URLhaus Database

You are currently viewing the URLhaus database entry for http://lehnhausen.nl/wwvv2/TPuvLWwtaCwvAeGThTlQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2199502
URL: http://lehnhausen.nl/wwvv2/TPuvLWwtaCwvAeGThTlQ/
URL Status:Offline
Host: lehnhausen.nl
Date added:2022-05-17 16:28:09 UTC
Last online:2022-05-17 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-17 16:29:15 UTC to abuse{at}flexwebhosting[dot]nl)
Takedown time:2 hours, 14 minutes Good (down since 2022-05-17 18:43:54 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-17UK4VOrBdxq.dlldll 928a7643bf0484c8c7a8cc105e935c4ee9857593316d23595004af3719ef2ae3n/a Heodo
2022-05-17QbwyKa9xAtOTzMI3.dlldll 88290574160dd12200a5337279cbc3ea9204eb7efa5e78f03d6cc748f3d245d0Virustotal results 16.18%Heodo
2022-05-17tb0DSUpbCP13W7EbjFU1ztqqQghONETZbP.dlldll 806e3244b1cb4460d2ce6d4085f436d8d322b958e922823e2cebdae3a32b84a9n/a Heodo
2022-05-17mmHOhs5C0To2FmOl10YDJq7eGhBXuu.dlldll d30c12dfc635b341155e4a8c2795113ba04a86ee06f0c093345b2fc11ef0c136n/a Heodo
2022-05-17TzewcxMgE11E1fzLdONOjGyYDo4qS58wJPo.dlldll 6050d2f7c6739c0c5f5567b4c1978b1a8ec66b1ad84e947b07703956ea1e1624n/a Heodo