URLhaus Database

You are currently viewing the URLhaus database entry for https://lggpm.live/cgi-bin/Yq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:535281
URL: https://lggpm.live/cgi-bin/Yq/
URL Status:Offline
Host: lggpm.live
Date added:2020-09-16 18:00:35 UTC
Last online:2020-09-16 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 18:02:16 UTC to abuse{at}contabo[dot]de)
Takedown time:2 hours, 51 minutes Good (down since 2020-09-16 20:54:05 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16IKLHBVtUE4z9ImrN1sTaJ.exeexe a08d313886929d1efb96d55751a2ab1a9a21b40a089b643b08eb6f9fb34855b1Virustotal results 19.12% Heodo
2020-09-16qErDYoBlWFtUA3n2nO.exeexe fd5de4cc19b310e2785139fb223d2dbf6d79d0d36a8dc512a0e696615ae3d4b8Virustotal results 19.12% Heodo
2020-09-16hgteUyDXoapo9M.exeexe fa5458a8dee9ef3439f8d0ca9edd8a107ffabb87ac3498ddb44e9229ee5c28fen/a Heodo
2020-09-16vJXhvo.exeexe 68e41def7665f009a28543d324274cbc46fa581fe39d937b72cca145cc32bee8n/a Heodo
2020-09-16Mk5J7R2eX4q.exeexe ff725cfa04d7d0b903d3fa6d6c49da0590b6fb458c85c3159f15ae64753f56d7n/a Heodo
2020-09-16rm8diXNWQfn9rLle.exeexe a05eee272d05d68bd6ef11caec57fc6d6ca7e94cfda09671819d882f1a06d44fn/a Heodo
2020-09-16beZ8LJs4f.exeexe 06e7eb13939350431cb5b26825f186e6b248e5825a34a08f9ea6a9bb3e8ab77bn/a Heodo
2020-09-16XDL3sLt97.exeexe c7af60898d2b5fbffedddc798bcdde7c0b848b309bc173986a2ab909b015499dVirustotal results 17.91%Heodo