URLhaus Database

You are currently viewing the URLhaus database entry for http://legalaawaz.com/wp-admin/http://Scan/NeIJZJc2Q6U/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:495842
URL: http://legalaawaz.com/wp-admin/http://Scan/NeIJZJc2Q6U/
URL Status:Offline
Host: legalaawaz.com
Date added:2020-09-14 13:07:07 UTC
Last online:2020-09-29 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 13:08:45 UTC to abuse{at}hostinger[dot]com)
Takedown time:14 days, 12 hours, 16 minutes Bad (down since 2020-09-29 01:25:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14DAT_293.docdoc 3dc5285bec0496d0a4993cc2a0d80e534010b345115320b8b96343b8ab9b10e3Virustotal results 20.34%Heodo
2020-09-14Attachment 20200914 6487485.docdoc c97df0581f5b0b143567afac2ce6e6580a80ab58c283cbb27e706dbbc194bbe1Virustotal results 21.05%Heodo
2020-09-14Attachment_2020_09_14_58703.docdoc 383354c8056fb386a9af9f40c354846726ff04165ca01390075eeefad8c28faaVirustotal results 20.34%Heodo
2020-09-14REP_1032.docdoc b7c1d330ae0704a55e88453febc87487493166e74f41e8858126b915c055ed5cVirustotal results 21.31%Heodo
2020-09-14Attachments_20200914_32478.docdoc 31948483fc5ed6d49d09367c9dd1e1d602a0124ce7f4758a4ec04c3c9b71c2fbn/aHeodo
2020-09-14DAT 163300.docdoc bb6a3ee26f9149b198a32723d6d5426533b1594c905789aac7f97296e2cd0624n/aHeodo