URLhaus Database

You are currently viewing the URLhaus database entry for http://lighthousehealth.nl/cgi-bin/lm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437111
URL: http://lighthousehealth.nl/cgi-bin/lm/
URL Status:Offline
Host: lighthousehealth.nl
Date added:2020-08-20 08:03:04 UTC
Last online:2020-08-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-20 08:04:02 UTC to abuse{at}godaddy[dot]com)
Takedown time:1 day, 4 hours, 47 minutes Poor (down since 2020-08-21 12:51:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20KPS_TCF_080120_PTP_082020.docdoc c57a4ab4e5c80b5cd6551c5927e4a052aca796d0dc0e9ee1f0e18308fca78605Virustotal results 23.33%Heodo
2020-08-20PKS_080120_LHO_082020.docdoc 6a447a70db4f2e7215f33631662611d615c4f4bd0e2b31baff0fa75c3a8d970fVirustotal results 23.33%Heodo
2020-08-2022012856.docdoc 370f13258c923be12a4ce1b761f231bb3cb640389f75c77b5a50180cf21b221aVirustotal results 23.33%Heodo
2020-08-20FILE_12062117.docdoc 3da591c1f30346def38ac8250002af997e551d7becd721d5e5a5496dfb26e236Virustotal results 23.33%Heodo
2020-08-20BAL_QZT30IJ6LOS.docdoc ecb3b2b9316416b63637ef7d6897153212d96e0eb618eb31054cd49b23934ac6Virustotal results 23.33%Heodo
2020-08-20TFUL_DD7301686919VJ.docdoc 7fb67aa831054759be82023e44384c4b66d597c530c373dce100d90456da55a4Virustotal results 23.73%Heodo
2020-08-20TWZ_080120_MSS_082020.docdoc 3950245c4b02b5b36cad1f7785113bb4312d8afd9f6106882f29d16a80a6735bVirustotal results 24.14%Heodo
2020-08-20PO_08202020EX.docdoc c128930805475cc08cad774225a789ee3c5c540905ced9d87342acdb10b007e0n/aHeodo
2020-08-20VVE_080120_KDI_082020.docdoc 667bb3ab13aa4efa45244b943c39bd6a1309d5c91b5656c73a5e8fe5350fcd7cVirustotal results 21.43%Heodo
2020-08-20FILE_201007471807866.docdoc 415ba65e21e8de9196462b10dd17ab81d75b3e315759ecced5ea8f5812000c1bVirustotal results 21.67%Heodo
2020-08-20REP_PO_08202020EX.docdoc 2fc7d5cc2fd5f00fee90b4d1d265361efe6e1df4f8a82427b7b0bd72ba4ae9a2Virustotal results 22.03%Heodo
2020-08-20REP_KD0905928017UJ.docdoc 65bd1b927dcce32a7171cec9e1e26732660728495e44d5f85a73f898aa2186d6Virustotal results 20.34%Heodo
2020-08-20024349139869475459774.docdoc 42b7f25c4a31dab88b3c821c55354cedad18b8b81e8785bebf31b5ddd3f1d9a3Virustotal results 20.34%Heodo
2020-08-202403054256817438820.docdoc bfdf3c9957775bcbc77fd32ca103eb77c0d7ce345a27bde62c3347647ad94a06n/aHeodo
2020-08-20FILE_PNU_080120_VHR_082020.docdoc 6a1d4f7d099b5838523267a6171d718e09385c8ad15f2cebc47a4fdde9b1d6edVirustotal results 20.34%Heodo
2020-08-20BAL_98677512.docdoc ffcb336fb1265e56e3ab3a0a1fd778031732ce4193fd6695ccb644e914feae92Virustotal results 18.64%Heodo
2020-08-20AIH_080120_EXE_082020.docdoc 6e647b837da2262825372b4fb5ccf78f780e467cdcc593c348153bd1619dbf86Virustotal results 44.07%Heodo