URLhaus Database

You are currently viewing the URLhaus database entry for https://www.mautau.win/aspect-ratio-4dhao/840BPoJIZ601j9AZGJWDsZut5uX3UTIna5WceJV6ww1ZKIdYUpGTD0mo7Pot/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:956666
URL: https://www.mautau.win/aspect-ratio-4dhao/840BPoJIZ601j9AZGJWDsZut5uX3UTIna5WceJV6ww1ZKIdYUpGTD0mo7Pot/
URL Status:Offline
Host: www.mautau.win
Date added:2021-01-13 00:41:12 UTC
Last online:2021-01-16 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-13 00:42:16 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:3 days, 15 hours, 49 minutes Bad (down since 2021-01-16 16:31:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-13BXJ8VFNMMQ.docdoc 1b833b967a9b2dc29a4982addef8500c6480991a907be97fdccc799d21dd337bVirustotal results 33.87%Heodo
2021-01-13ZBZQ4JPIQH1FEEW.docdoc ed1d3d3103290456664d1042c875c1faef705150c5c1cb9c49bcd418dbe22160Virustotal results 26.98%Heodo
2021-01-13VLL9KU.docdoc a4b2c79223d87bc6523817efc6ae96ddb3a517b509a0907f5aa47ed93cf1bd78Virustotal results 26.98%Heodo
2021-01-13AWDDHW.docdoc c3b7ff21320580568f7e1b978e5374ccb1a15fe34c35f94eb2463c1570faf385Virustotal results 24.00%Heodo
2021-01-13ET6KLKG.docdoc 274ec03dc6e83bf12177697052207e2413c15948b42bb11df4a4ee110eb84803Virustotal results 26.98%Heodo
2021-01-13Z9IB4OCN4SYP5V.docdoc 3d0f797849969d919b2a23e7c8b525550fb34076e60df60ab4e380fff6c8f9f4n/aHeodo
2021-01-13BKFSNBA0WI9WY.docdoc 6519108ab0d32b865e06f74784831341df7a5c7a0f02221511a5a13b8762e375Virustotal results 25.45%Heodo
2021-01-13ZRO83XKBATY3.docdoc 02a4f728e72a9b3f8acbdfdce4bb3390cdbd32fd2a8ff9d4294afbfeb8ef65e6Virustotal results 24.19%Heodo
2021-01-13PLNCVTX.docdoc d2232dfab1a3d97b00285d3baeedaff80ee090c7fb8bec50f6fb23554fc7d4aan/aHeodo
2021-01-13GF35YHN4NT340QE1.docdoc d77e78f619d681603f2d2c3ecc803419724067121e18623302a4155a0efba1fbVirustotal results 22.95%Heodo
2021-01-13AQKUIHO9FVB.docdoc 5cc80cc17bbb89808db987af2bbfbe02975c1d67cfb77ac0a9a5af0468a36210n/aHeodo
2021-01-13HQFCBXXHHF.docdoc d93333dbffefb763131024dffc1c0723d897a65c7b8d2701f5fa5bc9498ae89fVirustotal results 23.81%Heodo
2021-01-13JJOQ26DT9Y8ZQ26.docdoc 57ccab2fc1f81d4b18e810f2b5d3f0834274c59f9a6d53cb4af3eb81768cd5b8n/aHeodo