URLhaus Database

You are currently viewing the URLhaus database entry for http://tuffgreenlawn.com/live/sites/JklLIrXA8uRLcj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:610084
URL: http://tuffgreenlawn.com/live/sites/JklLIrXA8uRLcj/
URL Status:Offline
Host: tuffgreenlawn.com
Date added:2020-09-24 14:07:05 UTC
Last online:2020-10-08 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 14:08:03 UTC to phil{at}belugacdn[dot]com)
Takedown time:13 days, 23 hours, 35 minutes Bad (down since 2020-10-08 13:43:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-26INF_2020_09_26_6242.docdoc 4893d5828613a7b157505151182a80ad894439fe4f65ebeb87fcf641880ca47aVirustotal results 51.92%Heodo
2020-09-25Attachment_853.docdoc e55b497502188dc8b8da281b3a2e03550c1ff2299b5d45e61f51502706652bcbn/aHeodo
2020-09-255959603.docdoc a49a7d5867195b7929fcaff3660cb0c4eb2681e413ec18f9f6fec4978e3cce9en/aHeodo
2020-09-25INF_IUD721941.docdoc fe890849b50a3266c007ef8b917afc54bed8de8c8630f33cea2fb0d9d6bbccaen/aHeodo
2020-09-243196288-2020_09_24-7609.docdoc 6e66d8867c0662cf0e56a6f089023982569672f6775772dc6c4015e6a65f25c8Virustotal results 24.59%Heodo
2020-09-24INF-2020_09_24.docdoc 951d6f18d680fd8bee849c739c1e9b2da02df8baa9230ab6c74266f3bbe444fdn/aHeodo
2020-09-24mes.docdoc 48dcbfc04efdbf5c4e3c2ab520e718e34fbdaf95d38ffbdf469d4e40e850cf5dn/aHeodo
2020-09-24SV0280 2020_09_24 36744.docdoc 6ca4c4bc99110bba835cc64055378d05d0ac578abdbfb73fd3b4bfd9958123b2Virustotal results 33.90%Heodo
2020-09-24ARC-63372.docdoc 3db5537afa72bac1ad7529d5026dc4962d42b2e6af1cb12235cfc1f8751676b5Virustotal results 32.26%Heodo