URLhaus Database

You are currently viewing the URLhaus database entry for http://lashlabplus.com/stats/f6t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:255253
URL: http://lashlabplus.com/stats/f6t/
URL Status:Offline
Host: lashlabplus.com
Date added:2019-11-18 23:24:12 UTC
Last online:2020-02-04 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-18 23:26:05 UTC to abuse{at}hostwinds[dot]com)
Takedown time:2 months, 17 days, 4 hours, 35 minutes Bad (down since 2020-02-04 04:01:55 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-27this-site-is-virus.docdoc 3e9636672ed7edc93c9ccda01264aa515f9d53a2762afaf3a886fb2f28c15305n/a 
2019-12-04this-site-is-virus.docdoc ba57435f9b3bea77406bcd02208ef02c6d25610a85f9a3704a07221f31ce7529n/a 
2019-11-24this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 20.34%
2019-11-24KhPzeE8bu6z.exeexe c003648cbb298ac7d5720d9461c40ee849f838e67829f2675c32d22be62d41fcVirustotal results 66.18% Heodo
2019-11-18IF6U.exeexe c45a7d66c95e4bc6703b0b243eb8707bab4f22bb37953ae64331c873bce80a15Virustotal results 11.59% Heodo