URLhaus Database

You are currently viewing the URLhaus database entry for http://cabinet-lgp.com/wp-content/secure.accounts.docs.biz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:169759
URL: http://cabinet-lgp.com/wp-content/secure.accounts.docs.biz/
URL Status:Offline
Host: cabinet-lgp.com
Date added:2019-04-01 19:04:06 UTC
Last online:2019-04-02 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-01 19:06:05 UTC to abuse{at}lws[dot]fr)
Takedown time:11 hours, 44 minutes Good (down since 2019-04-02 06:50:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-02NEW_INVOICE_201904_S4_5-12_030714.docdoc 5fa78da23a8e6295dde375c04b387d3013f840ec1bf02c507843fc28e8c3195aVirustotal results 18.64% Heodo
2019-04-02invoice_number-U5_73-14_66962894.docdoc 2cea5a5983f18cbb457cade99d38f735fc9ef0aeab6b7b6a3b33a031cde2bc93Virustotal results 19.67% Heodo
2019-04-02last_invoice-201904_P7_0-55_2912118.docdoc 787bf83389affc931752a1cb3686ce6aeb487e2cd32e06fa70b7c7c705e31451n/a Heodo
2019-04-02INVOICE_DOC_Y0_41-57_26510318.docdoc af994fb8c890ae1a9fb714ca0d3ad09316a83f3a08631571f966eae70576fb39Virustotal results 17.86% Heodo
2019-04-01201904_D2_82-00_474378.docdoc e2571ae759e2f01f73324af0c4fb41a3707176791c9a3c8835468b46129402c4n/a Heodo
2019-04-01OPEN_INVOICE_B6_3-65_8248632.docdoc 8c51449760f329e638238d652539d53b08c1635cb372fe9c48a8fdcd6ec06305n/a Heodo
2019-04-01NEW_INVOICE_04_2019_R4_2-56_72957.docdoc 806e979745b7c1ba89de060b6fe0b2b07b9841ffdc4944f389cb484309061098Virustotal results 21.43% Heodo
2019-04-01inv_num-V8_1-30_26649357.docdoc 74c0f86ac4b0bec02518a4727d2d45286e5660a0df01c9395eabc30b89019968Virustotal results 19.67% Heodo
2019-04-01invoice_number-H3_29-88_3383051.docdoc 00fb192e814c1ad08d7dadeb2d254e34d89ddfeaf0fde918b485aa356fc2c4d0Virustotal results 18.33% Heodo
2019-04-01last_invoice-201904_U5_5-28_623393.docdoc ee6ae2adf55bd6c8729ffe4e60dc203f4feccdae203b37ef1af5f732249304d8Virustotal results 17.24% Heodo
2019-04-01NEWFILE_201904_V9_4-91_04005654.docdoc 642462fa935f38c809ee0c544a7866a9ff4dbe4d7bda81be5a3169a7615bd9b2n/a Heodo
2019-04-01NEW_INVOICE_04_2019_E2_2-77_390136.docdoc a391a27ffa57871274520e1c74827cdb883b42c9d1393c0b44716d87f071744bVirustotal results 17.54% Heodo
2019-04-01NEWFILE_M0_74-84_8363590.docdoc 2f5c1624fca182c1abd767020cf77ba959093f8fd76b2414dc90b716ef29ae1dVirustotal results 18.33% Heodo
2019-04-01UNTITLED_FILE_Q7_3-30_8438342.docdoc 1b0d32e3bcc174deebd7f242ec79c6e779ea8d5f2625b819764ba7f93d221990Virustotal results 18.97% Heodo
2019-04-01last_invoice-K4_35-40_4427787.docdoc 0e6b0f6b9a10ba48c279a16ecb646ca4b82a3d4c5c96e00a5b6d691347b69c6aVirustotal results 16.67% Heodo