URLhaus Database

You are currently viewing the URLhaus database entry for http://lgonlinecenter.com/leverl/bu-q0cwt-1964/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429721
URL: http://lgonlinecenter.com/leverl/bu-q0cwt-1964/
URL Status:Offline
Host: lgonlinecenter.com
Date added:2020-08-11 21:47:13 UTC
Last online:2020-08-13 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-11 21:48:11 UTC to info{at}veridyen[dot]com)
Takedown time:1 day, 23 hours, 35 minutes Poor (down since 2020-08-13 21:24:09 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13InvoiceAXZ23247438711.docdoc 9c555a84e2b325b4c2d60e9dba477c087791380312f4c5c664d3ab4f1c47ab86Virustotal results 31.67%Heodo
2020-08-13INVOICE-P124-62396700.docdoc 9cf677f5a27b277fc9af936f45fa6f2d17dae6d17d01ac701bb52a6b8aa6cce0Virustotal results 32.20%Heodo
2020-08-13INVOICE_M688_6281857.docdoc bbb9fe86aa40ba295e0be4880de0abbfa638f492114049528e83d17b67a1dceaVirustotal results 30.00%Heodo
2020-08-13Inv-LEZV07-25475750.docdoc e72282cf5896d2a6649446f6023b34c7d71ba08f5be3bb0def9185fa742c3deaVirustotal results 30.00%Heodo
2020-08-13Invoice BSW7174 21644345.docdoc bc8eae589f288288973220fbb7fa40b5ff4be240e0835dbbdce92b9f3bd02ac7Virustotal results 29.51%Heodo
2020-08-13INVOICEYBPU03953267.docdoc 76149a3b59fe79492a16a9a3d94dc59e1759885a245cbb685d06de9a95f7278eVirustotal results 28.33%Heodo
2020-08-13INVOICE-MN54-20488424.docdoc 52c981dcee0a9c0bc80ec192b453e8af6b01ced6cb3187645687ad0fd1b13221Virustotal results 27.87%Heodo
2020-08-13INVOICE_M23_7108837.docdoc e9bc4332a3fd2de13d8f4d58aaf749131a93e652fd663f83005b1437936a715eVirustotal results 28.33%Heodo
2020-08-13Invoice YEJ2438 65759664.docdoc 7689a27b894cae744cbcc6233ee883c95f92853ce314becca2b0eb1428689c49Virustotal results 27.12%Heodo
2020-08-13Inv-KBBY4-1157772.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Invoice_EO550_418160.docdoc b58536809fa841324f6ebd181e66c4e897843b4689a45987ba00691b7c99f35cVirustotal results 25.00%Heodo
2020-08-13Inv-EYNS75-46182993.docdoc 780339401d94d888dd79a9d81b94ead083dc9070649cdf2e72eb3a6a78eb45d8Virustotal results 26.67%Heodo
2020-08-13INVOICE-1-61397268.docdoc c6448d3ae149d4be02cc47863725d1c6422455e424cc378cc755ada5109d76c7Virustotal results 26.67%Heodo
2020-08-13INVOICEOT3762277759530.docdoc 0b9983bedd5702a9bf94c237a85fdcf11a637f0212b8ab32dc746da8a2a62148Virustotal results 25.00%Heodo
2020-08-13Inv-KGCZ6138-673039695.docdoc f844331d28cf2533981a9e753d6df2e9677efadaeea9b2c014266991ae78280fVirustotal results 26.23%Heodo
2020-08-13Invoice0763882794.docdoc 642f6238f4c26f7e8829b4739309809c5b2ec80f58e0beb4df4cbfdfd8ebe42aVirustotal results 25.42%Heodo
2020-08-13Invoice-IJE2-052432758.docdoc 43b13b874d7ccbe6821d27e5a403e6415ece6d1972ad7409f6f294d1bce52112Virustotal results 26.67%Heodo
2020-08-13InvoiceS5843203434.docdoc b858572fbe695215c2aa6ade7ada24c980392ad2f5c9e3564d4e6446ef424383Virustotal results 55.00%Heodo
2020-08-12Inv-ZSUM078-097334.docdoc 9b5d7e0c6ce7b00011f1c9fa7157bded3963629b18e4b79469bb62c84e80a312Virustotal results 51.67%Heodo
2020-08-12invoiceM035834176928.docdoc d60d130c4369c7d41edf041927897b2ceb6b845a66b97bfeb0cf7d60575fe399Virustotal results 47.46%Heodo
2020-08-12INVOICE LFI194 786105779.docdoc 27f5a6d1c03ee22b1c20250a5cf13fc46584715e452dc107d3f7263371a96809Virustotal results 48.33%Heodo
2020-08-12INVOICE-1399-4696983.docdoc 24b41c6091602c0f9df9cc64905ce9dac977a04f700ae0607de467c101a093dcVirustotal results 49.15%Heodo
2020-08-12Inv YDKK4 78013673.docdoc 0c7d085dc88b57e56819a0a9319e1aa089ad9851a0ea21137aab6309395ed039Virustotal results 49.15%Heodo
2020-08-12INVOICE VS8 691743029.docdoc 8f22c5b8a56662958bd763c2384e43945178b03a9f9736e8bbaa814451cc9451Virustotal results 48.33%Heodo
2020-08-12invoice-TRX6815-2295241.docdoc 87a59fdf7ab0abb1c6263fc0c53650659aa5c3d50d09d38c6696819017787e38Virustotal results 48.33%Heodo
2020-08-12Inv_9343_399641869.docdoc 42eacf30bc2f17cd5c7fab970199ff08189d908cfdebacb920bbb88c356d92cfVirustotal results 50.00%Heodo
2020-08-12InvoiceYHL831398163.docdoc f2414110e5d69a3653a43f580b5a599f99245d0492065654a44a6d46529eed3eVirustotal results 45.00%Heodo
2020-08-12Inv-2-6140806.docdoc 3ac3af554f63c5c308ab18407e4d3aa155f7a2ada7a3be3b6bda7eb71fde450cVirustotal results 47.46%Heodo
2020-08-12INVOICE-HA0-1397092.docdoc 7ddd9bdcbe8ca80a8ffa5bdbf8ad1e388522433cf9925d2686ce9e3295c9bba5Virustotal results 41.67%Heodo
2020-08-12Invoice_XCS328_9599036.docdoc ae4e6ac684f5b88e2165adea2e0df977852b853b20d129fae3d53600eebeca8cVirustotal results 39.34%Heodo
2020-08-12invoice-LPAQ110-0363299.docdoc 46fed267e7c6021ed463ca677ae1723631dea7e71a831436e0dda8fed9cbb552n/aHeodo
2020-08-12INVOICE EPU516 0176627.docdoc d38dd6d1f7f64159fb3a29df7e5c78123b2cae316e479623072837fd852874d8n/aHeodo
2020-08-12invoice-IB80-10763811.docdoc 7e80fbe683372b02372090968d9795df4d7683ce0f8691fc8a8efc25e49364d2n/aHeodo
2020-08-12INVOICE NZ43 491747.docdoc a4b8da2397aa872bf9a58f4ccc3aac1d9048af566659687b5cd8cc7c1c72b7f5Virustotal results 30.00%Heodo
2020-08-12invoice_Q860_767185127.docdoc 04c3ee92415cfafc302333e952bebc0d791a327e3227b22689726ff4de2357acn/aHeodo
2020-08-12Inv-IMJ3-874410.docdoc 58e99da90bc92faeff54c3c395483bb8140c2e586cb53ecc349fc87ee90cac23n/aHeodo
2020-08-12INVOICE-98-129436.docdoc c07b5e469c2e5394b5cbef04fcf93c830b4426bd340c19a901a528f0378213c2Virustotal results 30.91%Heodo
2020-08-12invoice-FZ9327-060832.docdoc 2eed3a8cd7264c4e5e286048d5cb139808f8c21fe67311edb2f743f85e4700b6Virustotal results 30.51%Heodo
2020-08-12Inv O76 1275369.docdoc 08d1bd7eb9b7a4ff987f2d3825da852bee8259128948a327f78e7b1b843c3e8dn/aHeodo
2020-08-12INVOICE WOO0 9129473.docdoc 42355a35a2bf3d690fed99b24a34a5e6cd67fa3c21c20e7747d01a1f71d998ecVirustotal results 27.12%Heodo
2020-08-12invoice-HTV1296-71086215.docdoc 92891d0665902ca174cc6ebf4cca8fec9d9486730b7796e2c4c63b5a2f29ab8aVirustotal results 26.67%Heodo
2020-08-12Invoice-X68-536973.docdoc a0cc5c1b5719f2747bf50cf50c3c6416863a25fd52bfd960cb679beef7e6b2fcVirustotal results 28.33%Heodo
2020-08-12invoiceP574711720.docdoc 0e8a907717e28fa7dd8fd51ac5cce01762d73113c64dcc2c713e65de4e2787ccn/aHeodo
2020-08-12Inv-IRLD2897-5849136.docdoc 67f8bf7d4315c662fef2cd8677c13df8c32bce2d486e47610402d81436c1f696Virustotal results 27.12%Heodo
2020-08-12Invoice-HTH1-936025413.docdoc 3878a507270346a9cb72ef10f715fea30a403ceb12326e565fcf4e03abb874edVirustotal results 27.12%Heodo
2020-08-12invoiceXIKD7616143.docdoc 7dd439987c7b56a1968a7037a72c4d2474cb03e2dda132f07275fba3ca216685n/aHeodo
2020-08-11INVOICE-PBH95-280818.docdoc 19c60452fae42f6c268705bde00ef94bed83022e4969001353d14549fa028fabVirustotal results 51.67%Heodo
2020-08-11InvoiceIRT9945835628569.docdoc baa7ec55d76e7be67f654211832accb7b7352442fefbadd3a4047e63adcc24c1Virustotal results 50.82%Heodo
2020-08-11Inv-WEZ6178-765869.docdoc 98c981a420851abdca6108f1264153f000a93d4efb36a2df630d0fb91c63aaean/aHeodo