URLhaus Database

You are currently viewing the URLhaus database entry for http://landorestates.com/wordpress/NELf96wr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2028250
URL: http://landorestates.com/wordpress/NELf96wr/
URL Status:Offline
Host: landorestates.com
Date added:2022-02-04 08:43:12 UTC
Last online:2022-02-04 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-02-04 08:44:38 UTC to abuse{at}bluehost[dot]com)
Takedown time:6 hours, 17 minutes Good (down since 2022-02-04 15:02:33 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-02-04Wk64VB78ZwOZ5.dlldll a881407f202c51074c28a8ea94ba94afa9687aef59c25f9ff8968b1ec49ace22n/a Heodo
2022-02-04Z8GRIZrKVZwGdwK5QBc.dlldll 506d0643d447087c1f2b5e1642d9c206c460ea2a5bd7793d85740c6022b6187dVirustotal results 46.15% Heodo
2022-02-04A0aVdwqE.dlldll 343d8478ff4898ac22414188e445cd7ac5170b70287a5e08a7d82442e137d311Virustotal results 46.15% Heodo
2022-02-04OYFK.dlldll db32fd6064158946083b7680605c50fbc299294a1e838c5cd0cd16a3121816b3Virustotal results 43.08% Heodo
2022-02-04PelTy8F2UuU.dlldll 4bf4f57960d958e437c5ba3fef81557561487880d0ea46f8b3471f425a4ede6fn/a Heodo
2022-02-04aOy0n30lDeHTb.dlldll 9f48e6fe01ef0f827e5e9991a0938cf4c213906a7aab8144cbe69c8e4209bb69Virustotal results 40.00%Heodo
2022-02-04ZAQjy8G3j1zi.dlldll a3422806b6a969e8e15969e11ad97a6d0e806918fc3a740dac715594922e782eVirustotal results 42.19% Heodo
2022-02-04ogxFCdVjIvxH3y.dlldll f6691e243f66376e3d60480b791dacdc2e87d412cabd6eb8d1fb11b86c98b256n/a Heodo