URLhaus Database

You are currently viewing the URLhaus database entry for https://lsim.in/wp-includes/xvvd-6i2h-5336/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417065
URL: https://lsim.in/wp-includes/xvvd-6i2h-5336/
URL Status:Offline
Host: lsim.in
Date added:2020-07-21 22:16:40 UTC
Last online:2020-07-22 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-07-21 22:18:02 UTC to abuse{at}hetzner[dot]de)
Takedown time:2 hours, 10 minutes Good (down since 2020-07-22 00:28:37 UTC)
Tags:doc emotet link epoch3 ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22Invoice_AG010_12493808.docdoc 7476dba24b28d2a074d7e75aea79591f98fbb95b065c91870b5a8198ab615f19Virustotal results 26.23% 
2020-07-22invoice_XW80_93812179.docdoc ee7974d011582b83c0464f15d86e55b3306961023b16ed3c195c6c1953ea5835n/aZLoader
2020-07-21Inv-TJDF926_333982.docdoc 062c45cd22faf032486fa920e68f639cfd2a7b640c0d36d297e6490118729c69Virustotal results 26.23% 
2020-07-21invoice_90_862096.docdoc 43025670822df6a6ae1ba1f56baae65c0d563c0c12410244aeb8fb166be9f737Virustotal results 26.23% ZLoader
2020-07-21Inv_MJD3_80249512.docdoc 112aa4be04d85780875343365b40f2fe9351e69dd4756d26a01f923251e17a49Virustotal results 25.81% 
2020-07-21Invoice_JNE4430_913079.docdoc 3e48fa00d3dfee3093ad2affb99324ae8e7261f2c92fd9bc71ffc5923a7dc4a3n/a ZLoader
2020-07-21INVOICE OEH08_297359385.docdoc 74a3c90f0a3c99e8816a94689a4cac44f886be61e0dc3f6d324a661c16c663f9Virustotal results 26.23% ZLoader
2020-07-21Inv-ETP47_985193.docdoc 9c3f1dbdddf1aea861852243a66b3795d0cbf86a1ee36fb372505a839db31540Virustotal results 26.23% ZLoader
2020-07-21INVOICE FDYF76_909878.docdoc 9e2fa2ec0c3818292f9a10539ef4bdcda848df84a8e0223cae2f28f82360a11fVirustotal results 25.81% ZLoader
2020-07-21Invoice-332_205756216.docdoc b4e3c557317004de4b83d941a7dbd81648b8383245a1b95806b736eda61b53baVirustotal results 25.81% ZLoader
2020-07-21invoice-LH5768_714476.docdoc 747095882ee4fedcb2d7306fbda6bcc5b792e877d427b855d80a0fdf5db073a2Virustotal results 26.67% ZLoader