URLhaus Database

You are currently viewing the URLhaus database entry for http://www.leodruker.com/En_us/Information/122018/ which is or has been used to serve malware. Please consider that URLhaus does not differentiate between websites thats have been compromised by hackers and such that has been setup by hackers for serving malware.

Database Entry


ID:90946
URL:http://www.leodruker.com/En_us/Information/122018/
URL Status:Offline
Host:www.leodruker.com
Date added:2018-12-07 03:36:21 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-07 03:36:29 UTC to tech{at}hmdnsgroup[dot]com)
Takedown time:1 day, 16 hours, 0 minutes Poor
Tags:doc emotet epoch1 heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-12-08form-0274442750.docdoc688770a69b2985abf2ab475f0b7f855918d9270b8f5324686762a476d1eb4c85Virustotal results 18 / 61 (29.51)Heodo
2018-12-08eForm-180820955653444.docdoc320b35c8c5146de33eed58792af1dc16801b5d950359838c58117e305a6369a6Virustotal results 17 / 59 (28.81)Heodo
2018-12-08file-367484306702694.docdoc5e3e0f0004f9ccc6d49ba5d68dc566cc58af71bf03af31b5febe4d820e28fbb4n/aHeodo
2018-12-08doc-5157583489813779.docdoccefebc8f2b70693fa4826272e750c817720c33f9df9ba0af600aad8bda8cc25aVirustotal results 18 / 60 (30.00)Heodo
2018-12-08Untitled-1802098875.docdoc6b9b7e68ba6730d54c569cfaa439d2fdd20bef04b78c40a6f816a56cae2592beVirustotal results 20 / 60 (33.33)Heodo
2018-12-07form-48851026318582.docdoca298273fba811a57dedd9b66815ae54d289044c5e1710a1c748d3756c79cdc49n/aHeodo
2018-12-07form-6093683985739.docdoca3873624e6bbd7513d75ed44f7aa81bd5308586b974793f7be4a50d608e66abcVirustotal results 20 / 58 (34.48)Heodo
2018-12-07Untitled-7397271522901091.docdocade6ed8ac6cb9784f94571780dd18a951e3dc8d424172270bc98668dd9a80704Virustotal results 19 / 60 (31.67)Heodo
2018-12-07doc-70553228489608.docdoc17b80113f2f0a5f22c6ee8dc979a1994fe6740f1f62e4bf3160dcd7e84aadb8cVirustotal results 19 / 60 (31.67)Heodo
2018-12-07file-92803136212.docdoca6a3caa920589fb154965983eaf7df4b2c7464655949157f7bcd5130c2929706Virustotal results 18 / 60 (30.00)Heodo
2018-12-07form-20857016211.docdoc5f8ff1ef51141c4819d24f5aebefc11dd654eff470bf7dd2bf68f5d7e213961eVirustotal results 18 / 61 (29.51)
2018-12-07form-548919981926.docdoc88f7c08e711bb92426806d665995e2d373ffc4af92aa6e0e141fee27b0dad0efVirustotal results 18 / 59 (30.51)
2018-12-07DOC-6255113657461476.docdocd70f0c25d91b778e5991c3947b89823a372efaf67cf6336c2a44fd479b9105a2Virustotal results 18 / 60 (30.00)
2018-12-07eFILE-164219074209.docdoc4711ae2828acecc28724f4a7df9a2f350c93c8e6ea945278bdb2824518c4b8cdVirustotal results 18 / 60 (30.00)Heodo
2018-12-07FORM-5941730242079.docdoc25d7739ee8c7798d26aab5499e0af080b8a01cce30fcdf4c08c3e98db4333aecVirustotal results 18 / 59 (30.51)
2018-12-07DOC-928659939814.docdoc63b4b91e9cc294cc6ab6f1c95d8f8989dfaed22eff2791a5c84fb54d7c379346n/a
2018-12-07eForm-02815721429199.docdocee31da561fda319dda8e6f278befe3d6c063dc64dd93fe0e083378d5571ddabcVirustotal results 17 / 58 (29.31)
2018-12-07FILE-8847985275436644.docdoc5e60598d344825d47f5292dddd1461643788687b2902e06debef939eb9fc2692Virustotal results 17 / 60 (28.33)
2018-12-07FILE-41160128613214.docdoc39c4d6e0e4dabcb151c63cedb80c20898101dfdec2beda7e30af815261c8c8f1Virustotal results 16 / 59 (27.12)Heodo
2018-12-07eFILE-5039811868.docdoc280b03be699024017d9aea4798286ebea9402ae6e1abcb90c675438efb47157aVirustotal results 16 / 58 (27.59)Heodo
2018-12-07file-6242714842.docdoc5b897c28a487e658f6907eda481a0c1d6c5237cb9304e1322675fc71c31c5392Virustotal results 15 / 59 (25.42)Heodo
2018-12-07DOC-1500434417046140.docdoc3c0e083f257ae49ebcdfb1ebebedd038b8cdc98bfc019002a2050e70764dd191Virustotal results 16 / 59 (27.12)
2018-12-07FORM-8475057176.docdoc50de750ba8e5bc7dd266302fc17837e2bc2e52ff64d696fde5483593b4effeb9Virustotal results 16 / 60 (26.67)
2018-12-07DOC-818795349140435.docdocbfc71334ea56e0f338da61358e7d9dccd34c2799188d35467186c2fb734255ddVirustotal results 16 / 61 (26.23)Heodo
2018-12-07eFILE-400038111252.docdoc022411990c7ff9f424ac6ddf6d0e4ecc0a83eebfd2e769b21330f2cc3e67325bVirustotal results 16 / 60 (26.67)Heodo
2018-12-07FILE-69977882481085.docdocb6fc93e8d999ad593cd5466d34a888a8ccf68a905716560ead25ebd0d6b19ab4Virustotal results 18 / 60 (30.00)
2018-12-07eForm-36727750524.docdoc0c2adfea9dd5af860956b45cc4e8cdb967dc9210c8375daed99e478d2e074dedVirustotal results 16 / 60 (26.67)Heodo
2018-12-07FILE-87885312689.docdoc92be261b1d512a18c27d81c13d7d8e728e939f1dc75af1bb1559dcce1ae64522Virustotal results 17 / 60 (28.33)Heodo
2018-12-07form-4338737761.docdoc94ed4902fdcb0cc97c879f9a3c0d36f751b77ea7a37afecb771be1e96e35725bVirustotal results 18 / 60 (30.00)
2018-12-07doc-749363074853.docdoce415e9496cbea9351fa8884a6ed0951847feea5cc8c92bda3abe68d4d2c8221dVirustotal results 16 / 60 (26.67)Heodo
2018-12-07form-5704673046881.docdoc0029192b66856ab4c67705c299c31178efd5ae6cfd5f9a17b2f4c5337a987069Virustotal results 16 / 59 (27.12)
2018-12-07file-357499392476.docdocf5b218f4091d1e1b944c3544ae820b78eb8ed0795ea7b6ff5595272703574798Virustotal results 16 / 60 (26.67)
2018-12-07eForm-265679599067526.docdoca3f9d20a724676a5f565f92181de6cdab9bc3106cf2a42eb248be7ff4c00510eVirustotal results 15 / 58 (25.86)
2018-12-07file-442100979671.docdoc7aaacee3deab0188fdcbbfc18fc1cbebc7c75b6f053a6444f4def47b318c80f6Virustotal results 14 / 58 (24.14)Heodo
2018-12-07DOC-34946000411631.docdoc03f250e74a296adcd771f19adcbc187fb7f9420306aba4b1fd8d6c3b3420cf31n/a
2018-12-07doc-3793611295965460.docdoce8da3a2455ab14a9ba664f2bba4189d6ddbe20eaaa832375bb4fb6d7ff39f1f2Virustotal results 14 / 58 (24.14)Heodo
2018-12-07doc-29402427586.docdoce5ffc538f0d107bed7d7876ca9d9afd66846a122a7edc6c0f5fa880171a9e255n/aHeodo
2018-12-07DOC-26367444072463.docdoc75293ba9d0b6cfb14e8b09a604c727307627065dfac4ec23ece2c1483f25338aVirustotal results 23 / 59 (38.98)