URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ltyuye.com/wp-admin/rrktd1y-1v-75/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290952
URL: http://www.ltyuye.com/wp-admin/rrktd1y-1v-75/
URL Status:Offline
Host: www.ltyuye.com
Date added:2020-01-17 13:25:15 UTC
Last online:2020-01-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 13:26:02 UTC to esabuse{at}hkbnes[dot]net)
Takedown time:9 days, 19 hours, 7 minutes Bad (down since 2020-01-27 08:33:26 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18INVOICE-HYOG7_9656480.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18INVOICE KPHY8174_27936132.docdoc 8c6a507fab568587e5c6676af0cb7ee8f57833a37e787f437e4a5db18e66622cVirustotal results 27.87% Heodo
2020-01-18INVOICE_441_361841689.docdoc be4d9b3676d0bd95a24755c84b152d727eb0043cb0a2d8c240c567fb1668786eVirustotal results 25.42% 
2020-01-18INVOICE-MIYB9_164092873.docdoc 7e54c4db472e2b0660907fdc2d1a839364f6222f6e29c5702ff1e56ced3257f7Virustotal results 22.58% Heodo
2020-01-18invoice-CDM4_9118245.docdoc e70d619f1ca2594c00e8973e7268a2d2d3bb0917c2663977b998e567542fcd45n/a 
2020-01-17INVOICE_H0_3977932.docdoc a8c4e3f1c16e9ff3857699615d8f6bd392a4d88dfdc6f9dd9b43b523ac3158ebVirustotal results 19.35% Heodo
2020-01-17INVOICE BY130_31560626.docdoc 9d50256ecfbc6630a03d98c2f512c1084d03a8a416aeda264c405070e9a5d3bbVirustotal results 18.03% Heodo
2020-01-17invoice HT65_553176.docdoc 8b2a27d8044f6a13f7fd0a1b6aa157c90d32f67c0d170b3afa6e5c8005423af9Virustotal results 18.03% Heodo
2020-01-17Inv-X09_42485573.docdoc 76202cd20a4fb8c39e2f03939e6264b8ac98f7f40b5182ce5a9506ac5870e722n/a Heodo
2020-01-17Inv-YWJQ7_024657.docdoc 5b5d276c15b051d7bd90d0a94065b9989ff8678436c073df253abb3dc9d5f2c1Virustotal results 22.58% Heodo
2020-01-17Invoice-980_35613212.docdoc 4cf6b6c5e758de95aefdb0fffc36013c29fbdee525c30ebd1b85f19870f12963n/a Heodo
2020-01-17Invoice_260_084086.docdoc 50682122531706e8b035ce5b24ace8f3b0e7e50526937b524c4523e7da0adcdeVirustotal results 19.67% Heodo
2020-01-17Inv-GH8859_370340320.docdoc 6ea8be369da94860d9527db3416a7abc777e4a9c653d313aae08ed33082e603cVirustotal results 19.35% Heodo
2020-01-17Invoice-VZ575_78871648.docdoc 559a07cd9e86fcb6787310e586b5f97ad4ecd0cbfad46d213673d6f8c9618999Virustotal results 21.31% Heodo