URLhaus Database

You are currently viewing the URLhaus database entry for http://l7.net/portfolio/PM-45840/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1971828
URL: http://l7.net/portfolio/PM-45840/?i=1
URL Status:Offline
Host: l7.net
Date added:2022-01-12 21:14:04 UTC
Last online:2022-01-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-12 21:15:09 UTC to abuse{at}liquidweb[dot]com)
Takedown time:1 day, 14 hours, 27 minutes Poor (down since 2022-01-14 11:42:27 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-13T-257.xlsmxlsm 965ba65b5f61878b8ae10148e82de812b432f517f3d45802be713ea45aefd0c9n/a Heodo
2022-01-13828795649158.xlsmxlsm 7b6f6a4bbc69ade611b991ec40d097b4b37590aa12be7376228f7a7a3b13220dn/a Heodo
2022-01-135262572187434.xlsmxlsm b76e18e3aa77d8a35159a5b34f93940a933d206ef27896c6abca13c2686d24abn/a Heodo
2022-01-13667_0369.xlsmxlsm 3ccc385404055d349d08f8743232053863df38651ccac0bc96a0935598a00c1an/a Heodo
2022-01-1349879674_239.xlsmxlsm accddc7c06e08cf3517f7277a5c299c85176cd7821220fcbc6681c3dfba5be01Virustotal results 30.16% Heodo
2022-01-13673564852_7.xlsmxlsm 05329907bc087ee86b8ae6bda563613a6891d861b5e7eceaacd742a96de38c7fn/a 
2022-01-13KM_012285.xlsmxlsm ec995f8d459c0874c745d8677b81fddc202d0f1588488797bd81654f025a037cn/a Heodo
2022-01-1396737460_15.xlsmxlsm b4fb2c694f76e85c361b9c285f67b7a5a15074919db0b9eb2d55521390eedbc3n/a 
2022-01-139935-75518587.xlsmxlsm 43b4a4ded4844dc3840f383b8b10f7c9691f0044e5cf6a24681fdd62927988acn/a 
2022-01-13TVII_1697281.xlsmxlsm e2053410b37647f1f7e190f99174fbe37bf5833edbc9801319f4443e1478eb7cn/a Heodo
2022-01-13GR-335.xlsmxlsm 6aba2f1108a54a6e94dddf1fd12bc6f4b8b8a6d083fc5481e8ad35dc9b20b192n/a Heodo
2022-01-13Q_23958.xlsmxlsm aa95f57035882d90669b43af7c454c22d91f4e3c0525a83fcc6a0138d12d2a8bn/a Heodo
2022-01-134151-92.xlsmxlsm 78dd5816d66701839612b5caf64d4337e45d516e52b5f177345f5019ce4aa907n/a Heodo
2022-01-1301JXE-00987.xlsmxlsm e07efb44e73f01e1cd957c1874bce0e453c91eaa561f46efb373edb97100320an/a Heodo
2022-01-137048672_873.xlsmxlsm 4f9ce5c9c9dd88a6a01a3df3299e0aa43da3bad195036c22b141f28769708334n/a 
2022-01-13D-2.xlsmxlsm a8b105b33e639fbfaf784868e4c8b14639d7e0dfbde96bb5071fa8d7160595fen/a Heodo
2022-01-13DHF63027489.xlsmxlsm c87454534ee25d7d677e5bab46857f861240685ce17532b788892d370096be83Virustotal results 30.16% Heodo
2022-01-13e7.xlsmxlsm 1070ee81825904e9b69247d5ecd09aa91e0be9722ff1b627740e98e0bd48ee7fn/a Heodo
2022-01-136719671556058823.xlsmxlsm 4c2cf1d0796d8ac276ad283bbb14986b510a2a3b33e76005c8968b653d43d844n/a Heodo
2022-01-1368242719_3.xlsmxlsm 08c7c9f40c6db283966c794771c90b7d9f65dedfb785b861e02187f62f0dc0c8Virustotal results 32.26% Heodo
2022-01-13fwb-113.xlsmxlsm 4624a6c75a73e206d26cf23225ddf8c14c9bd3fac85edc04aebf63a281aa8bd4n/a Heodo
2022-01-13528420_87407380.xlsmxlsm 399fd8ce9218a6b24bbf3c9e307934df9b2954d45119371365be1360c88ec6f5n/a Heodo
2022-01-13HQ_0086.xlsmxlsm 8b97c32b643fd911fc305bdb62b94e1b34bf97ba87335b1f81cabe2bbf250d24Virustotal results 27.87% Heodo
2022-01-13tkpak_37986.xlsmxlsm b3a8073712469f70329fad465825f867bd6dcf83420de3004730f91ecc938138n/a Heodo
2022-01-13N_4085.xlsmxlsm 125468fda9c224d8a3ccdf92f08037a343c0341a8e64dc2c1182e1d3d4e496a7n/a Heodo
2022-01-1384899021-7895358.xlsmxlsm 0c23040b2cdf922d16cfc8d568d6a8fae67ea86e7de5268d0aad58d9a592946eVirustotal results 25.40% Heodo
2022-01-13040704-07188235.xlsmxlsm 13f975538e7e72ac755218c6a35604d36e0278e74fed8e2270476b89268a7f2cVirustotal results 23.33% Heodo
2022-01-13D298023906.xlsmxlsm 9e443aedd2833d67bb9b858bd14abc6a235186f865e05497ac39ab8cd0185156n/a Heodo
2022-01-13979998827_2686732.xlsmxlsm d47dc5f481df3ec15f19e8625c29b0beaf33c401b23191b818c9ecf885e3c8dcn/a Heodo
2022-01-1376866SGHWYIJ_7452714.xlsmxlsm 2b8b0ca757e3eccb527d9ce11a9a8815f5a9ce3c6d2ed5a8711d4c109e88bd71Virustotal results 22.22% Heodo
2022-01-135212675-49.xlsmxlsm 1d8482afdb97aba866fc26b21eaa9f92f46ea841566bb0588150aecd4347cd45n/a Heodo
2022-01-13z-5416495.xlsmxlsm ae4c37f20738b2bc766ca1b1437dd27be15c5a86e663f8ce3fc8be6762483305n/a Heodo
2022-01-1364426531_0.xlsmxlsm 2cfe6cc60d786a8b94d9d3114d344fb74c21e5ce5391dea3d1550df17fee05b4n/a Heodo
2022-01-134956874.xlsmxlsm 80f7072eb1b894cec06813c3267356f693ff21d0d1f116d1cf53d5b8035277deVirustotal results 16.13% Heodo
2022-01-13kXOm_876.xlsmxlsm 7fc994decafbc81cd090c28c1de605c93e2ae18f645faac2d1f6680b85ef7c13Virustotal results 14.29% Heodo
2022-01-1381691WSVEI_018489.xlsmxlsm 27142990970a1968021bca00b4005ef206e3a553179b2e717e82ebfe8a8af1b9n/a Heodo
2022-01-13GPPOJ_29480447.xlsmxlsm 8e8824a855908e301cb873fe67e37eb4af99b32f75fb1ea8997af913540ece02Virustotal results 17.46% Heodo
2022-01-13143598-38420.xlsmxlsm 7116287ff5fc3e837e06fb2ea4d6a131127ceecf8ef165f088114fdc8aa9e17bn/a Heodo
2022-01-1385931892_8138.xlsmxlsm 18c55721fbff7b023ffab344abd151b7627bcdac0645f7074a1ad6b311828779Virustotal results 8.33%Heodo
2022-01-1326400_10.xlsmxlsm e19c4cdeb5c2e9417e8976342dcf2494d337be7e4f6be1f465e9eacf998a6d5dn/aHeodo
2022-01-131645076609664.xlsmxlsm 38e984900acb5a6830c8ea2b34c0b1b85c45b32848da185c5bd3e2546ade2311Virustotal results 8.06% Heodo
2022-01-12646549185-1766200.xlsmxlsm 20039ff121b47e5026b29877b299b76e47f3c7f766b9010a04e148a19823dbb6Virustotal results 20.00%Heodo
2022-01-12NGP-069184.xlsmxlsm 60610dee4927e907b5a6a4ac49f8c921fa8af7005b2e8deb2b26ffcc1cac6322Virustotal results 16.67%Heodo
2022-01-12i_26522831.xlsmxlsm 24355720d9e3b12c0bd49ad9b2ade504263a3bc06d95103a3c086a316dc2ecbcn/a Heodo
2022-01-1277691006.xlsmxlsm 31ca17b03ef6422b7d631d23ad6af8ceefc4fb869ec0eab149172ceb59400342n/aHeodo
2022-01-12260051759148.xlsmxlsm b0567570cc27cb35b55793660817b24f15272b40b9ee6e8c733c3c12ef981aa4Virustotal results 16.13% Heodo
2022-01-12H-121.xlsmxlsm ccaea531ac7002797b7c988cd5b1feb6e53f5caf37ab0b4d4563040820706f74Virustotal results 8.06% Heodo
2022-01-12llqv-2.xlsmxlsm 3c8b54def22442aaa334cbae48263d897ca2d62d76dc4df4e6efb03849d8c2a7n/aHeodo
2022-01-1245815NDKHIVKPX425053.xlsmxlsm 43456f22a22af4bc49f0c52a891b5993721cd8595dc6f051a1a5ceff1f107621n/a Heodo