URLhaus Database

You are currently viewing the URLhaus database entry for http://lenabis.net/rmk/Reporting/46542787/mtoLuL/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:724549
URL: http://lenabis.net/rmk/Reporting/46542787/mtoLuL/
URL Status:Offline
Host: lenabis.net
Date added:2020-10-20 17:02:07 UTC
Last online:2020-10-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-20 17:04:04 UTC to hostmaster{at}nic[dot]ad[dot]jp)
Takedown time:19 hours, 54 minutes Good (down since 2020-10-21 12:59:02 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21October Invoice.docdoc d9c9cdb661798fec5696237b21371f7bd3b1fdac360a68aa3fc3d863e1d6173aVirustotal results 32.26% Heodo
2020-10-21Inv. 00832383075.docdoc 2808f5432076507429694409af31703a91c9d7e104800e8465efbd76926928fcVirustotal results 32.26% Heodo
2020-10-21LC-100120 PSYH-102120.docdoc 58605ff883aa8ce6029f21718cdb67a185161dd9de039877800960957563c02dn/a Heodo
2020-10-21INV_97022.docdoc 8b2cc610d0bcf80a6efb3dc33ad4727a7a354a8d054fa08ea02d82e5f82e93den/a Heodo
2020-10-21Inv_7830.docdoc 9ae2a76f7986879c8240f676ae9dec6196bccba2a978f23adccca97489d1e33cVirustotal results 34.62% Heodo
2020-10-21October invoice.docdoc 3066b546570363fffc99b9c8264f2ec405df38fc02ee37fa0a3e7a69e3c24244Virustotal results 29.31%Heodo
2020-10-21Payment.docdoc 8cd445b93100d4a1d8b8d09b1829c4460f50271afb165768a5b263664916c0cfVirustotal results 30.77%Heodo
2020-10-21Electronic form.docdoc 23fb1844a3cad0f727d5bf74d8ed76b134681db7486450782109d760f792863eVirustotal results 26.67%Heodo
2020-10-21Form - Oct 21, 2020.docdoc f41d3c54b63ec1671bd601f1800ff185f8c325398a4ae3e1747d7d2421a2bfe1Virustotal results 26.67%Heodo
2020-10-21invoices 281 & 7400.docdoc 335cd0b68598573b5573526dd255bcbf94fba7506c1955a07f5fa0e6cad0e7a6Virustotal results 26.23%Heodo
2020-10-21Invoice #9748.docdoc c197a6840f019226e39e14128490f861eb67b738ccfee85a256e97847047b769Virustotal results 28.57%Heodo
2020-10-21invoice #24818.docdoc cda828dede96620b0eed85c89ba9eebb9aae7aa5f6b54141207e8f0f9e44e0ebVirustotal results 28.57% Heodo
2020-10-21INV_259330.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21Payment.docdoc a32b8fc89045749411368894b5eb70012518a8d9d1703b940bcbc966c0e40bdfVirustotal results 50.94%Heodo
2020-10-214419869527KX.docdoc 10a79d7cf0b1366e69b0473e9164dcdf109149a6551b18a6c277a242261f5dd3Virustotal results 45.16%Heodo
2020-10-21Electronic form.docdoc e321ead5188a4d2e7abd2c7f2ca1bc74c905e875d34703bea49fa84c50cf4ed0Virustotal results 42.37%Heodo
2020-10-21Electronic form.docdoc 58a681865ea454572eb661486c8e06854e90cc7cd2d5ab95ae331a724f5ce97dVirustotal results 45.90%Heodo
2020-10-21INV #0059361 FOR PO #076920600.docdoc 8d8971cd4eb8a2c26f5263e44299f9f468d43614dcccdcfae564420d264e0d29Virustotal results 43.55%Heodo
2020-10-21Payment status.docdoc 29cdc20b4b547e832ab1e9c0eeff5b71201efe4262d8d542a8b359131f26ed1aVirustotal results 42.31%Heodo
2020-10-21invoice.docdoc 15680f3d4397a2ea2191e960421dd8650642415c14be15b1495f859bc6b9d7cfVirustotal results 41.94%Heodo
2020-10-21SLI-100120 ZUXG-102120.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.94%Heodo
2020-10-21INV_5908.docdoc 106359e17594a3265349fbfc1a2fd1e2f19940ca5c4b2262c1d021bb8d74fe11Virustotal results 42.62%Heodo
2020-10-21INV #00996930 FOR PO #9912789285.docdoc 31b6905dac8845a6ec882d8c569a76792cf589be6591ec8270168d35a8047a3fn/aHeodo
2020-10-20October invoice.docdoc d590ed65aef80ecdc7f0a44755ee436937f30c0b05287ce6d177b654512940e8Virustotal results 40.98%Heodo
2020-10-20Electronic form.docdoc b07a48ca7d09a730829f65f399a5f0496e4c14989705d83a73630dc2a67f80f0Virustotal results 40.98%Heodo
2020-10-20Invoice #064.docdoc 9be377b592614918b5f4aa295f73afeb586e3e386f7bec12cf04637f31433d7bn/aHeodo
2020-10-20Copy invoice #7590.docdoc 4b4c3539bff4d5461f5c5a5ceae568c2e301a62f273ac881508f6deaaea89835Virustotal results 39.62%Heodo
2020-10-20TY-100120 FYOK-102120.docdoc d6755b63b325a0da010a33d5a3e1698866b58b7628b6c3b47a5beb12663604e2Virustotal results 37.70%Heodo
2020-10-20Copy invoice #19203.docdoc c1a2f053ac0b9cafe6d08072e6971d0dfad8f938cc167753df413b1a5ee4065bVirustotal results 33.96%Heodo
2020-10-20Payment status.docdoc f8918c22b7bf74403126907c7e3fd18cdba5c16dc3bef59652e99d67d57d8d62Virustotal results 33.96%Heodo
2020-10-20INV_7759.docdoc 9c7f9441f61d7c2798707bc28069012911e4547e38374095bb23506fb1bbee2eVirustotal results 31.58%Heodo
2020-10-20invoice #5328.docdoc 15e191fa2be80a5d0b1b3af67b1ed360c006e3634442bb6255e4cc0f901abcd3Virustotal results 32.26%Heodo
2020-10-20invoice #036168.docdoc c9804b898a9d2326b05f4037b2eace298777d1a387273033692c9f6deede6cabVirustotal results 32.73%Heodo
2020-10-20INV #247 FOR PO #78441163.docdoc 1fad7db33eae6c2158f57709f82ff40f10276a88a34414418c06ad738eb22299Virustotal results 32.26% Heodo
2020-10-20Payment status.docdoc d71d5d04020304ab739545240d25684b106882802e265a64cba2af565ca6c8efVirustotal results 32.26% Heodo
2020-10-20PO# 10202020.docdoc 98bb25e6f42b7ed9cbaff96437ada2d6b17e0a4bb5a6d1d2e2a8636233ade5a5Virustotal results 32.26% Heodo
2020-10-20Invoice.docdoc 61835e08172767d73a9e6c5dfb1fcc8b904d60c3b9cd7b382bcfe43aeab5c2c0n/a Heodo
2020-10-20invoices 76684 & 3526.docdoc 4217ed123cc2bd063b8cc599340aec39fda437a4e62df3118a01251a915c226bVirustotal results 34.62% Heodo
2020-10-20Inv_801630.docdoc f64d1d64e95cb52e8ac1e43c619b165f65e0a882fb8d0e8314f2e82271425089Virustotal results 32.79% Heodo