URLhaus Database

You are currently viewing the URLhaus database entry for https://www.lhbfirst.com/wp-admin/disponible-knTcOLH8-uHaJJQpENJJR9AV/external-profile/9nm0535asyp8wz3a-zwv16x2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303937
URL: https://www.lhbfirst.com/wp-admin/disponible-knTcOLH8-uHaJJQpENJJR9AV/external-profile/9nm0535asyp8wz3a-zwv16x2/
URL Status:Offline
Host: www.lhbfirst.com
Date added:2020-01-31 11:08:12 UTC
Last online:2020-07-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 11:10:04 UTC to ipas{at}cnnic[dot]cn)
Takedown time:5 months, 20 days, 6 hours, 38 minutes Bad (down since 2020-07-19 17:48:57 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01Factura_qq501q5287.docdoc dda76af8d395dccbe545d1229617376570b747b0bacfe5582b646f42937eb732Virustotal results 38.10%Heodo
2020-02-01Factura EEM6942 70645.docdoc 030b8dddafd42ef14d23d3b5870e020247a721f03265ded1fbc412d0d42fd003Virustotal results 37.50% Heodo
2020-02-01Factura 02_01_2020-ED8869847809.docdoc 79accb4ce6aff5a064b7f464f398c18c37eecd4adf21339a1824347b469c8996Virustotal results 37.50% Heodo
2020-02-01factura-26886069862.docdoc 925aa1b36350cc64b4a2b8f821d9ded718b3a43d442ce2cd862d3315585050f0Virustotal results 39.06% Heodo
2020-02-01FCT_5062460180.docdoc 183e62f5bf4e4e6d18a1bfb90dbbee1555da7d65f21fca506a930a27f0aefba8Virustotal results 38.10% Heodo
2020-02-01fct_H6559298 780445651223.docdoc e32c6131507273873c65fed58ff6d79fed48ec505001d9853da6d7d487d79010Virustotal results 35.48% Heodo
2020-01-31FACTURA_02_01_2020 H6G494125530.docdoc 16dc2ea6966445ff4b382ab180a5983bbe8513068550a030d7581fd6c0e46bd7Virustotal results 38.10% Heodo
2020-01-31fct W66345-749762479463.docdoc 964ade2e36826fb06c5ca21cd4cbbd3a11a8e21c195e323ae8cfd383543d1d93Virustotal results 31.25% Heodo
2020-01-31fct_35888067268.docdoc aebb8ef053c29de1aab7da94fc9873aee20eadcb51be762f73f08a2aa0cea7baVirustotal results 31.75% Heodo
2020-01-31FACT-3V8212.docdoc 7df4b1ba365168795d999be611b28e076068dc3a6a2fed14e065dd689a2d841fVirustotal results 28.81% Heodo
2020-01-31Factura-01312020.docdoc b21358d6c77db859428adedf4f2f657357cc13d818befc72583e6cc9590cd135n/a Heodo
2020-01-31Factura-5p14119pnn.docdoc ac199993dd292049e9915d128c459ab0532939a5cccb634c589eac134039e9cdVirustotal results 31.75% Heodo
2020-01-31facturacion 3p137ommnp789.docdoc 31ad07da3bccaaebc18676212e40fcd30a280ae55fd101eb55e89302c9532580n/a Heodo
2020-01-31facturacion_82C25293337 75399766040.docdoc 91275159f80eeb0eff909660f56290704daffd027e4b5725ef33573c925488a4Virustotal results 20.31% Heodo
2020-01-31FACT_J23877-63599848.docdoc 9ab30abebfdb3619b5253d44a3e4b928ad5d7ae3a1af4c5634f3b1faa7e675a2Virustotal results 20.31% Heodo
2020-01-31FCT ER34420526 9640180471.docdoc f5de6a5841b14ac02d31b476bd367a5495077baac0b74d43c3fad406c435ef6cVirustotal results 20.31% Heodo