020-11-05 14:49:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28inf_1277110565227.docdoc b1de6df6c2b5ac15a030ee3b606165a808dd7fb78a4d22a267e304c2edad0fc1Virustotal results 28.57%Heodo
2020-10-28I_PO_10282020EX.docdoc 68cb170125b6d8fe85e4573f3324f27ca595e8a2a2f0d624742c817590b42765Virustotal results 29.51%Heodo
2020-10-28GTY_49324974.docdoc b10f4a4b46a88d8bd137cb2d76eb827b89f16acd953490d55b6161aa0e99b7aaVirustotal results 28.85%Heodo
2020-10-28file_98361787.docdoc ae95832fb60bc0562205f82b20e87746681b63fd589abc9312ca650f0cde8507Virustotal results 39.22%Heodo
2020-10-28MES_DHTD565V964HLZ9.docdoc 101fcc93c33f4a28332bd09291db3501b3d13ef433719cbf7750e9f6a73b88f2n/aHeodo
2020-10-28file_AMT_100120_FQK_102820.docdoc a74bd9bb59caf16dcb34bc909644f9b39712ff04e230af2fd8f4838af00e85f8Virustotal results 36.07%Heodo
2020-10-28rep_69313471.docdoc 0b62b154422aa927a6906a75fdc8edfd4c143365e4b5e4a8ffd58badd6fdb0d4Virustotal results 38.89%Heodo
2020-10-28DAT_VX3448854089HW.docdoc 2a46f3f595f2eea533b556a67f2558d85d955f1784d1d48cbe78b2e5fae35f34Virustotal results 28.57%Heodo
2020-10-28ZWJ_100120_WKI_102820.docdoc 1371c2d34a1e3ad727d60804b08ef021e7568a841acc95ce5cf1773149657ea7Virustotal results 29.03%Heodo
2020-10-28List_00378962.docdoc 3a183e3b2c742a3307c322a6e8e75c3741b4b35e456bacd95fead4ceb74fcf12Virustotal results 31.25%Heodo
2020-10-28inf_PO_10282020EX.docdoc 7f286766434b67cb7ea25119d469c086c70807bf665e8e373acb472ec284a72eVirustotal results 31.48%Heodo
2020-10-28INF_BVEXY0KPVWA.docdoc f3caca68ae462481d5bac777996fa838a0dce95c7eb782713404fa5e3712a2abVirustotal results 28.30%Heodo
2020-10-28X_PA6444953854IG.docdoc e774de558ab588e2aefc6661f8ddf20b6a02ef8a6e2c4504a0b03e27d9c19df3n/aHeodo
2020-10-28ARC_JKV_100120_BNW_102820.docdoc a9dab3a7ee17c4e9ebd90271c21ba1f27a69094147e4f37b14e8b584ef3bf74cn/aHeodo
2020-10-28REP_88498211.docdoc b7ee22f0341587e221b8a80c3caf8fe78b8d8ba06220d4cc28641f82d0d32bb0n/aHeodo
2020-10-28REP_5512882079.docdoc bc8c74e5b69ba384b49d43f30b6707c6982c97d843cbc3771fe0027cc844869fVirustotal results 25.00%Heodo
2020-10-28arc_NE0540827760TS.docdoc 09a4d7f3bbc95dc5b795441093b4f44943d384f0b9087a71ddaf1b55eda16ec6n/aHeodo
2020-10-28FILE_VG0576295703FD.docdoc 42437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17n/aHeodo
2020-10-28Arc_JYW_100120_FHV_102820.docdoc 2474770e88e989b790cd585fe0e234558dc6ce20bc8ddaf5a4e1f5c0733bc09dVirustotal results 22.22%Heodo
2020-10-28Attachment_3004166830612945261860.docdoc a30d2b343e3646a2a05e98c5b7f976a1f67e12574ecb880a2a460bec35735f6fVirustotal results 27.78%Heodo