URLhaus Database

You are currently viewing the URLhaus database entry for http://layunomore.com/wp-admin/lm/upAf7OlIhVyAd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:757607
URL: http://layunomore.com/wp-admin/lm/upAf7OlIhVyAd/
URL Status:Offline
Host: layunomore.com
Date added:2020-10-27 18:48:06 UTC
Last online:2020-10-28 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 18:50:48 UTC to abuse{at}upcloud[dot]com)
Takedown time:17 hours, 4 minutes Good (down since 2020-10-28 11:55:00 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28inf-2020_10_28.docdoc 5cf54e1bb1d28b6fe18106c2ab05c35a90362e5eebdfea67e4f42f3f9f6f3e3bn/aHeodo
2020-10-28arc 20201028.docdoc 8b9fac63d3833d86de7736d588f7430f57c887e9c17752bc24682da2153113den/aHeodo
2020-10-28arc 128.docdoc f7924c0145c0ff8ac501947adf36affbca4f0718dc964ef681ab241d0e390c74n/aHeodo
2020-10-28ARC 71582.docdoc 6cfa4bc9d98411218a03a8a0227df17da83335f49beab3784ef3ccbfe0f2e0dcn/aHeodo
2020-10-28UNTITLED-2020_10_28-3058.docdoc fbb671ae1f53d8726d9bf7afbec7fce69952163f4ffbe17de732c67b2cc2a527n/aHeodo
2020-10-28INF 993184.docdoc 3f613f9a6463317b5a575c8829a4e8c8f04a69a3206d14ed89f9c76dba29d162n/aHeodo
2020-10-28Rep 2914.docdoc 2efc5b4bae391cc5eefd5b06ac3b3e4e4a321d8350ccd641403be754f64f019en/aHeodo
2020-10-28REP G925.docdoc 0d2cf62672624cc37b321be32008ed5ac906a33a9492a327631b8886ac918b40n/aHeodo
2020-10-28DAT_2020_10_28_755.docdoc 5ba6a0db5fe221f32f4a9cd85cf69ab066cc4f6186d6e93b5669571a32a35d7an/aHeodo
2020-10-28Attachment-20201028-636.docdoc 6caf7862cf4be1450e259ce7dc287f887103e42b874b426123ba7a5219444b26Virustotal results 28.57%Heodo
2020-10-2894079FR 2020_10_28 6070.docdoc bab7e3469ca42e62451b6a11a29c4410f143ed4907193e6091f3ff0fe486cb05Virustotal results 28.57%Heodo
2020-10-28Untitled-I609017.docdoc e549afaef9205d532d55d91cec38651852e85a6cb0bfbfc07904a59f1a6b211cn/aHeodo
2020-10-28FILE 2020_10_28 42458.docdoc 37b3eea45fea263bb43106564a82d2750f430bad89f1b14f7fac32fed149e8e5n/aHeodo
2020-10-28File-2020_10_28-Z9598.docdoc 6bf49682da7e06dc378e14693f4dcb29147a7f29c73fe4b3206b979058af6b2bn/aHeodo
2020-10-28Dat_2020_10_28_7207.docdoc f4d738149ed04a904e53e846a49b9996cb7ed6f4cfe4f3071150e581ed3a4609n/aHeodo
2020-10-28Mes-MJD82477.docdoc a003060572cdb9836b81c7e55a99cb99107bbaf0b15183ce3f823b5c32690392n/aHeodo
2020-10-28dat RF3790.docdoc cdba75792bcf44a350ab83ecd05679196648d93ea60f426ff3e28d4239bf1826n/aHeodo
2020-10-28list-2020_10_28-URW199982.docdoc a3d3cf6713d70294e39dbcf0379e082d6a257adccbdf41d1fdba62df8aef883fn/aHeodo
2020-10-28Attachment-2020_10_28-S2833.docdoc 785d6c0b148d8dddf3cbb492f290386eed4b1e54c7960b26263014af5b68b783n/aHeodo
2020-10-28inf_F249.docdoc 6702852d6449cc2549b7987cc2fa0583a15fa2f831dc77cf8c8d428605912203n/aHeodo
2020-10-28ARC.docdoc 6c17bfdc1c41fd0b9618f61b8789ef61ad808a81048b22038c3ac8a7f6ba686cn/aHeodo
2020-10-28arc_TZE224.docdoc 8480e663d0a058194b6a6eb9701872e426d2039988a82de35c226dd13cf012fcn/aHeodo
2020-10-28Mes_2020_10_28_H231.docdoc 64b7e5242a5c60c2b2031129ad5ff53540b70c43ac2530d09a627c3f8d4f4c43n/aHeodo
2020-10-28Untitled_20201028_266.docdoc 13578189ba67b1b728017c0e96a3708199a8c879f2be7531e35e6570b09f31ban/aHeodo
2020-10-28list 2020_10_28 017.docdoc c09da99f44d060cc07412d7cd8f81d184f0530fe7a5b2e0e4e32e5e1be74fb5dn/aHeodo
2020-10-28dat_2020_10_28_9712.docdoc 50f1ef11f8245c538d7f44158d5666f2036513ee4d95e1699313c903e0574a9cn/aHeodo
2020-10-28arc_2086606.docdoc 9ca8226ef71916dee3526b14cb6e112f6d9c12c2365d5bf4ef43eabfa3c844d3Virustotal results 31.75%Heodo
2020-10-28dat_2020_10_28_326.docdoc 6d31a92d5a682c250c92f5f41cbacd685697e662f5ced5145c76a0cc0044eb56n/aHeodo
2020-10-28dat-20201028-1960400.docdoc 88a224c66bc34bf992821c58b6790906b8048d27fb20dd123ea5379ede510dacn/aHeodo
2020-10-28inf_2020_10_28_NOB911085.docdoc bb767a987c3bb38d105c55a5e17fe4bec3ce116f87235dce04be1f03c3ba6fccn/aHeodo
2020-10-28list-20201028-Z741740.docdoc 7862369f401d84f41b94003a00d8fe6b36e51c435f35a8e996138a0f52fa1893n/aHeodo
2020-10-28rep.docdoc c430d5a21c9bd894ee7f7adad674ea7a0ec0520df916938568284c655ecb2c8an/aHeodo
2020-10-28LIST 2020_10_28.docdoc 937caf4bff20604ce065b1e9c219c1af06ad065dd2522bf6256e0b06c40b9844Virustotal results 29.82%Heodo
2020-10-28rep_2020_10_28_327363.docdoc 5bafcb869ad1c89b92e8d0cf06c05c51bbc54f713743a5e7e4638fd6153b5d03n/aHeodo
2020-10-28Dat-908685.docdoc 9bd0e68a4d1b0b3fa07441324dbc77574a04628efd26d801f15105057255e5fcn/aHeodo
2020-10-27Attachment_20201028_662.docdoc 13dc41a09ac500a00ec0a4a9843017260672fdaaed428508c6307ff3341c3e95n/aHeodo
2020-10-27list 2020_10_28 SN295870.docdoc 7f4e135c6557e09fbf0db84e8fd9ca4bd69547747c806a09e8b4ff6651109c0aVirustotal results 26.98%Heodo
2020-10-27Untitled 2020_10_28 04863.docdoc c651101c619e07bbec5cf5a52967126141ba3782bdf7c3af4b53903d30704096n/aHeodo
2020-10-27Untitled 0211.docdoc 0de43abd8d4f8877ff865f52486cf10fdc2c9c8c627562969e32f6b00ebb36f5n/aHeodo
2020-10-27Rep_2020_10_28_FYI9734.docdoc a97d0d9b4dc3721d627ef5df398f56c03281aacd47b15299f409a1f2a3c70fb1n/aHeodo
2020-10-27DAT_L0216.docdoc dc195bb810b63c35c74cc0cdd8690cff533be0b29da2a5e568c8a03d6b3bc05en/aHeodo
2020-10-27ARC_2020_10_28.docdoc 53f11a87c5eb09d98d2ad6807bf4a19a1844cd1c984dcb9365e45650ee7374b0n/aHeodo
2020-10-27dat_20201028_0180559.docdoc aeccec42934a9750b091d5e65045ea9666b71067261ed4c53919afaf00ae7cdaVirustotal results 19.35%Heodo
2020-10-27mes_20201028_5960303.docdoc 2c0e571af9551f882e0f962c19799154fd0e9d82e9c8876d726a11f50cbc9676n/aHeodo
2020-10-27ARC 2020_10_28 PXP57022.docdoc 63fc16f5e75a6bf8e072742070a020c44ecbf4f3b462c6480046003b2e4e8eb7n/aHeodo
2020-10-27Attachments-15281.docdoc 2601d9525dd1d87f14ecb71e836de82f20354f4dde1251e0847e313c57d8ff7fVirustotal results 19.05%Heodo
2020-10-27doc_20201027_H991.docdoc 138f306945c20e8dd813e43d036300dded2bdf97a71b4fc586989871a11a4fbdn/aHeodo
2020-10-27mes 63392.docdoc 62bcc19331151319c7f92f51fc561380900d5c6f4b128b0df63db3ac0c442afcn/aHeodo
2020-10-27ARC-20201027-NGS97939.docdoc e8b19723225167f1b831cdfd075a80a02537306d5d73af68da53d7dd4fd27229n/aHeodo
2020-10-27DAT_FLD8859.docdoc 7361bce55fc9bf2abccce87123c812bf499278023d0b206d6ea656a87bf3d592n/aHeodo
2020-10-27arc-B22900.docdoc 9a665625762701ef94a2ebac83e7afc5fe24eeb05095df8655a980ba20f75343Virustotal results 19.35%Heodo
2020-10-2776051646 2020_10_27 B79393.docdoc db2eb128cacb5bd4b950a7cb261d660b45eae83b44d19ff364b9d4d1eccaf6d1n/aHeodo