URLhaus Database

You are currently viewing the URLhaus database entry for https://ahmadifoundation.com/wp-content/MSd0YF4oA3qdiarDG6zwA7eB3B9FWpWaph1Yoyqz4gVh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:760497
URL: https://ahmadifoundation.com/wp-content/MSd0YF4oA3qdiarDG6zwA7eB3B9FWpWaph1Yoyqz4gVh/
URL Status:Offline
Host: ahmadifoundation.com
Date added:2020-10-28 11:00:08 UTC
Last online:2020-11-05 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 11:02:07 UTC to abuse{at}godaddy[dot]com)
Takedown time:8 days, 2 hours, 50 minutes Bad (down since 2020-11-05 13:52:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30Rep_WWZ_100120_MLP_103020.docdoc f4983c5881da987bb4dcca9069e0134657dbd559cf50165c0f35c3f1c4595948Virustotal results 40.62%Heodo
2020-10-30DAT_52732114089514.docdoc fbe079c5cd46bcc371fedd49df3189de10406984e2882c76b08947941f1726fdVirustotal results 40.62%Heodo
2020-10-30Mes_YI4104008299YK.docdoc a120ab7f12256c4b260034ecf26910f2eb405bb2c41ea9d1d78fcd2f529d2debVirustotal results 36.54%Heodo
2020-10-30MES_LYRLBQEGNWTU1.docdoc 3416748dde8336e8081847df55d2ef61d1081a8bd9d76faa5922683231da8c94Virustotal results 40.98%Heodo
2020-10-30rep_96133013438517.docdoc 2a2cd3fa6ea3c1207553da6896b030a743a3893ec1b95b494ba27d6423f8857dn/aHeodo
2020-10-30mes_55S4BDVDTD5HE5M.docdoc 78896f92d061592d98c06fc87245d2cf4074475faf24d2470912e785760c29b3n/aHeodo
2020-10-30File_PLM_100120_FIK_103020.docdoc c5464029a0c6ac085492b9e9e1380d0304bd195c8de6e1dd71b51d4c9f8a5433Virustotal results 42.19%Heodo
2020-10-30Arc_35984564690.docdoc aa221230a7342817478b117f2ed838ceb8290bb367bea08770c362b14c2fdcbbVirustotal results 39.68%Heodo
2020-10-30rep_180121019.docdoc 4cd342f5baeddb3b9ce82b0f360ee43411ce30c8abede6b1f2a8181ed08da110Virustotal results 39.68%Heodo
2020-10-30Mes_NJ9024J8.docdoc 0b7f26dc76b83127cdf687f818e652f050a9b3726aa76bc30947f94e4e25ffd4Virustotal results 40.62%Heodo
2020-10-30dat_12963143071106.docdoc 8f71742d1582c153a4011a49f8bf5ab9fe4129b6937832fba73d68bc0e95a438Virustotal results 35.94%Heodo
2020-10-30UNTITLED_GNP_100120_PXZ_103020.docdoc b2f80aa2efc9abdf137f78f830f2366b29e5bba74409138f8db1ed6163e25819Virustotal results 35.94%Heodo
2020-10-30Mes_UMI_100120_MIY_103020.docdoc a51d194ff7cccab7defe2f64127934a4ff3699de37c60019b40dd62d631baf04Virustotal results 35.48%Heodo
2020-10-30Attachment_GZY_100120_RNK_103020.docdoc 2fe61550011a52e12cb324aa8cd06faeece3d1f05ae42f1c51bb7e055a647877Virustotal results 31.75%Heodo
2020-10-30L_PO_10302020EX.docdoc c0f5989eb238c0d187f0a5341698ac293ee524d1132278aaff5ab4144a4b91a2n/aHeodo
2020-10-30Inf_PO_10302020EX.docdoc c2d7ed25c4c34f44dc293833d3ea302d281d24981385c437e411a50ede35e72bVirustotal results 30.16%Heodo
2020-10-30inf_49611905.docdoc 1e2927648e6c1e230ea519611dc8ffc414549f3da0fbe74854b2b2431a5731aeVirustotal results 29.03%Heodo
2020-10-30FILE_711276593691686.docdoc 2bd445000ef12b82a7dbb15a89578a71ad17a82cf8b2f19239fa60afb2ba84f3Virustotal results 26.56%Heodo
2020-10-29U_99156701513697.docdoc a692ebd8ffaf553afe6a7e4b21ec46977dfc073877399130d26bcb1aac0ec33en/aHeodo
2020-10-29Mes_35255092120663989997106.docdoc 979cfc195db76bdcbddcabb8651ef3892b61790b4802159e1fe31edd08d0e7adVirustotal results 26.98% 
2020-10-29FILE_PO_10302020EX.docdoc f4d2f6dbbb53d79cccef95feda58515350e863a1f1522bf60c830c0230754866n/aHeodo
2020-10-29List_73956511.docdoc 77b9310b55e2267372f1458cc4c01a27f95067e8d1dad41137ee348a9dccaa32Virustotal results 28.12%Heodo
2020-10-29File_OZY13XIAQSUIEW.docdoc 168c46a9b7c3c72ceb572a447f6317e5b66aca4735ea8e096bc92f0d03628879Virustotal results 34.92%Heodo
2020-10-29Inf_EACBC8S039Z.docdoc d28ab268249104b8e40b88f99670cb44f0cc8c440b22b983193c4e6fa4e0ea95Virustotal results 26.56%Heodo
2020-10-29File_PO_10302020EX.docdoc e5ee1bc6b5f6544f1d789848862c6469f2f32c20627bb4e410a1bc21f0005817Virustotal results 33.33% 
2020-10-29List_FXL_100120_DSD_102920.docdoc 41439f935c27535a7752ad0b7a778de41fa076af62cee2bf3ce8138567fd7060Virustotal results 34.38%Heodo
2020-10-29REP_R4X2CEAZV6NATH.docdoc 1d0a436d11e82575e2d3159ad264e3a58bb3caa9f6638ee4b8a94a5373219628Virustotal results 35.48%Heodo
2020-10-29dat_9534629046270452.docdoc 37906d0ff927695b534899703a92007c2472c7dd1fb8a90e03dc6050bacbe3a2Virustotal results 31.25%Heodo
2020-10-29dat_97234701.docdoc 98a507399c617fc492438aae1e2f0f8c2f01dbb954b3055846dfc5c48e84c7eaVirustotal results 29.69%Heodo
2020-10-29FILE_PO_10292020EX.docdoc d51925f43c610d0116c831c9282a4b3fcbca83fce4a02bde7f425d81eb7a2243Virustotal results 31.25%Heodo
2020-10-29GP_PO_10292020EX.docdoc c9bee872802f41154444cf83a87057e1caa72888e8b2c3901933201b9aa6312an/aHeodo
2020-10-29FILE_835728746660336.docdoc c9c1857a6ae5a7ee50f6b0df9af96ab1f60e60df0bcc86caf0c561838b4eb20bVirustotal results 31.25%Heodo
2020-10-29rep_8484930191425.docdoc 1cfbaf38e833a8dcab12a6f7a0c42e5b5033bc4f188f022607c0e3853f92a6eeVirustotal results 31.75%Heodo
2020-10-29Mes_Z18HGSXI2.docdoc 26116918df27572814521839a1d3ffdb544bc825e81c871aa514890cc6411d44Virustotal results 29.69%Heodo
2020-10-29ARC_VQ9870016679TC.docdoc de9ebc94403f8ac175dbfb0a01cfd6e37753309402f94fbe7cd71755ab5d8051Virustotal results 29.03%Heodo
2020-10-29file_HJQ_100120_VSD_102920.docdoc cc18834ee43070da990675aa77ca54b1f00e3af5bb607464447c3ebdcd2cb356n/aHeodo
2020-10-29DOC_UGU_100120_USR_102920.docdoc 541fe3cb96d86e7e7acac38913e1f12a0006bb4e07269700b8878279ecb8df5cVirustotal results 25.00%Heodo
2020-10-29UNTITLED_QSV_100120_VKR_102920.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29DAT_WFT_100120_MHG_102920.docdoc 49a477c47d332f275cc0c14abbd81bb687b943da8481d37220f1191d429061a5Virustotal results 28.57%Heodo
2020-10-29Untitled_2607213075392359130388229.docdoc a3aba18f164b5c210ef16ea9fb2afaa20707a268cb84c43518dae121b7518614Virustotal results 28.12%Heodo
2020-10-29INF_68989639.docdoc 29808c9db3a80e9ed46d4aecbe478dd8e57089d7e2977c916421cba71b0d6c42Virustotal results 26.56%Heodo
2020-10-29Untitled_HESV4CIPUCEV.docdoc 5db58ed4308eeb76f9c66c885d4f1b53530d6c42eac9d755e67bf41989094087n/a Heodo
2020-10-29Untitled_37281402624935205039349.docdoc e134359bfa4a04bffabf20a6522d2a4c8d807619578853ba0387aa395b6495c9Virustotal results 26.23%Heodo
2020-10-29MES_05747225718.docdoc c77bdf30a9a94eafd3718a954bd79a8e9ad3b32761d6c45ae1b79245df7599bfVirustotal results 21.88%Heodo
2020-10-29list_PO_10292020EX.docdoc 3dda8251733c1b96b75d29bcbe3466add36d495368b4b44232fae1dba4a4cec6Virustotal results 20.63%Heodo
2020-10-29REP_PU2408096999GH.docdoc ae454b06f63308de7e1a613281feea2eef089041c67af45e72ceec804482b526Virustotal results 20.31%Heodo
2020-10-29FILE_05733139.docdoc 4a364de81c8e1064d68390dd954375aeadf021b771249cea59881e7e0fcc3156n/aHeodo
2020-10-29H_GV3543418016TM.docdoc 3a1dd7ec119b96ea68facb223082a398ff4c038e58e7d166c80d7a7d4a3758abVirustotal results 20.97%Heodo
2020-10-29REP_0178006416774.docdoc 6b696b987488f5f9abee78f4d38565535d928adb645de9f48e95a99914bc5dc8n/aHeodo
2020-10-29DOC_96705314.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119Virustotal results 20.63%Heodo
2020-10-29dat_92347885.docdoc 5a00d4a9d8e50c06f30007460af1dc4f73950dff8ef4d1966ec4098c16712bf0Virustotal results 42.86%Heodo
2020-10-29Dat_94302540.docdoc 38df7a8d7d8ddeec4905b01777148222f208d5030b7a44665b5fdafb5bd9ff19Virustotal results 40.32%Heodo
2020-10-29Attachment_16175363.docdoc a94691d74d543c82cfb7a293d0de416bec72dbaa2a2776d2ffa9b176b28cc12aVirustotal results 42.62%Heodo
2020-10-29DAT_PO_10292020EX.docdoc 48f5efeee13fcdbe837223ddd4c1de97dd87be397e6f99bb95ebfd19af5aaf86n/aHeodo
2020-10-29file_NCF_100120_PXT_102920.docdoc b89f35d5cf8a6c4366983f91cf345888e2142d20af960d0125778cfe40d307a7Virustotal results 40.32%Heodo
2020-10-29Untitled_HU9658813481XI.docdoc 63df7914667bd2adc0b6e4b2db5b67f07a6154956568765321641b6dc1469cf5n/aHeodo
2020-10-29Rep_811419957608758281444406.docdoc 8d2d6adef59a01ef18694e5a3d506ce951137f27e28405c64bb16fbb915266d2n/aHeodo
2020-10-29Attachments_64548954.docdoc 4a64cdcef15cb3314d81486a5c6c1fc590e6579da756365b73c08c8adae77b95n/aHeodo
2020-10-29DAT_WTH_100120_DTL_102920.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 43.40%Heodo
2020-10-29List_08880785.docdoc 4c8eeccd2a16f80874acd0057d5ec622d3701e32a3198bdb763f39e39ea28982Virustotal results 38.10%Heodo
2020-10-29DAT_W10ANL1X7AZXALC.docdoc d41fde459d5a6605355b1daac05e7fe5ed46f2f70d564951027067566a049475n/aHeodo
2020-10-29Inf_UJ4147378963FM.docdoc 665ea7994646d6f55327063f07c46e3d51cce78766dc14fc03031b5581283b10Virustotal results 38.10%Heodo
2020-10-29Attachment_PO_10292020EX.docdoc 9f2ed62dea3b679b6dfecbb79905a34ef056e81af2e92c4249fe4521711b047fn/aHeodo
2020-10-29File_SE2536269685HU.docdoc ab7a59b346e75d68ff9a689f85a0d2a96833a3048478fab68af1e8f1bd4d5905Virustotal results 36.51%Heodo
2020-10-29Attachment_55274774.docdoc 56b4b239b93d5528e7f80a5bddef47bcbe22a9318d3abf88be53dbb4aedd66ceVirustotal results 35.48%Heodo
2020-10-28Inf_02135523.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28MES_GLU_100120_UXL_102920.docdoc b693171616c84c6e6bf6f7a486ac2efef18cab45a608593d95def463549f2f74Virustotal results 25.40%Heodo
2020-10-28J_C65GABO428R.docdoc 6e663577a7ba709bc7fb008addc85b8177361cb8fe92f3c79ab88bcecd10783aVirustotal results 24.59%Heodo
2020-10-28MJJ_YR6508166821EI.docdoc eb056d51f99a6aeefbd8db271b24784e988b456f939812f40b9b6108a4805941Virustotal results 22.58%Heodo
2020-10-28Mes_PO_10282020EX.docdoc 88ecbebf3f50eca1713851898cb315638b520a2c46f5d21f370de5ac8a4de484n/aHeodo
2020-10-28Doc_13377927.docdoc aa5e7414db596bbbac651408e85b19557a2415a2e42a4a2689cf37c1f3dc1c10Virustotal results 22.95%Heodo
2020-10-28Attachments_RMXSKD6SOF.docdoc f25bd084ce8d81cd2533601965f19c49105798af5fa7465757626b6cd057dd61n/aHeodo
2020-10-28File_PO_10282020EX.docdoc eae43aeb02650178d0fd02ed1c824f36d89c2a2950399621c4a7c29ecb8d7e73n/aHeodo
2020-10-28dat_TVK_100120_LFZ_102820.docdoc ad112b9ed4b1078a7142b24121c402ec49a036e33bf0e514f8bdc5b720c216deVirustotal results 17.46%Heodo
2020-10-28mes_Y2TT3WU6.docdoc 548e2dd3c73fb009710071b48a2afd21140eb1328ad31397857707060efc61a3n/aHeodo
2020-10-28P_EZ7340203385KV.docdoc 54a04ad4747b88954b6501afd0c033a819bfd9e67df5354ed77031d04e8e23bcn/aHeodo
2020-10-28arc_30393562200435.docdoc 3e40a7defd105440e12f2955234fba81780b20f1dbc188417b1381f6738ab15fn/aHeodo
2020-10-28rep_633111519083470682507.docdoc 7d38c4d98d05cd3a7a0fc6898c9d86ef1c29cd8dcfa3403d0222ff508843a325n/aHeodo
2020-10-28Y_2CMC6U14DXTLU2P.docdoc a1d186d5fb1e72178aeec7001aa59b78764e0c5405470905e737baf9cec89c26Virustotal results 17.74%Heodo
2020-10-28dat_PO_10282020EX.docdoc a3f1465cf2e8a92e8d9f932ab8d561cd6a02e5f832b42bfa856a5cac7fb96566n/aHeodo
2020-10-28INF_MZF_100120_ZOK_102820.docdoc aa825d666a2394dad05c014830cd132ecdbabfe1dcfd7e7eba18ed43bda6de33Virustotal results 17.46%Heodo
2020-10-28Arc_52807734.docdoc 7eeb30a34016ac7c6d48178f44b12c48df17acb131f0a96847d1cd67c464ce30n/aHeodo
2020-10-28Arc_846C7WBQ.docdoc 1d9d2d513d2906aa7b8400819aece2cd5e80976226792618b60a507a2daa906bn/aHeodo
2020-10-28Arc_F33OBAE1A2C.docdoc a7c464eeb2745a70c0108df133c47695689e8205a9b36343bf6652b953700739n/aHeodo
2020-10-28Rep_ALT_100120_DWF_102820.docdoc 95dbd21a4a3f7bfb45ed46713d99b7881129368a675677e970e647b22cde6d05n/aHeodo
2020-10-28doc_2910711358.docdoc 92a3589e1b3fd70341f8bf112b36413666415cdd61c4c49564ec228ef12fb723Virustotal results 19.05%Heodo
2020-10-28doc_RVZ_100120_GJT_102820.docdoc d137ecd544d81788f995e57831d42f753cb8010032c9983800aa8fb52799f2f7n/aHeodo
2020-10-28INF_5395835193055622024.docdoc ae264639594117f77da175c96741827cc7ecee91be8eeb65c10f207c26a2e800Virustotal results 17.46%Heodo
2020-10-28UNTITLED_76772301.docdoc f6534e33c00179aff63a48e6ebadc4d2bc15c3203361b67264ce1894ff12517dn/aHeodo
2020-10-28Attachments_UK9863465223UK.docdoc 19c244f40868914450fb2bccb57e67ab4fb5679b222017b8c0dfd53dc1980334Virustotal results 17.46%Heodo
2020-10-28Inf_N7ZQRFN.docdoc d424fcc461427fd257e6bd50b98d81df0efc3254426388661e5ec4d9a4815fe4n/aHeodo
2020-10-28YGU_100120_XZD_102820.docdoc 1133a03122cec0b03c3cf2b52c1b1737d103ec16050bc4deeb5914bd339a4900n/aHeodo
2020-10-28Doc_PO_10282020EX.docdoc 4c8c238793080292318a1698f8e3bb506d63d0e1335171fb6ba9ce1369c5daeen/aHeodo
2020-10-28file_71810879.docdoc 320e1d251976122a8a99eb8cea6215aff119aaa931d99ff58c30e220a062044fn/aHeodo
2020-10-28Arc_77316493.docdoc 3f02da0066fc5957eca4a61f1f5e7a8c53804190c4709ae8fe273eb6508561b8n/aHeodo
2020-10-28ARC_30139869.docdoc 362dc59ca77c1bafa2f6ac163566994c9a8fed193b5285b3eff678bf8588eab1n/aHeodo