URLhaus Database

You are currently viewing the URLhaus database entry for http://legalempowermentindia.com/cgi-bin/9Z6L/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720290
URL: http://legalempowermentindia.com/cgi-bin/9Z6L/
URL Status:Offline
Host: legalempowermentindia.com
Date added:2020-10-19 23:08:15 UTC
Last online:2020-10-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 23:10:15 UTC to networkadmin{at}znetlive[dot]com)
Takedown time:1 day, 18 hours, 50 minutes Poor (down since 2020-10-21 18:01:03 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2144vvZ.exeexe 7594273ea1a0b8fa3f653fa547bc03afdb13a00c182a2dcf8f7b76d182b3f95dn/a Heodo
2020-10-21EgSvurI3yYi53kNQbX.exeexe 8aee37156ff18ad454aba4792cd7d33c4aa5bafd52e95a90e44f2c187cf0b7cfn/a Heodo
2020-10-21Y.exeexe 2f8687af23d5ecb7fb0bd17237008b66828e368e9acc4a7abcaefb886a2537fan/a Heodo
2020-10-21BX0Z1.exeexe e385eadec8513fe9d017e480ba3c6b00cbf0e20bf1ecbd045738b03f142ef047n/a Heodo
2020-10-21kZKeSCWmgn.exeexe ae60510c55842c4ff909d319a49f7c5f3c498a60313af48a8ee6cdcc67d8c9dfn/a Heodo
2020-10-21EtTyNYSKU9uDoAVzjo.exeexe 255e3e1ecbb7e316472abdc380f580525046ebf999d55b8b3a51a951dc36e531n/a Heodo
2020-10-218.exeexe 219e52a0481a8d8ee0b367c3da41a2d4e6dec70b6463d3e26c30a9c06ca9c4b0n/a Heodo
2020-10-21rc.exeexe a5a81544a31f99c469fcc9d4ee184ea3949404d30c369c5bc578c44286770115n/a Heodo
2020-10-204lEZ5VWIEqqNuxzOAWZZ.exeexe 43fe52d85b25fb8fdbe4acb1b604c7183127dd7f459fd7e8655c1bb40373ac2bVirustotal results 18.84%Heodo
2020-10-20NhpO.exeexe 57738abde7e0d71cd50877d989587a579e6a3c36376118fdcd08151c4abb8c1eVirustotal results 16.90%Heodo
2020-10-20kB91bOhaYaFGA2bOFSoq.exeexe 405bbafd9d79b1db23d896cb0e13eb1e8eb487567a8307b80a57aca28fab6ce7Virustotal results 16.90%Heodo
2020-10-20dunDj6UT5csCQX9.exeexe eedc017415ce27776c7627896888b8bc3250c3287837db547d9830508097d589Virustotal results 17.14% Heodo
2020-10-207eQ6UAX.exeexe 5d690fa2835395b1f76307986578690c6e6c9bfc1376a3051adb466345578a9bn/aHeodo
2020-10-20z820DmsJoottrVVK7P.exeexe b67097d6a9df7aab63706092c279ef1ca084112cf1b304aa4881e091ea33353dn/aHeodo
2020-10-19exiSiSSnLboEFaS.exeexe 2e94bd15a4d0534a873639566a3749ad24924da7c505b554adae986e655fbcc9Virustotal results 16.90% Heodo
2020-10-19qHfQ4.exeexe 417c785f3e0369e318bb3897b919a36d54a93e918df86d83c3b3b5a70d01c340n/a Heodo