URLhaus Database

You are currently viewing the URLhaus database entry for https://lancasterroofer.com/design/balance/331312/mXAibNV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:750665
URL: https://lancasterroofer.com/design/balance/331312/mXAibNV/
URL Status:Offline
Host: lancasterroofer.com
Date added:2020-10-26 08:24:05 UTC
Last online:2021-01-12 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 08:26:04 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:2 months, 17 days, 16 hours, 9 minutes Bad (down since 2021-01-12 00:35:40 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27form.docdoc 6c40a86cca19d777bd981ee02c7511d1e4d2cb3b958f17a34e06eda569c38be3Virustotal results 24.19% Heodo
2020-10-27CB-100120 KPOC-102720.docdoc f7c62df3d72569e02a22d018a54631d3041f23b308ed9da7af261561ac318a74Virustotal results 27.45% Heodo
2020-10-27INV_7076.docdoc 799de3c0b3c57093a424c4e80e471b26b7f7d121e6e4b75a250304ed59ab9d6fVirustotal results 34.92%Heodo
2020-10-27Invoice #91480624.docdoc f1457d9b1a902adaba47239190f07fb8d1bf37f60293ef49138cb03a435bc841Virustotal results 33.93% Heodo
2020-10-27G-100120 FMMY-102720.docdoc 618b42ed1f918805007ba2386a3456d92250a54d5091f096234f293b695a5715Virustotal results 35.19% Heodo
2020-10-27Copy invoice #653407.docdoc 3f5ce2d57635a5ebfdf3de5fb1d6be2b71cae647e4cf98150a81368533f525a8Virustotal results 35.19% Heodo
2020-10-27October invoice.docdoc eae3592508245e9877cba463c7e74f5efccaebe4835b7a884c95968d75f94c6cVirustotal results 36.00% Heodo
2020-10-27INV #00127970 FOR PO #0025599540.docdoc 3ca351359985314f547ded15fc36b35b353619a5caede67c300b0598eaa5aee8Virustotal results 28.57% Heodo
2020-10-270011815.docdoc f06c45e24ae91421d8606be6df208fa0cf0ec5dc53e2f9d1db1a04725b593911Virustotal results 34.62% Heodo
2020-10-27Inv. 027258.docdoc b8b8567515aa6d706de0c6d6d50693f246b46ad98f3336ba7dda3057d5044634Virustotal results 33.96% Heodo
2020-10-27K-100120 RJEL-102720.docdoc be38d405f6ea9e49d7be5ef0c7f75b7c3c8b201ed03af92b15ae0f6f284df534Virustotal results 33.96% Heodo
2020-10-27F009 invoicing.docdoc 5e371b305eb74219f8f11f61a0e4d713ca73e7e21a7b8205627e01639fee8a73Virustotal results 50.00% Heodo
2020-10-27Invoice 007221290.docdoc e46fd80923092207fdfde7d99af929b43f3c66eeb30bf6914255531cd77a59a0Virustotal results 49.18% Heodo
2020-10-27Electronic form.docdoc 928033086d1937f273987442ab4d4f7144320be797ebef8c68d81e18cfbb1efeVirustotal results 46.67% Heodo
2020-10-26invoice.docdoc c6837f0ac871c07b7e1330f74ba054bffcf4b9d45e482669cfa35f7447229353Virustotal results 43.14% Heodo
2020-10-26XF2839813675PN.docdoc 4a7c1b0ec0e78d301cf0ea258afa8fd51ad627e470aa1353b34da0ea4f8bb7a8n/a Heodo
2020-10-26DE-100120 GDNN-102720.docdoc c7b32d97c409e0a129cc49c45ce69e94b6fc692f3f8bdfb82523f616d5d38968Virustotal results 42.59% Heodo
2020-10-263426014990CN.docdoc 48dc30e76d484749d152e5dae556982822af7448889052940e5e1abd054228e2Virustotal results 37.10% Heodo
2020-10-26invoice #653422.docdoc a62c93dfd3c439aafd9f872886f1021f430fe76e679e7baac840782f382bfb29Virustotal results 37.74% Heodo
2020-10-26Electronic form.docdoc 715e60a24fd90a6e59aa6930219217d550926adf6e14321bbdc712b5cbaa4f94Virustotal results 39.62% Heodo
2020-10-26Copy invoice #3200.docdoc 4b5939a661fa44e48ad882e2f5073289a1765a5fed23044fa7ffd93a44e5cb27Virustotal results 37.04% Heodo
2020-10-26invoice #4048.docdoc c22fdea1e3ad51bd8cac48c47f5cc24cb600b219ca5f5293ea140a5d8d91bd22Virustotal results 36.54% Heodo
2020-10-26HS477 invoicing.docdoc e4e2b59b96de572796b1b3d7aa8cdaf3527ec0435e4855c01e7a2442d6caccf3Virustotal results 35.85% Heodo
2020-10-26INV_456905.docdoc 0b28aafc9c3a3a6c6108c222626c51b1f5840f4f5fe9484387ea3af62d715537Virustotal results 37.29% Heodo
2020-10-26form.docdoc b823aa2b209313c49fb5c09dfd90f9bf7ce8983d5d1e8db87074552297ca8164Virustotal results 37.70% Heodo
2020-10-26form.docdoc 0231bc27e673f5d22b291e5653e498f8bb7e278d7d9b521aaa3cf2ecfbac49a5Virustotal results 34.55% Heodo
2020-10-26M-100120 KPFL-102620.docdoc 33bc493e35171898f15cc529330ffef62bef083d637effcac019e6afbb5fae73Virustotal results 30.00% Heodo
2020-10-26Inv. 0050269964731.docdoc ff6d3c607b5f92d70c1f9fd9de7df3fd0e8e4b6c690c04a6705baa30d71c4f68Virustotal results 31.48%Heodo
2020-10-26invoices 825 & 9968.docdoc 0f7d25ca53837ee02d337a5f2e901a415fd61ef5f9307a2126d6bebda45ee81bVirustotal results 31.48% Heodo
2020-10-26October Invoice.docdoc 2abddf44ec8224372481262071d1c56bbd016b6c3bf03319da7330b0d13758c6n/a Heodo