URLhaus Database

You are currently viewing the URLhaus database entry for http://leong.ws/Scouting.my/closed-Rpng-iupUpmO/open-portal/vjlva-wy3z97y8ww/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422321
URL: http://leong.ws/Scouting.my/closed-Rpng-iupUpmO/open-portal/vjlva-wy3z97y8ww/
URL Status:Offline
Host: leong.ws
Date added:2020-07-30 18:51:17 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01dat-2020_08_01-639.docdoc 92a8c9729a35ef4fbe97b8b931ac2ba3284ff4c1aaaab30eadbe36ad12c75465Virustotal results 47.46%Heodo
2020-07-31List-NM7227.docdoc 8698a975eeefa70a6e8eac20e57be07dbed23f59301a735a72892edcfdc62d26Virustotal results 49.18% Heodo
2020-07-31REP 2020_08_01 1043923.docdoc 796654f192e741799d2243175e6ea18540b6c48fbed84b010dd806485acbbbceVirustotal results 47.54% Heodo
2020-07-31Dat YYQ846.docdoc 09b591c165b3ecaa1fdc7b1afc9b6a2f9cd8a49b1e9936d7949a8ebd083163b3Virustotal results 47.54% Heodo
2020-07-31rep 2020_07_31 EN52663.docdoc b90405b5945098e5acd1f81f9821c66b49f8bf3b41ae47e41ffb76e5a95de4f3Virustotal results 49.15% Heodo
2020-07-31List 20200731 UY0926.docdoc 44d519578a005cd82f6c6e858d27cc39d992c0ddfee4c8f94d951b5135cec3b5Virustotal results 48.33% Heodo
2020-07-31FILE_2020_07_31_2771444.docdoc d20d76e55f20052f0e63179b3aaa4c91c0e0ca1edbe7d38737e1ca1aabf2798cVirustotal results 47.54% Heodo
2020-07-31dat HI6116.docdoc 775cc5726879d9b9708606b11e87b678b61b022aa5ec842c5666d3cdcfb8a4acVirustotal results 47.46% Heodo
2020-07-31Inf_2020_07_31_882174.docdoc 6b43b38cbc9af296e3ffeecf0f53986f42af21fd59ce158d7deedc06d597880eVirustotal results 45.76% Heodo
2020-07-31inf_U83323.docdoc ec8b46f21d2533753c2813ecba4080d27fb413b98099f87223b5ef00175669c5Virustotal results 43.33% Heodo
2020-07-31mes-EV559262.docdoc 5a2684ad28a602e041aeddf1c0ffab3a0ce29c3420b4a4d8a8351043a2269483Virustotal results 43.33% Heodo
2020-07-31LIST-2020_07_31-3936.docdoc 60aacf6d4c9a53d3dae37206f889daf474b87fbc7e5b88196bc73600ea886d61Virustotal results 43.10% Heodo
2020-07-31Mes-20200731-FF15187.docdoc 56acb99a4ce942c9970dd5e96a8bdbd3e446b89c9c66e8876a9894c569afc259Virustotal results 45.00% Heodo
2020-07-31Mes-20200731.docdoc 4acec2a5ef0b6f549b39db572081188d4e2d9cc039f95a709c105b7aa3bddf7bVirustotal results 41.67% Heodo
2020-07-31List 2020_07_31 BYC685.docdoc cb6ac957d36fc72b75e45e7c90202b929041dd3d870a095ddae756a7f50180a5n/a Heodo
2020-07-31MES.docdoc 5335d6881bf6a2b0776a89724043b6693dec8ffb4848b0c66954f6373c38cb20Virustotal results 40.68% Heodo
2020-07-31mes-20200731-TJN312044.docdoc eedaaf67ad14a0213229367966ad1333e3f8085e1e6b83683d7fac0e3e16ae28Virustotal results 40.98% Heodo
2020-07-31ARC-20200731-878.docdoc 925fb8974d3622ddd5df080f3bee888c2ce91a92d43cd6b685ee82c8108deab1Virustotal results 42.37% Heodo
2020-07-31REP-20200731-X4617.docdoc 7172995d1d5b54353bce9bbad1ec7900ca7175b8a7e41e5d86bd80df42e1014an/a Heodo
2020-07-31arc-2020_07_31-1688.docdoc 3d31440aaa15138bb6061b0269a5d0f6a34fc60d1647b276f2d3363410b30997Virustotal results 43.33% Heodo
2020-07-31DAT_20200731_NJ681.docdoc 34407bf711172d27bd7de483c210c07d89c0f512f8606c1667b5d2abb410c00bVirustotal results 49.18%Heodo
2020-07-31LIST-2020_07_31-R930446.docdoc fa3e81294239894ab6d187ff561319cd3f23649f9888593ae2c7bd734af6ecfdVirustotal results 49.15% Heodo
2020-07-31FILE_2020_07_31_1791.docdoc e72d96697d3a527fb2aaec8654ba7eaaa7e255a7d15b23b12e1345e541be502fVirustotal results 47.46% Heodo
2020-07-31Inf 20200731.docdoc 57b075be6438184bf527bd055363a33f851ee9acb765aaff3c717f2ca6ea7d5fVirustotal results 49.15% Heodo
2020-07-30FILE_2020_07_31.docdoc b9c357adce4a39fef2bdc25779951e2f40307dade90e05fdd0f95b77cf77c786Virustotal results 49.18% Heodo
2020-07-30file 8899177.docdoc 0a9f914ca755dfbf80dd6538c03d01cbcfeededd66ae48baedc5bd1f94e27ee9Virustotal results 50.00%Heodo
2020-07-30dat_20200731_4540.docdoc 80565d4ed000d2c561645c79096f5e2fe04ac3f5c7e9e34ac68cb4ed9306ceabVirustotal results 50.00%Heodo
2020-07-30FILE-20200730-MSZ18986.docdoc f750390b091965033d74cae96cd391a3a3283edd4d3eb524aa9a3576fb98a08bVirustotal results 50.00% Heodo
2020-07-30List-2020_07_30-690.docdoc 94edc6ca93bf52aa32d4a4c5ff3382b0a1e1b39e3b234ff48354551d37aecbafVirustotal results 47.54% Heodo
2020-07-30ARC 20200730 4376340.docdoc dbdabc0245226588757dd5317307e3e4d7307b6948dc4c467a1dbff0231e7e0bn/a Heodo
2020-07-30file 20200730 10629.docdoc 91ca93061d052a14b274339763d741aff2307339b9285e4cdc47bd58597dcd55Virustotal results 47.54% Heodo