URLhaus Database

You are currently viewing the URLhaus database entry for http://leblon.com.do/profile/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445234
URL: http://leblon.com.do/profile/invoice/
URL Status:Offline
Host: leblon.com.do
Date added:2020-08-27 14:20:06 UTC
Last online:2020-08-28 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-27 14:22:02 UTC to abuse{at}linode[dot]com)
Takedown time:13 hours, 34 minutes Good (down since 2020-08-28 03:56:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-28BAL_QG3868985649XL.docdoc f0f0ab7a04453d0254724613cfca62b5ec613b5af5b11183af648ad8a558a47cVirustotal results 32.76%Heodo
2020-08-27FILE_AXL_080120_BHK_082820.docdoc 6c11c295ca138decdc721470c867b1e45723acba612bfdd37a226cbe2b200b45Virustotal results 32.73%Heodo
2020-08-27REP_PO_08272020EX.docdoc 49b0709d22536eb3ddbf6b3468a63cb48491a014a7895436ceed6e3749888f5eVirustotal results 33.93%Heodo
2020-08-27REP_Q5LP6WL5MP8F4.docdoc c0753298252008cea783150f24c9245a600020cfb03c4832b57be156bd3ec96bVirustotal results 32.76%Heodo
2020-08-27603748714416901992.docdoc a943fcb717ffc0c4a656e231f7fc21bcfc04099db295369eb1b66b86493e9b7dVirustotal results 32.20%Heodo
2020-08-27INV_JXG_080120_QMY_082720.docdoc 16c7a22b63e70322f5531e616e5cca7114e5b92a37ff13669587c767b02b58e8Virustotal results 33.33%Heodo
2020-08-27PO_08272020EX.docdoc bc43939828fd6a1666c50e5e4976c5f62968fefcf20351b2e0d36354e24afac6Virustotal results 32.20%Heodo
2020-08-27REP_AR7421673227ZW.docdoc bb699717744f27bea319547bf28c60bf7f8f2e77ba8b4af89e00f5b6aaa09f5bn/aHeodo
2020-08-27DOC_VH4356928450OC.docdoc 72a047a55409445c1767467b0e67391b0fbdb99be5b2e6a5457df52c7e2ef398Virustotal results 38.60%Heodo
2020-08-27AOG_QV6238291725CJ.docdoc 46bcca8c7bcdecf0bc7ca571bea317f1aadbab8a0d93d7ed83f54c41adcca87dn/aHeodo