URLhaus Database

You are currently viewing the URLhaus database entry for http://grahamlegalpa.com/wp-content/lm/ep25e77ow3dlhjtu54tthepaihv0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:704129
URL: http://grahamlegalpa.com/wp-content/lm/ep25e77ow3dlhjtu54tthepaihv0/
URL Status:Offline
Host: grahamlegalpa.com
Date added:2020-10-16 21:42:04 UTC
Last online:2020-10-22 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 21:44:24 UTC to abuse{at}inmotionhosting[dot]com)
Takedown time:5 days, 22 hours, 1 minutes Bad (down since 2020-10-22 19:45:40 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17GELY_ZL8165314909YN.docdoc 360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134Virustotal results 53.23%Heodo
2020-10-17LISB_BD7V48LCZ51RRM3Z.docdoc bd5e318573106192eca830985c93ad07583928c7ba9b1f752ee5ce3e38eea593Virustotal results 53.23%Heodo
2020-10-17BAL_PO_10172020EX.docdoc b61cc94625d0aec1674d3ffb90ade5b30575e1eb8a755f9944cfcb4d40378041n/aHeodo
2020-10-17HF3694736749XP.docdoc c5b951c65f67f1136dedc670dfa0cf0fe59abb9172a0fe5a6011e2882e129e8aVirustotal results 54.10%Heodo
2020-10-17UVU_FP8776239199MK.docdoc 83af4eee8013969fd28932937f24ed1bb6031013a525dcd161ed6914b41feba5Virustotal results 53.23%Heodo
2020-10-17DOC_61206710.docdoc ab13f6f95154d0396465d9bb9d42e49708e2efdd49c259b7189ae2c7c7c2d389Virustotal results 53.23%Heodo
2020-10-177VVT3TAC5TXW1.docdoc 8eed16b7e0a64351cb06ea437eeae8f69b227cac04237187ed17cff470a3cb0dVirustotal results 52.46%Heodo
2020-10-17DWIE_9135039855940840353799679.docdoc 9fddabb44e0d01bdc8e0886790e1e34059ac1aedbe3faf4cdfa66bf9dec923cbVirustotal results 53.23%Heodo
2020-10-17PF_71566556.docdoc ff9996026d66c80170010bab3d84d0ba1ecac3a6b87f8e694008feb0bc0b3d4fVirustotal results 53.23%Heodo
2020-10-17INV_138162387479448.docdoc a9c15187e473446421b0e900dcd094ee8be1c5ac010d6d2a19bcc988f60d7ddbVirustotal results 53.23%Heodo
2020-10-17FILE_328135629139076276980.docdoc cab952f8c6436054516b7fb9b6dc980a0921858a4a312229099f2817b9846340Virustotal results 54.84%Heodo
2020-10-17FILE_EE8333765714CN.docdoc 9e5f94414bcc33c4f9405dd2c0747ccc8c79921dbaab834a1ce8cd0205bb1f9bn/aHeodo
2020-10-17DD7232856027KV.docdoc 6d5ed047cba0f40a2bd108fdb285520a5590c29ac64b7a9d32a20719905f1e7cn/aHeodo
2020-10-17S_SLI_100120_NZY_101720.docdoc ab8be8e21a7c5f0a158818bdf5fa9883acaffa78d8cfa5cae36ba7d756b8fed6n/aHeodo
2020-10-17DOC_17196170.docdoc ca5d768289c225dea34f82176591548fc03963cf653f0a8ea0b6e0f9f71ca3aaVirustotal results 54.84%Heodo
2020-10-17J_PO_10172020EX.docdoc d475df1f773d7613eb0737655576c72e27384c8dcd3f851df9ab4ef978049108n/aHeodo
2020-10-17DOC_WF3025702524UO.docdoc 8358ae3aef04560a786b84a17aa88a981d700993291a3b11aa001fab16829ad9Virustotal results 51.61%Heodo
2020-10-17INV_PO_10172020EX.docdoc d1e952f7b8eac274a9eb54c0ce6e8c6542aaa16cbdf7345c10c79852c2d5bd0dVirustotal results 53.23%Heodo
2020-10-17SR7405610485YC.docdoc 33e3f84944619fd92c3e53215fafb2b4b962f3e7b97ac0e358959d8ca710de70Virustotal results 54.84%Heodo
2020-10-17BAL_XZ6363547405IF.docdoc 02730b23749bb5e945d78771425520fe94a15b5647f34a7efeca54a72c9297c9n/aHeodo
2020-10-17D_QUEBAHFXILSY.docdoc 19b133b4ad7b5c3072ca746a89f06864d39ca4c8985ddfb2eeadd125ff5cd7a7Virustotal results 50.00%Heodo
2020-10-17EQ1L8NLH.docdoc eb06448eea7b0d73132945671275ea572688e13de195a89974d8315900ff8cb7Virustotal results 49.18%Heodo
2020-10-1787063777.docdoc 4f6043ed53481592c3b9db4608a157df568b466062cba2018b8e5c59bfb40563n/aHeodo
2020-10-17FILE_56347585.docdoc 99acccb026919eac0d3249c8a9207a71d032fbe59c7540c12aee398ae86e6780Virustotal results 50.00%Heodo
2020-10-17A_O4TPXX3F0NX.docdoc c40e490d1149a43b982a7c65d5f04d36117a86623374f75bf8d47f31090f8b18n/aHeodo
2020-10-16DOC_57053759.docdoc c25321d27755dd74dfcb51c16c96a607d16b09b59b1cbe7f025dc89763d9d630Virustotal results 50.00%Heodo
2020-10-16REP_PO_10172020EX.docdoc 3772d83153c2d54a8a3dd72055370d3db69948bf4eafeb69018ce518c7801d05n/aHeodo
2020-10-16GDE_100120_IHE_101720.docdoc 70c3e11a1960c379e6be0215b70999623bb37cad12e932cf4d222f70f078c6d2n/aHeodo
2020-10-16BAL_52959556.docdoc bf79372e0c3a2b7a3b0df0f3994621206443404f5c382b8ad5e5c609c6b0e043n/aHeodo
2020-10-16L_99718847284218257701275.docdoc 39dced6aa4d3785efffcddc9b87bb1744c386d811cf509ac1baef383eb0c38cen/aHeodo
2020-10-16REP_PO_10172020EX.docdoc 69bf38e708fcc10caf5824bb4460ed7f950dfb3085f715c81303b992c3bb6857Virustotal results 51.61%Heodo
2020-10-16INV_PO_10172020EX.docdoc 7bc4797a66cfb8dbdc6f95c5568595d0229200838644a798b7228d1bde86b554Virustotal results 46.77%Heodo