URLhaus Database

You are currently viewing the URLhaus database entry for http://luilao.com/yakattack/protected-module/close-warehouse/2ozmo1p8-8w7741v/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307243
URL: http://luilao.com/yakattack/protected-module/close-warehouse/2ozmo1p8-8w7741v/
URL Status:Offline
Host: luilao.com
Date added:2020-02-03 22:14:04 UTC
Last online:2020-02-04 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 22:16:05 UTC to abuse{at}ovh[dot]net)
Takedown time:16 hours, 40 minutes Good (down since 2020-02-04 14:57:02 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-04Arc_C223566.docdoc 167323f590c8eea01e897581a3de8e00606c176ff6518fd3ac0a3d64dd2e7d9aVirustotal results 36.07% 
2020-02-04ARC-2020_02_04.docmdocx b71394268acf3acca757143450d5ccc9030bb60cd3e5e9e3245f81fa1b63e757n/a 
2020-02-04FILE 2020_02_04 FW094.docmdocx 66fbfabc52fac899652f0e490be589ec3d3c5d3cf233ca24171ab6d8ff55a50dVirustotal results 34.92% Heodo
2020-02-04inf_20200204_646.rtfdocx 7866c794e416ef1f3bdbf8d29370390f025c8846d1b4e5d61b2c0b74daa75508Virustotal results 34.92% 
2020-02-04ARC 2020_02_04 M22567.rtfdocx 29d71c405f029109b5b6a5eb51f5f957a706b5130105c3abd7e3e97cccc66c2dVirustotal results 36.67% Heodo
2020-02-04Mes-Q087.docmdocx 002d694ef8bf683023d2285a4a16c1673c4ac35874c13d7cfd9c9dc9cee5854cn/a 
2020-02-04INF-20200204-5852.rtfdocx 028f4c2dbdc1cc4dcc34a7dd5f190ca34075756f22fefa208b992649fedf8c14Virustotal results 33.87% 
2020-02-04REP-2020_02_04.docdoc 7769ae1cce4e29c3e8bd982600d46a07804c1f66a2772bf00ea100aa24c227baVirustotal results 40.68% Heodo
2020-02-04LIST-QZ21792.docdoc 06ef3b76fdfb2eccd0a672a1023ffeff68a0dea6d2a4da527eaa596842391fc1Virustotal results 38.10% Heodo
2020-02-04INF-20200204-66134.docdoc 0c5326e304b5b23196b990d4ba1000e7a34150acbfa3b3cd8aaa35a12f124e26Virustotal results 38.10% Heodo
2020-02-04List.docdoc 05ead2ea8d0ec1dfd4f5b491661af731b41e275c0471f7f733cd097b544413ddVirustotal results 38.10% Heodo
2020-02-04ARC-20200204-Z913.docdoc 501750ada1703f7865f401e573449f6204b469b099d9e1e9fdd8f51413c17639n/a Heodo
2020-02-04MES_HI555870.docdoc 3d78b8943ee63fbf0eea864676e6cc25a64863d53c9252807f5cfd86ebe3c4fbn/a Heodo
2020-02-04list 2020_02_04 BYW0951.docdoc 96ca41fe85593ec2adee71cbe9ddeae3c084689d3bd049ba0b3a548895583c11Virustotal results 33.87% Heodo
2020-02-03Rep-20200204-JF3036.docdoc a958c01598fe12500a80df8027f579420835f95b60f2d55b885127d396e6196bn/a Heodo
2020-02-03ARC 2020_02_04 48819.docdoc 56188fc7bef05cf136d0cf8d50fc2570fc10a234f8bd51457024d407a7421504Virustotal results 31.25% Heodo