URLhaus Database

You are currently viewing the URLhaus database entry for http://spearllc.com/_dsn/h54alb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:18105
URL: http://spearllc.com/_dsn/h54alb/
URL Status:Offline
Host: spearllc.com
Date added:2018-06-12 13:34:07 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-06-12 13:35:31 UTC to abuse{at}godaddy[dot]com)
Tags:emotet link heodo link payload

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-1307687.exeexe d0b044a1c563f2211941bf4aa2cd31804e34ff26f4500fd9dc35c7024522064dVirustotal results 10.29% 
2018-06-135805.exeexe dd0478177da7f8fba7e07f8b801d6070746cf33c0e908f591313d50173976d86Virustotal results 13.24% 
2018-06-137889.exeexe 20ebd21a9fa73dfa8e6ecfd806acf1a47b65069015ec8eb62aabd118f4fef133Virustotal results 23.53% Heodo
2018-06-131957.exeexe bc6d7a37ccc4c90a43296b0b5c7a70cb35bfbffaada6af024470afd998a894b7Virustotal results 22.06% Heodo
2018-06-135237.exeexe e8e2a9d63f14e6665b2ae0800958b6ea82240a140fa8372c8fd383bda6ecd223n/a Heodo
2018-06-1369380.exeexe 42897c7eeccd7ddb30c3315cb1590c29913031fd1a8f51a99b8cd8e080ee85b3Virustotal results 26.47% Heodo
2018-06-1319318.exeexe 7792a08c1cc7194ac83f8610e1a6d7f08a85a848cecb20d23ac14fd8bcea1078Virustotal results 25.00% Heodo
2018-06-138347.exeexe b76030b46dcf58cf550d989ecf5e6cf4ee38501a49a35fa4ab733eb04e0e3f57n/a Heodo
2018-06-133958.exeexe eda09f5de86d1faacef0f932200ed39d6aa2f8771939268e1b653bb7170c0749Virustotal results 23.53% Heodo
2018-06-134420.exeexe 5789dc19ecf21dcd96a72497ec9a384d52dd010b4cb9cee04c0c2062ac09fa66n/a Heodo
2018-06-1314239.exeexe 6774210237275d00e197c23a867d6d07e1b27909c3bbeb2efa5550a94486dee7Virustotal results 22.06% Heodo
2018-06-134568.exeexe 26d5725f7b9028b03df9cd6bbbb08fbbb78d909d5f8f3b6fe923285dce6a25b0n/a Heodo
2018-06-138407.exeexe 32f68f3984d3cfc94e777422ce214c62a6f4785d2e4fda2ffc76262cbbd0a90cVirustotal results 22.39% Heodo
2018-06-1313229.exeexe aea946c7340536eca6efeda0a141af8f332585877c29bb0fcb6985d42f239ceaVirustotal results 22.39% Heodo
2018-06-139538.exeexe f3224259ff8945620e9044ed6fffa77802d14bc17f4664aa8a5fb4381d018320Virustotal results 19.40% Heodo
2018-06-1260358.exeexe ece2a89aa4bdb318370bc75458d7d790791d7b46287888d40b555e3b7726b228Virustotal results 13.64% Heodo
2018-06-125612.exeexe 91d0f65b0e9f62ccb7817030967cde51c8f4806a8acec6deabec39c7d8adb416Virustotal results 22.39% Heodo
2018-06-1253013.exeexe ebe4ed8c191c7c09e706d9409b49f559fb8ab85ecf4966963c7f1a434e54e99dVirustotal results 22.06% Heodo
2018-06-1222447.exeexe 8e6abdbee16746ed9871ae0a6717d207d1554b4ff9f86e5e53131438670fa702Virustotal results 20.90% Heodo
2018-06-1240076.exeexe efd5ac975d25e7809b72f3e6266aa8a2024b14200ad2278a48fcd3bfcd222c8aVirustotal results 29.41% Heodo