URLhaus Database

You are currently viewing the URLhaus database entry for https://leadiasjunior.com/wp-includes/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624604
URL: https://leadiasjunior.com/wp-includes/invoice/
URL Status:Offline
Host: leadiasjunior.com
Date added:2020-09-29 19:07:34 UTC
Last online:2020-10-03 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 19:08:06 UTC to abuse{at}hostinger[dot]com)
Takedown time:3 days, 10 hours, 32 minutes Bad (down since 2020-10-03 05:40:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-01FILE_HPG_100120_QBT_100120.docdoc a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47Virustotal results 38.71%Heodo
2020-09-30INV_4924898441455094842280.docdoc 896b1086164f16900fa21fd364f85761da882abeb87573d0eac49e7dfaf2524bn/aHeodo
2020-09-30PO_09302020EX.docdoc 0bffbb268223d255d4ebdcee53bd0d8e990843600bf96f811f47a550d1e366can/aHeodo
2020-09-30DOC_PO_09302020EX.docdoc e2689c227ea6d5424060e6fce6deab414a52c4d27719a2a2f4a2b9eb635d4f9an/aHeodo
2020-09-30REP_212798624.docdoc 797ac0be9b6e1c912dab41fdf6c487642e027c1a24c2a6510ee3a1a326ef7bb0Virustotal results 37.70%Heodo
2020-09-30PO_09302020EX.docdoc 0594dad5ba161c51ba71ffbb41c36696b151edf4d1d7738b31a026cd28164a4dn/aHeodo
2020-09-30OHDJ8DQ1MW.docdoc 8649c9f23563646d5b0033bb729307388ddb4396da639cbf0385c08ec0a01cffVirustotal results 32.26%Heodo
2020-09-30PO_09302020EX.docdoc d56585c6e4a0ede125061be754c5a0c9b45728232d4c61937ffbc047df3aae30n/aHeodo
2020-09-30DOC_DJS_090120_JUC_093020.docdoc 48e23cb77f6629ddf1c1b70ff1af00789fe9ed39014db2e97b4be24c2e13a168Virustotal results 30.65%Heodo
2020-09-30RQ3733659411JV.docdoc 4a9f3550003b6a5732c04dafb0112c4a68a0e1b9b00f0244bbf65efc7561823eVirustotal results 31.15%Heodo
2020-09-30INV_PO_09302020EX.docdoc bbbd4c73bc383a0187533459a3e99105ef733893b116bda7aebf13a371dba532n/aHeodo
2020-09-294913355963973.docdoc 5bc9314961b874f09854775cf9f6bce09cc9c8106200074edb961cd544efb675Virustotal results 30.65%Heodo
2020-09-29QZ7769044396PG.docdoc defbca721d5850239ce954155a629ed1728ce578781b3e387d8c6305144f0838n/aHeodo
2020-09-29REP_JVK_090120_NCM_093020.docdoc 5d9881c8900498814ca049d263ca3339b113198bfe781ccb5e5ffbc2b23eb325Virustotal results 30.65%Heodo
2020-09-29FILE_41106287.docdoc a863d09af176344fa94c7820a54398bd505f2ee93f7f66a6f05d3e60b71479ecVirustotal results 27.42%Heodo
2020-09-29BAL_MRN_090120_LCV_093020.docdoc 16b031e38044afa7252dbfb56c762b3723de1cb4b3535a8c76bd5d4f10a2819bn/aHeodo
2020-09-29INV_0586327232003.docdoc 0581f0969b158a86c635f6c5a3931c57571aaaae1eb93475efeb0fcb6a99d1f9n/aHeodo
2020-09-29REP_SG9645735056WK.docdoc 33c16dca57826043e0e0e906d157fcde3b15178d62747fe0ee0f10f1589d9498n/aHeodo
2020-09-29FILE_BD9PGJ4KLK17YMCI.docdoc 5ec415733e64c05854cc229c0978d9da72b7615bb092d7cfab7f2b36059af466Virustotal results 32.26%Heodo
2020-09-29J3LID71E.docdoc 0242549ebc92f3e40e21ec852316e2a5e84ac870bf1a1a571ba2dee66ecb2128Virustotal results 32.26%Heodo
2020-09-29L_PO_09292020EX.docdoc e8bc44088ba55cb58a8611c777ab11528143331cfc47bbb9dfcb92342f70696bn/aHeodo
2020-09-29D_RITP682DCXEG0MD.docdoc 2e997b7baaa8519fff2a756670247b75a5b9fd00addafb830d7ad6ebc7ad18d1Virustotal results 32.79% Heodo
2020-09-29FILE_KUA9LHV4YJGB8ATM.docdoc 4c12091055b16db3d329d221e16a7de91f9dbc93593c907716507d7e3eeb8a53n/aHeodo
2020-09-29INV_PO_09292020EX.docdoc 767c5236fd7a0daa1058773f0243a7f1f3548fa0579f8020ade8ed117c9530cdn/aHeodo
2020-09-29A_2ZGUV7R5ZMZ094.docdoc 9243618e3533ddf75d1106555b3aad908b5a34d8ae7a1065a683bf73e6b21a4dVirustotal results 31.15%Heodo