URLhaus Database

You are currently viewing the URLhaus database entry for https://legion.com.pk/__MACOSX/pT3h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938248
URL: https://legion.com.pk/__MACOSX/pT3h/
URL Status:Offline
Host: legion.com.pk
Date added:2020-12-22 12:45:07 UTC
Last online:2020-12-22 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 12:46:15 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 hours, 49 minutes Good (down since 2020-12-22 21:35:17 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22Xs1YbH.dlldll 40b2276b5f2e54f945aacbc8eec699b0bc7aeccec109305d33d600b96dad5464n/a Heodo
2020-12-22hRkrQ6jfngtbsMZR.dlldll fe0b2695942accca37445aa3e6545e85b68ae4daad46ccbad20239d50d8a073en/a Heodo
2020-12-22X8bEIaQpU9wLoDY.dlldll cb2183060c6b48cc7538ddb4ea5223e6d74576179cf20b87ded4dae867822565n/a Heodo
2020-12-22MCvxLJzmNkn.dlldll a6bca1c82c49ab44fee2db8b5052e05a507af1bbad94f58a73cf558ab7d5b36en/a Heodo
2020-12-2269HkcnZD9dJPV9jBdDp.dlldll bca150bd60780f63698ed16efe5d885ce01d914696669f606f2a193edfe202c1Virustotal results 19.12% Heodo
2020-12-22F5n8t80ha.dlldll 9f0d5b65d77f6c919636443b10370bf940890017a923d3252a5b9fedf2ba7767n/a Heodo
2020-12-2250.dlldll f4ede79d7ca3d2ac114b6b304da315b14d5322c8dccb2e4c158265dd6e6fa463Virustotal results 18.57% Heodo
2020-12-22ow7RYf.dlldll 42347ece3986b8ece2fce05ab05feeae150fdc88d40944eed61b6b3c35e2a696Virustotal results 20.29% Heodo
2020-12-2249nyPnhkVdpF5Mx05QAzd.dlldll bdeb2c7ddebefa92ebfbda70f9de9643e3245e1cf4bc087e938be02aca13a3fbn/a Heodo
2020-12-22WaYtSLYt0q4r4.dlldll b9ba14be0fe830210289d9fdc2b083bcb8a4dcf056717a454889cf91efe9dd6dn/a Heodo
2020-12-22LcA.dlldll e336d7cdc6ac462146fdcc741850ff092b2eedefd90e7a14c468542bff9fc41eVirustotal results 20.00% Heodo
2020-12-22BrP4ltZ8G8qe3.dlldll 92f2db9df9429589a07b0600c19b353ca393d4aeabf33e3699c873ce4acd9906Virustotal results 20.29% Heodo
2020-12-22zI.dlldll 9712af0fa9920d38b8062e2dd199c29664f647534fe65566c54c8cdc42e58de2Virustotal results 18.57%Heodo
2020-12-22yKtz.dlldll 4890a9dcd00608537b8b50669b1fc2a2a29e71056f0bae4d0cd4b0782b6ec9bdn/a Heodo
2020-12-22yiUdDBV48DpD.dlldll c79726a36b8426265465faa8ff15d024a932c836457f583d3421aabf465e4500n/a Heodo
2020-12-22V4GZ0bpOpknwm1eyKlrc0.dlldll 5085e7cd7ea308adf38d095a32206c4e66fa2fd5faa6ccf8845aa3b08c8d3d46n/a Heodo
2020-12-22v5YDD3K.dlldll fde242df421ba254c475a960ce92d7eaadc4dd3f55a5bcafb77e6d79da7a24a1Virustotal results 15.71% Heodo
2020-12-22B2cpPuSNm3bM0.dlldll 14fbf21b4dae36e7aa8b60d1abe4f46dcd5bebc8ecdc42db5a1bae688de8c189n/a Heodo
2020-12-22gx.dlldll 52a94bcb0365183ab2d4722002673d5d1867a7e375cf3bd2978489f0d4ad986cVirustotal results 15.94% Heodo
2020-12-22xV4.dlldll 653c6b6f0f83950660be5b44516901b7950f60680e89c51ce8de050ec394dd16n/a Heodo
2020-12-229KZfbQ5J0CcgE3gsx.dlldll 49742453d054e78f93b9fe33661029a0551a59dbbe1703685c08f92774df6e04n/a Heodo
2020-12-22k0bIejDS.dlldll 217255141916470a566a7bce1a8eecac051896268415b59c73ebe0481c31ff0bVirustotal results 35.29% Heodo
2020-12-22cRBy9.dlldll ae1e8a33f7f1d418d3c98b541e93e6bbcd457b238bda606a0bcaec5469cb2456n/a Heodo
2020-12-22i9FHIHaa0Na2ABQx4l7.dlldll 27beb99c5d74056c04b117b1fa28fc26a7a11c238a06348c7eb75011eef53ac9n/a Heodo
2020-12-22PoTyIoBjrY00nPZFTJw.dlldll 18cf53e4dadbfe6b37d0f7214bc093d5e2541c8cc87681bd3964a61fcb8275ben/a Heodo
2020-12-22ZQh08m.dlldll 3a16361548e0e37ce25163437dc59dc7134d8a1b06c0e88e7f3a74c0314a17e7n/a Heodo