URLhaus Database

You are currently viewing the URLhaus database entry for http://leendesmet.be/cgi-bin/n9z/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453276
URL: http://leendesmet.be/cgi-bin/n9z/
URL Status:Offline
Host: leendesmet.be
Date added:2020-09-04 12:26:17 UTC
Last online:2020-09-04 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 12:28:03 UTC to abuse{at}nforce[dot]com)
Takedown time:2 hours, 47 minutes Good (down since 2020-09-04 15:15:13 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-04uBPrsrDCytHnqan8va.exeexe 37447cd31ed53110d9da9011bf2dc118ec4a5fa28b517f50c24d6287aec26c03n/a Heodo
2020-09-04rj3UNoSuz8Ew.exeexe 9141a0eda09d2e2e2b569393d977f04ab64bf3f858adc82b0a47d658066fa850n/a Heodo
2020-09-04m7.exeexe 8cc72dad8812447cd07e513fde612984a7024995239378586c98a42ab796dd6en/a Heodo
2020-09-04Fu8DWS.exeexe 11c957514aeca3081766929932efeaabf4e43b3804678825c8bbe86c1df6a3bfn/a Heodo
2020-09-04U5XeoIx1UAV.exeexe 1bb0d42b02ab5dc8b521c144c3cc37ee3f20bb1f8a91d36a66f5b87bd9d12074n/a Heodo
2020-09-040NO5p7iJv.exeexe 4e00a55203265a9d427863f2b932fa94b25029df784b1622ca0ba34a5a74d877n/a Heodo
2020-09-04d7cQmLgIj9V.exeexe 3eb8f2c72d7ddfd1a7794040ad4668ab2bc861da57dd0a8aba34b04accb93876n/a Heodo
2020-09-04zM4N0sbBTSeAxARGj.exeexe 7a38be2b37c15f42269a1dd7c4cb104c4d1939144e704cc93b0a16e878304d8bn/a Heodo
2020-09-04kpFcJFM8QtZAhdoVRIo.exeexe 5ccafda21e1c067fcea5621450904176361ca14b20f04a9664ae290bd842d74bn/a Heodo
2020-09-04BX.exeexe fa30a8b59a3c4fe64426add1522b8538c14b419c6fbfc899f4740d6dcc36b7ccn/a Heodo