URLhaus Database

You are currently viewing the URLhaus database entry for http://lezliedavis.com/swift/paclm/0663/s4xgyrxgnat-0047597/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438099
URL: http://lezliedavis.com/swift/paclm/0663/s4xgyrxgnat-0047597/
URL Status:Offline
Host: lezliedavis.com
Date added:2020-08-21 10:01:03 UTC
Last online:2020-08-27 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 10:02:05 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:5 days, 14 hours, 32 minutes Bad (down since 2020-08-27 00:34:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22Electronic form.docdoc d264878eae29d3da022f38e67a38560346ba42cbb6dbebbf0e6c852c666fb1acn/aHeodo
2020-08-22INV_76847.docdoc 6f6e1037eabcdd4495abaec04471ac97398c57eb88493b324e2d89ad9bd7af08Virustotal results 38.60%Heodo
2020-08-22Invoice #8406.docdoc 564105a864ba17349c0c70d8c11883b4edaf7b9f653bc074d57ec92e33923d61Virustotal results 36.21%Heodo
2020-08-22form.docdoc 5d343c4cc60ceae7c55758376842b90845f6d3dd1d7ab8fd2bed44ee745bf527Virustotal results 37.93%Heodo
2020-08-22INV #0261799 FOR PO #080785420367.docdoc 88fafca4b3195bc1843721aa1d78221a5d05be8d88f43ceb0e85aab917c67a43Virustotal results 36.21%Heodo
2020-08-22Electronic form.docdoc b199113c89d1f14f205054c9a7cce7b661199224054e035b6f5044205dc27cf8n/aHeodo
2020-08-21Form.docdoc d09a4703239b8dd258d5174bc65647fa6b951cecfcb7c2f9c46a29a061a7a769Virustotal results 36.84%Heodo
2020-08-21Invoice 26607.docdoc 31ef2257cdb7b9006892fb9754673511beaf648f6c3a899b9bff3031310a9acfVirustotal results 37.50%Heodo
2020-08-21Payment status.docdoc c7abec97a993780d8d6bdd8fbc2a7c77bb49fdd61e57637ac36ecefc9f748350Virustotal results 35.59%Heodo
2020-08-21INV_29652.docdoc 2d4370eba117c88617870ab941572195d2facde4eb4e1d768507d37840812da2Virustotal results 33.33%Heodo
2020-08-21Invoice #7798.docdoc e5c9f8c0ccfa47835d30be512636ad1b0e40d75587d5a309f586b67796aae5cdVirustotal results 33.33%Heodo
2020-08-21042564769.docdoc df8d09457a129b57c4740b237ac226b0e0245d035dc20930563bab681e98e8c9n/aHeodo
2020-08-21Invoice #64470.docdoc 43057d3c74a6fbe3be2660879e861ae3d0b2118866abb1e3fe8bc169c526d957n/aHeodo
2020-08-21Electronic form.docdoc 214116ae52ad96af88fa41e0ea271fecb493e2afbc403bc3ca2c184ffd03d996Virustotal results 32.76%Heodo
2020-08-21invoice #9214.docdoc d594bcea91f0259160c0122a56ad8ec4a7896173295fb3b2c197781cb1bbfddcn/aHeodo
2020-08-21Payment.docdoc 83e013279f45dc89d5efc3717634b746a611baee472756272e91e1673d8fc3efVirustotal results 32.14%Heodo
2020-08-21Inv_9770.docdoc b43df5c0df066a651a976b156ca480e58acf3b61caeb45c08fadfcdb82e46addVirustotal results 31.58%Heodo
2020-08-21invoice #892787.docdoc 5ad1d00e81e5e6bbc93829790980fabae6eab63a8638ed9bc024a27d083ffb87n/aHeodo
2020-08-21Invoice.docdoc 43638c344ac4a446af722c229682fee9a8434923ce1cf6dd1a19bd2a0fc78c21Virustotal results 25.86%Heodo
2020-08-21HN046 invoicing.docdoc dfb4a0445bee97a362ee8ea96a3cb6444bc3ef4b7c96beaa5edf0508e6343c56Virustotal results 25.42%Heodo
2020-08-21form.docdoc 4ab72d91d0e85daec3f451ceb24b75e35a698aec75707fa853f10d780396df0dVirustotal results 26.32%Heodo
2020-08-21INV_187482.docdoc 583422020b6a3b13f25301f8010f577f735b052fc27666b44a6f860493f38f49n/aHeodo
2020-08-21Copy invoice #84674.docdoc cafc557261c0f9e0e43f24e43efbf14505b54d38271152c48e4a6dd3279769c7n/aHeodo
2020-08-21Inv_812880.docdoc 337fac0cbc61c0f73258d843a4a64b68b825d45037b7339ca2ab659fe3e15912Virustotal results 25.00%Heodo
2020-08-21Inv. 967632323.docdoc c6c8fb9bb0d155bb4fe8b4b7904de586efbf5c79f49877313b380b848ad12da1Virustotal results 27.12%Heodo
2020-08-21FK057 invoicing.docdoc bb998fa7586d496812a6964a3bd763b2b57c873cdabee67f841f6700e6bd4e34n/aHeodo
2020-08-21Invoice #94001821.docdoc 224d0b30bfff0d484bbc3b3cf1f7a97443aaa5656865fa5af8a3d545b3d5048dn/aHeodo
2020-08-21Copy invoice #703848.docdoc 7bf19f22efc3105310b2bf37df600a6d3bb4d2136d4ae4c7e0454ffbdb3939aeVirustotal results 21.43%Heodo
2020-08-21INV_524929.docdoc abedafc5e19de68937c53f7be30c1b392975062ba9a11d34a991ca703cd3c578n/aHeodo
2020-08-21invoices 055 & 70784.docdoc c50a12add2e3c75f860f563d042901761cb7ec0a2f4fa64ddc37c1dbbef8bbcan/aHeodo
2020-08-21Payment status.docdoc 21d54929d53a038a86a56cb5069a4769a462b032d74d222eccef96a97e9d5a8dn/aHeodo
2020-08-21Invoice.docdoc eeee33ce9e2286f03410cca48f68b1eac155b167eb430f7cb01333cc359a4d4an/aHeodo
2020-08-21INV_192739.docdoc ba4bb5f049cb59a1eb23f083cf22fe726a7d87f12e9b577f2eb52102b55496bcn/aHeodo
2020-08-2199112.docdoc b2c79cde6af53d39ae8ec8a5c9877900b803c94d70f8f7310ca1cf331d43ef15n/aHeodo
2020-08-21Form - Aug 21, 2020.docdoc d646ef25b1534f5efd3f042ecd13325dca48d60766ef904011a30390c1740e09n/aHeodo