URLhaus Database

You are currently viewing the URLhaus database entry for http://lekei.ca/ecard/images/css/parts_service/y5ut8akutvb3d35tipvisdkntq91_afo5x-4801493307/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:200277
URL: http://lekei.ca/ecard/images/css/parts_service/y5ut8akutvb3d35tipvisdkntq91_afo5x-4801493307/
URL Status:Offline
Host: lekei.ca
Date added:2019-05-22 22:38:06 UTC
Last online:2019-05-23 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-22 22:40:05 UTC to support{at}grouphosting[dot]com)
Takedown time:12 hours, 28 minutes Good (down since 2019-05-23 11:08:20 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-23SCAN_17666461935US_May_23_2019.docdoc 5a217e950f27df7da794e729b22980c2aa1417696ffa1ee861ce9e657fd35bbbn/a Heodo
2019-05-23LLC_2910190368US_May_23_2019.docdoc ea6d7990cfe848b99d391ea3690e80fa14710973f3b7a3a151602e736062d3d7Virustotal results 15.00% Heodo
2019-05-23INC_05015494249US_May_23_2019.docdoc e3b73fc71fce5c6eb0769674687f1fc666118b06404f2f9578a2818e0cfa38e2Virustotal results 13.56%Heodo
2019-05-23LLC_797077960794US_May_23_2019.docdoc 28398ed10fb49cc49f2cf4559ccbd2b5ce7213c0d62694dd637a5ec8d304352bVirustotal results 16.95% Heodo
2019-05-23LLC_6055473975US_May_23_2019.docdoc 86a95894b9f4bb96a1a7c256bc95a3742349d41377b18759cb25293d6d22ce7en/a Heodo
2019-05-23Document_803575985277US_May_23_2019.docdoc ca1a8569a1532152068e32e0852b97e573e075c2fd8bcc34fb9fa884d67734d0n/a Heodo
2019-05-23FILE_635246861553US_May_23_2019.docdoc e3bc63109b54ad59d61c2456ffdd5c0779b7eb114b4a5f94011657d7de51557cVirustotal results 36.67% Heodo
2019-05-23FILE_52751767223US_May_23_2019.docdoc 267b17c740799cbb8daa7989146943ffb5a415b2fa2101ac81c7f5f5824cbc58Virustotal results 32.79% Heodo
2019-05-23DOC_482552682711US_May_23_2019.docdoc a4961c971e9b1e255f1a12cf6a635dbb0b4f042a0783cca374f38073b52abaabn/a Heodo
2019-05-23LLC_310231402446US_May_23_2019.docdoc 1dbd7a3e1760453301a48e728acd4d235d74af47640920b0b046de689c66824dVirustotal results 29.51% Heodo
2019-05-23FILE_7487964283US_May_23_2019.docdoc b3de11f2d9a35f0ab55f86928036e4da3c3112e05a0bb7c42e03ad1a670a83cfVirustotal results 27.87% 
2019-05-23INC_4721431701US_May_23_2019.docdoc 7337128eb5289d453235b39cae458087abaf5f773ad087a1714a7e8701332e33n/a Heodo
2019-05-23Document_020864243865US_May_23_2019.docdoc dd54251fb8f9186afdc65473e70d39f42bb36aa2f3eb9d1ac74c35f7cd895d78Virustotal results 30.00% Heodo
2019-05-23DOC_1284324221US_May_23_2019.docdoc f1f5d0478731474c23d6a4471484b540243fa3bede2c3f843396844d3061fa3eVirustotal results 30.00% Heodo
2019-05-23FILE_2281898176US_May_23_2019.docdoc 9569dd8beeaa524e03b21f388397fac210001f7ad4723307700f37c2bce6c2d8n/a Heodo
2019-05-22FILE_920105199608US_May_23_2019.docdoc 6673817be34aa5db84a05855fa2364f04239bcb39d1956c00586357bc2e96382Virustotal results 27.87% 
2019-05-22INC_36079834491US_May_23_2019.docdoc 07361938b338966720b62ffd3b02e5a956e6366404284322e59ef2d2bdd5f8a6Virustotal results 20.69% 
2019-05-22Document_83721563061US_May_23_2019.docdoc e809d5a50a913e203d75b058361082b4de50e62b68f4f8a8dda875619d4ac4d4n/a Heodo