URLhaus Database

You are currently viewing the URLhaus database entry for http://l7.net/portfolio/5332237271/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1975013
URL: http://l7.net/portfolio/5332237271/?i=1
URL Status:Offline
Host: l7.net
Date added:2022-01-13 21:50:04 UTC
Last online:2022-01-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: sugimu_sec
Abuse complaint sent (?): Yes (2022-01-13 21:51:07 UTC to abuse{at}liquidweb[dot]com)
Takedown time:13 hours, 20 minutes Good (down since 2022-01-14 11:11:36 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-14PJV-8719.xlsmxlsm 127c23bfe45f05520e25aa2ee365653314949ad5bf52a5961e3b97b42ee942a4n/aHeodo
2022-01-140799571GUK-1012.xlsmxlsm 4ae00681a3df217ac3d3dc4f3e7b9a154540d3047f51504700e9f6d937e6a29dn/a Heodo
2022-01-1462GEB59855.xlsmxlsm e528e3738d4b8284c74b4e98c0cd720a9656a76170631018efa083afe6775b20n/a 
2022-01-140962702_0308.xlsmxlsm 5f371bba772204823b8a090dd95b8561926c57c6555fcfbad90d2ab65718ff71n/a Heodo
2022-01-14014482_7.xlsmxlsm 4ff2f64198d5fd1797397a1ecba30671d30b6f434b435d292a5814e780bb0ab6Virustotal results 28.57% Heodo
2022-01-1412UGWSEDKAPD-461689.xlsmxlsm 320e9b7c12da6a0484b786666c2e5bd35a707234d1503379ac882d9a9c7ecd69n/a Heodo
2022-01-14RHU-104.xlsmxlsm dd43f7aff805ec6fe3bd061d0b56f766348dc687159a25895ae03963e70e3d4fVirustotal results 30.16% 
2022-01-1474595_768705007.xlsmxlsm 3ed54e7edbfda5e8c76a389606e9626d5cdab72b4ed9b940465970e322d47ebcn/a Heodo
2022-01-14BcchsI55167723.xlsmxlsm c94b6907928429e7d56f171d9a379d24c0250086ffbeb2a9da5dde1049fa569fn/a Heodo
2022-01-14DKN58673797.xlsmxlsm dc929317cca3b519661820052cd357c4891f7725de37b15637010b5903292a0bn/a Heodo
2022-01-14950028458-52483255.xlsmxlsm d08e195ad3750d53f5dab90cbc01f05dc26d11db16c7eb3dc74a1656b7417cf7n/a Heodo
2022-01-14GAVUX_3198565.xlsmxlsm 48894064de8f0c8f53863ef98d25bc7855584bbbb261682c8eef1ff0e41397een/a 
2022-01-141590507-20.xlsmxlsm 046d5f85d492903e52b9161d9454a1b6a18f3980482650fff9a9b2ba7086c1c0n/a Heodo
2022-01-14b-12.xlsmxlsm 9bbdbbf2e16c8304a30bc12313362864d0b4611b6b5564e5fa4efeb559c9a4c6n/aHeodo
2022-01-14P_21.xlsmxlsm 0db8962b34a097cbefe62d17aae56cbb6e86fd1f8302a190427bf5de9e3a678cn/a Heodo
2022-01-14MRSTC77385119.xlsmxlsm be9b720458252f06a6688c838079c24730523961b9242c3a0c76ef5c4c1ac949Virustotal results 26.98% Heodo
2022-01-1499466079_6817756.xlsmxlsm ec237a7588cb70688e3f57edf9ec59126b234f51b996b68000604002a379dc5dn/aHeodo
2022-01-148953-17878732.xlsmxlsm 8705d70c0665223e1bdafd9d3ab2a3d0d2afa50f899b976f4a480293ccc715ean/a Heodo
2022-01-14BY6973867.xlsmxlsm 878245ca533c239b7066ce1bb483d8cd42a8d5887954c3e4db00b5a52d46f354Virustotal results 31.03% 
2022-01-1492279908OGUM_16518470.xlsmxlsm 296171d1b92b175041ee3829e60a6880b93861ef09614e912d112777fc2fe13an/a Heodo
2022-01-14dTO408155.xlsmxlsm cb0d9916b6be6d3b9d52d057b5b8aa3b223284abe331467dea72eca27165a618n/a Heodo
2022-01-14O_51.xlsmxlsm 0e2db8bad325d450826ee98740532c44b36d70a95f31178c85a50f4e8ee9c8b0n/a Heodo
2022-01-146886_730138959.xlsmxlsm d7e424ccc4f316f9abbabc2a3b0bc47b61daf071111fed745056ffc823c541c1n/a Heodo
2022-01-1461562146576146.xlsmxlsm b8b1fb98701bf450f491a99a027c35455ecc635801276ec74d0f637aa91aa3f9n/a Heodo
2022-01-1435375-730841.xlsmxlsm 5388d17d28ba671fbe8a27779a4ff0a97c15a00c1a91e946824b81b38c6d8e90Virustotal results 25.40% Heodo
2022-01-14879283ECQNAILG-96.xlsmxlsm 7419106ec7430cee9167f7375fefe8db7222770b811dd208a87ebc8ecc6823dbn/aHeodo
2022-01-14NC_58.xlsmxlsm 9c8a39e1e2d7547aebadc4f37b84543d9e48faca443b9acd76cdf46d65459acdn/a 
2022-01-1487479SELXROQ349346.xlsmxlsm 3dd7791745ef386d30fdac27e392533cbf154de6881440bf6bae3b947c775402Virustotal results 24.19% Heodo
2022-01-1412611369560871.xlsmxlsm 9914b76a0ba3fb9da5a56e91338779ce902665c925d401d929aadf7974293d79n/a Heodo
2022-01-14282451755_29689.xlsmxlsm 7625617812752849d1db7dc8713eb12b59fad515cd833d3a51fb14ed29290a10Virustotal results 22.58% Heodo
2022-01-134442_491117.xlsmxlsm 83129ffae0cf059607eeb86ba3abc6ba3a28905d44a8d69bbf844d966578f6a9n/a Heodo
2022-01-1309113089_725.xlsmxlsm 6988f7d044aba01c32dfd1a18e12f8a22021287669837002631609031be20c01Virustotal results 24.19% Heodo
2022-01-13TC_2732192.xlsmxlsm 1217dcbf810cee6fe242d7835078f9e5177ce7d1bb925405d550ea413b08fbb0n/aHeodo
2022-01-13026300.xlsmxlsm ebcf8ce780273a62dfc735a9ca26cab21be68b0ff57bd22a97fcb60537a979ffn/a 
2022-01-13ejV_226276.xlsmxlsm aa13ae55198d07ca88b97900dfc331543971593d694d45a94f290a25b5bf0edfn/a Heodo
2022-01-133832_85926.xlsmxlsm 1f79a3aaba0bcb4a01de9ed8c7ff49c87c419b7af3ba808588e67bb898434b75n/a 
2022-01-133445763037683103.xlsmxlsm 9f47ddb444c9cffedc84c7eaf7c80d10b990146564954a6134a910733bc0a38dn/a Heodo