URLhaus Database

You are currently viewing the URLhaus database entry for http://leadphysio.com/wp-content/plugins/dwe/P_31/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1974597
URL: http://leadphysio.com/wp-content/plugins/dwe/P_31/?i=1
URL Status:Offline
Host: leadphysio.com
Date added:2022-01-13 18:35:06 UTC
Last online:2022-01-21 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-13 18:36:12 UTC to abuse{at}EverData[dot]com)
Takedown time:7 days, 18 hours, 40 minutes Bad (down since 2022-01-21 13:16:55 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1402486921639455046.xlsmxlsm c95f568471e97a600183f2a71c62c8c16c86552989bf03e2e1b9104282700689n/a Heodo
2022-01-1415592015865617.xlsmxlsm ed0448141caba757e10c045d97e8593777ba7c60b8871b5871622b2b80ad1519n/a Heodo
2022-01-14QU-9.xlsmxlsm df06e51b72166281110f90f19e518fd3a11af0a1ced6a279c8c16277ad38e62dVirustotal results 33.33% 
2022-01-14EbugDt_074.xlsmxlsm 8af80399bba56ded76bb3e7373388d1354841bbea61dfab0094215403def66c0n/a Heodo
2022-01-14CR_781337.xlsmxlsm ccfeccd30191690fbab0da557c819cb4c3a300c1fa61faf33b618f6ce9a014d7n/a Heodo
2022-01-14677722TPQRPF-907593.xlsmxlsm ebffb509fa2150ae4536dcc78d9afb9a6bc23d22d1b8efeb4dc6ad296fb94254n/a Heodo
2022-01-1426080363756493599.xlsmxlsm ab5d8bf5fc5242d31fac07794a032f75a097559e76c27991d42d0afa48519db5n/a Heodo
2022-01-14532148567.xlsmxlsm 689555499fd2dff9a85acca987cf63ecb004150fb9428e7336b11a90eed8a4a6Virustotal results 33.33% 
2022-01-145470389293.xlsmxlsm 63d6ae5feb2ece25c4de9930b6779f1222d705097f3c6d16c06147699adef880n/a Heodo
2022-01-14wpjDBE_531567483.xlsmxlsm dac736a5562b2a96cece573228b50c17f369d3912fef2b92dc5ea40d5c427034n/a Heodo
2022-01-143841_9.xlsmxlsm 01e14e3c803705655e2068d80e77f2e2103118f38fa43791e069273b46c8cc0dVirustotal results 34.43% Heodo
2022-01-14347623860.xlsmxlsm 45e812f58d59fb2bfda7a64ae7be9b400f55c40c9d1867e23b351cd1b143ecb2n/a Heodo
2022-01-14ov808.xlsmxlsm 9770e911e79143121d645e9e5c84b8472e49263dd3ebe7f615b4051784d2ade9n/a Heodo
2022-01-14OOE-9504935.xlsmxlsm a972c47050ae7cf97f0c52155e8ab1462d5a9606eaf7140f1ee56f1e8a45dbb8n/a Heodo
2022-01-14JGEY_88736.xlsmxlsm de59e179f2f1f561d14fc8fe0d9e607430201108b22880bef5fb5284a2b0a41eVirustotal results 31.75% Heodo
2022-01-14QAQNQ_23826.xlsmxlsm 1f33cccbde25d58a817b0b6355084b8d0694bb104019808808694c2e6bbe2fbbn/a Heodo
2022-01-1445MDYNKWAYP_84344.xlsmxlsm ab3a001d34d3eda5f719c9692589bb86f0fd6fb88bc91e65f73d5a113496382fn/a Heodo
2022-01-1476261245_054.xlsmxlsm e05454c9c65893d53468742e56654dc8fb006fb1520b52a9fa1e672e65b6565eVirustotal results 33.33% Heodo
2022-01-142323636_4359038.xlsmxlsm e666db29cafcd8ca53bf39e302e59b22b962a623ce08bea482188b4b198b059en/a 
2022-01-14XUSL_377.xlsmxlsm 74fbe0349e9ce3a448a58ffd97a0d40d818b39d27cc47c021374846d7ba4d4a8n/a 
2022-01-14gjnVJ_70802461.xlsmxlsm 2a6e2750b860bc0613cffb355aee98ee8fa3930d2f1387ccbc9a5d022f22b14fVirustotal results 34.92% Heodo
2022-01-1493552228421793.xlsmxlsm e96a3f5577ef1f2045def7dac6923247f9ea4baf84301b8425761d362301bd83n/a Heodo
2022-01-14OBWMZ_38771399.xlsmxlsm 77c84a4f67f70d068261158ddf09d5e98292a7d86397fb95dec8f0092a67d25fn/a Heodo
2022-01-14hKNAzA-037.xlsmxlsm 9cd906e8e1ade72180999a159418a5afbfe2cebb2cbcabf9e53352b1101e8e99n/a 
2022-01-14287048357_844025.xlsmxlsm 9ae614389cacb729663a11f54b57c02e7fd9009561d9be530e42e61b4f9eac0an/a Heodo
2022-01-14095738346_1.xlsmxlsm 4ae00681a3df217ac3d3dc4f3e7b9a154540d3047f51504700e9f6d937e6a29dn/a Heodo
2022-01-14GMzRd-718110.xlsmxlsm 2bddcf7091fe815708701ec5e688ab154d2d422c7bb736a50dec1ad373b77d8cn/a Heodo
2022-01-14ttnfm987881.xlsmxlsm 5f371bba772204823b8a090dd95b8561926c57c6555fcfbad90d2ab65718ff71n/a Heodo
2022-01-1413_30.xlsmxlsm efe6738d4ba36185f68784a158eaafecfa97f2a854ae278b8d193f6edc65ed2fVirustotal results 31.15% 
2022-01-1474790971137.xlsmxlsm 2a27ce2154d11dc966ffa667153ed128ea0b55eafd8cdd00ec37a4068ea6f5ebn/a
2022-01-14GCRQ_69401532.xlsmxlsm 31880b7b69938b12824c65ef7240304c054a61f2c4e62b7f596cafbad8b63eben/a Heodo
2022-01-142197_1486.xlsmxlsm 42c5bb56d6d7939abf3f29c32648b0239c79d8362d5b7634e96c8387b4376831Virustotal results 28.57% Heodo
2022-01-1491209_7575.xlsmxlsm 033b712fd7d4d23cef910bf6ad4440c6e7c3d79f483b9d79ee72db130881a05bVirustotal results 30.16% 
2022-01-14814610124.xlsmxlsm 93797babbd39191ec7414750b549df061089d4b224c2465baa56820ed3583b66Virustotal results 29.51% Heodo
2022-01-14LpLDMl_20531485.xlsmxlsm 722d4a00f62f11f3e669d18aa37360f9fc04792b7d8b9c150c4adfd9f9e10e92Virustotal results 28.57% Heodo
2022-01-1420842332MGVKKAUND_07.xlsmxlsm d8fd315efba4dd6e72aaf30eb91ac6bbdc046717708c740158751ebf6a9e18d4n/a Heodo
2022-01-14890807950825.xlsmxlsm 38b84fcdf7e7ed1a95a221a66ebb59bf63847b414da3370144e103a23b9a577an/a Heodo
2022-01-14dNdi3347762.xlsmxlsm bd84338df7f1e8eae032de81e2839eb85a6f05c8e7f3afb88bade961419a9d49n/a 
2022-01-14UB-402.xlsmxlsm 69ef1b95072beb41ac0bd2bff9613836579a4e1b2738fd5f150a0507e1c97fa4n/a Heodo
2022-01-14y_3842781.xlsmxlsm be9b720458252f06a6688c838079c24730523961b9242c3a0c76ef5c4c1ac949Virustotal results 26.98% Heodo
2022-01-14095UILNJNGK_62688.xlsmxlsm ec237a7588cb70688e3f57edf9ec59126b234f51b996b68000604002a379dc5dn/aHeodo
2022-01-144179_49305.xlsmxlsm 8705d70c0665223e1bdafd9d3ab2a3d0d2afa50f899b976f4a480293ccc715ean/a Heodo
2022-01-14S_02.xlsmxlsm 878245ca533c239b7066ce1bb483d8cd42a8d5887954c3e4db00b5a52d46f354n/a 
2022-01-147913632-356.xlsmxlsm 296171d1b92b175041ee3829e60a6880b93861ef09614e912d112777fc2fe13aVirustotal results 26.98% Heodo
2022-01-141861_363967.xlsmxlsm 6ac14b86db1b807b8bdc126d8e1ba66536ff55b5fcddb9ba068bd70b176c52ben/a Heodo
2022-01-1426709813.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-14820924814214.xlsmxlsm 70331e285111162a78eb26ed4f17fa1fd42d663b4355e55f6e4aa117d19dd2f3Virustotal results 25.40% Heodo
2022-01-14TZK-34943489.xlsmxlsm b8b1fb98701bf450f491a99a027c35455ecc635801276ec74d0f637aa91aa3f9n/a Heodo
2022-01-147068918_192081014.xlsmxlsm b258f9290e51fbb164e311ba5ed55dc99113582e4f849be35be5efcd3a6784a7n/a Heodo
2022-01-14E_765339.xlsmxlsm a1a5295caf727bb6210b32ba53371db4451b4355c8bf0b420b09dc8e1182fad5Virustotal results 26.98% Heodo
2022-01-145000_2.xlsmxlsm 9c8a39e1e2d7547aebadc4f37b84543d9e48faca443b9acd76cdf46d65459acdn/a 
2022-01-14039_538362.xlsmxlsm 5e752b11e5c8a995688ec34e8bacbf253a0450479c1c2582dbd770d004babe51Virustotal results 27.87% 
2022-01-14929634CSAAVSZERD-811790.xlsmxlsm 4eab3977f88e6444a99925c2a5769e6b720e8a6ba4ee8cc8235e23a33a1e6658n/a 
2022-01-14013-48105.xlsmxlsm 948bece3441056d04af338e263063315d45921d28cf536276011fab5b2127a00n/a Heodo
2022-01-13HA_74.xlsmxlsm fbaad03de2f185ae958c7192e2215fb6678792763d4872c4d3081d8980edc463Virustotal results 24.19% Heodo
2022-01-13m61.xlsmxlsm e15f4ab1af0935e26f54b19c1221a5dd41698713dfa44c327a206ffd708f3ceen/a Heodo
2022-01-13921166DXX-790822.xlsmxlsm 88d07eac813b81a446e976b9d46feb95a86d3e4d0cdfb6e604d42bba8757db02Virustotal results 22.58%Heodo
2022-01-13660297991_1.xlsmxlsm 7585b5ae0e18149ef1ef83b54ff727158a1f11364edde0d8e4ecaa3462369f3bVirustotal results 21.31% 
2022-01-13AYmm_245.xlsmxlsm 096504811c78492132ac12b84ad2a6ee435ac882bd0a59bed69a1b10775edf37Virustotal results 24.19% 
2022-01-13NH614606.xlsmxlsm cbfdd288ed81b34166f40cbb96b59bf5836fe4dc0f06b4f121a97ad11fed7786n/a Heodo
2022-01-13F-96.xlsmxlsm ee2c0116fbec7f4a729f4570a26f035ca6cba2264314eb201bb486ee24a1aa0an/a 
2022-01-133287561-214.xlsmxlsm 80f732153350e276a2b676506c38904e02387501bbd7946340ee90858bcc5f79Virustotal results 22.58% Heodo
2022-01-133250830NJQM-93.xlsmxlsm ac61723d025f90be4b2b44d6643e6ef15327be31899b8cbdaa43c0a2fac25f5eVirustotal results 30.16% Heodo
2022-01-137993-91.xlsmxlsm ea518dd18446672c07dfd03a7b14e0f939a89b414a670198e7cf429b6cba7d84n/a Heodo
2022-01-13DUdJny771777.xlsmxlsm 178140aa190e5af477ce55e0e4eed3580b2bd4c9a7eeae1329291f31f286880fn/a Heodo
2022-01-13435CTSNES_538.xlsmxlsm 840b14be8c10c32e02b2c43fb7fce553f9a5fd5131d87cc9d95b514583ef2d49n/a 
2022-01-133441_2972.xlsmxlsm b61f87bbf1bdfd5c3b46851f485213ae5a8abd6764d3e228d71ff34b9ce1c2d6n/a Heodo
2022-01-13O2002584.xlsmxlsm 8186f82da42f9f07b405d280632e62d7632c4b472cbb489761bf400bc9ac2b74n/a Heodo
2022-01-1310182502-27396.xlsmxlsm ceaa2c7ed322909ff594d94f1e98548778f40597a6b440ff4fee26d924239963n/a Heodo