URLhaus Database

You are currently viewing the URLhaus database entry for http://bf2.kreatywnet.pl/owa/uBwx-Mk_AOJnUoYPp-KX/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:165819
URL: http://bf2.kreatywnet.pl/owa/uBwx-Mk_AOJnUoYPp-KX/
URL Status:Offline
Host: bf2.kreatywnet.pl
Date added:2019-03-25 22:45:04 UTC
Last online:2019-04-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-25 22:46:03 UTC to abuse{at}ovh[dot]net)
Takedown time:1 month, 0 days, 20 hours, 58 minutes Bad (down since 2019-04-25 19:44:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-272019_03___US___ACC600214319104___25196911570257.zipzip b904baa645ecfb62be403f9a0d39ced7275520ea0541b24ba7bdbbab4f5df115n/a 
2019-03-272019_03___US___ACC146114364___33582760717138181.zipzip 817ce9c8a0173c70eeb74e423af44880914c3ff65127815c9c4a0064e756b4ean/a 
2019-03-272019_03___US___US26367191401___4005456301619193040.zipzip 598fc1d50169fe30b3ac542ddaf3ad0ee38647f3916381d47ca3334c736ada0an/a 
2019-03-272019_03___US___ACC25443834196791616966___286848772.zipzip 10af453bd9c429157b7d817b96289304a4c9fe936d28322e5b3646932878c895n/a 
2019-03-272019_03___US___GPXTC8619766155417___038471731696.zipzip b13e1e0c2ffd9bc4290df4c8b8b2617f43d7da5f78148815f7e0e4a0e2fa828cn/a 
2019-03-272019_03___US___INSTR2802009230711___408625038.zipzip d62788f6108f736dcb7d7bb838e4d809368a732a1c2673d9ddcb3636e49edd35n/a 
2019-03-272019_03___US___INSTR911656214196908336___94688488132209.zipzip 2ce029e1cf10812a6d2878c788f5aa272dc00a7b80d71e069aebb99c98b07c6bn/a 
2019-03-272019_03___US___JY82765159964553___54562166881667581.zipzip 64c53b99091d06a99f10cf840fccdfa986d5a1ff3bd7c5e85abd315332427560n/a 
2019-03-272019_03___US___INSTR162367900751612395___2220805203085973924.zipzip 2c2bd863e26e1ef6a08648c664eefba75bf0b01c3e0f868755076b9db0c3eea4n/a 
2019-03-272019_03___US___PAY51185247370___572853690726852640.zipzip 3213794e0ba0dcaed32446c7d4f74b0e164afe98553762f84ddc65198fec203fn/a 
2019-03-272019_03___US___PAY647542440332___64712053741267.zipzip a37b4cb4b2f8a4937553c52d690be7a4638f679a9d86c87765942e40f9b0194fn/a 
2019-03-272019_03___US___US82563732592054712663___61857224270556840.zipzip a776f28568f6d773356214db19e44943c35563a5f2f2c8e5c68c79d657c73f05n/a 
2019-03-272019_03___US___ACC615197161489956___9081261487065.docdoc 409afa3d0959c8ae11f48ea63d04dd3b93bfe6fefecaa7e1f6c375b005b4392fVirustotal results 20.69% Heodo
2019-03-272019_03___US___EEW03673207226866___61363773752967760.docdoc 3ac20c785773ee12498bf3d4a26f4595b16b5d3eb825a033cc6397123c92a78eVirustotal results 22.41% Heodo
2019-03-272019_03___US___22867515163420449476___94011679490.docdoc 8622ad306bdb71845e69086858cb7bee044585ccf0a478d0610b1b04a192459dVirustotal results 22.81% Heodo
2019-03-272019_03___US___H9051949910162___143089572046764173.docdoc f71f4702f82ceca1dc68b304d4bbf1ec25bab5fea2ef53f05584f3a76c0e040eVirustotal results 22.03% Heodo
2019-03-272019_03___US___US77724284620808857___62089618862.docdoc 59838d3e05415150dc2df373f0ed8c94e1d5c1591c1a3bb6bca5a37fe40f410cVirustotal results 22.95% Heodo
2019-03-272019_03___US___PAY4875284387___4595980562.docdoc 8b4b82805c62319792ed6439e7f7405e56a5f5250c4cb61ee9bdded267435911Virustotal results 23.73% Heodo
2019-03-272019_03___US___PAY1372431090276291___6939758978824856.docdoc 80266352a8c60f023ff4848647a79512cd5fdf745c75b9457b541395d4c9f135n/a Heodo
2019-03-272019_03___US___99902298371302330883___00466245850099707.zipzip feafd9a724ddd7484624a9b0c0a03a742efa2622563ba396cbd2f9300e52ce5cn/a 
2019-03-272019_03___US___PAY072902092064749510___13938757549.zipzip 6d0e5b2b8efc5f69972806dedf3d13020de78584a06d45d33478894a92025b5dn/a 
2019-03-272019_03___US___INSTR2188320826___0905680629.zipzip 65f794c1a707b85a66f1ffe92646e77fe914af9cd71b399e229f2325281420c1n/a 
2019-03-272019_03___US___INSTR52798980324608___734256713.zipzip d8acdb435e1ae99c79c1399970546d833da222a1b6a808de00f2499203d27a4cn/a 
2019-03-272019_03___US___KKURS8014622560___68515462354091947909.zipzip 742f8aa7a8728710f2bd811df35cce9a1e5a2156d0438946ecb5cb644c2d4611n/a 
2019-03-272019_03___US___ACC3732064866___078453007664925248.zipzip 1e6e1a9b95f12fb877a6c0f62f30af552c0bde66f52bc98590c12b49b909b08an/a 
2019-03-272019_03___US___ACC37254737060960953___66299943950644.docdoc 015924d5bf2fd94b806aad406ff4dec89ecc17da5d0247231e2ae1ded25aff5eVirustotal results 21.05% Heodo
2019-03-272019_03___US___RFFTA6899817876191276668___093129904370.docdoc 5930802567671384b717edf74e414b4c7813e7e953b09f8581beb9f8c6e0c268Virustotal results 22.81% Heodo
2019-03-272019_03___US___US747636519911266___99381615298226998933.docdoc 8a108f519d4707a46d61cad7c1c65495ed26c2ba01f2efd75150f462cc596447Virustotal results 22.03% Heodo
2019-03-272019_03___US___ACC97706690983098493___9277464538205996.docdoc 05ba0aebd711d60db39935955f8efdb182571627966a6e129e537223577fb63cVirustotal results 21.31% Heodo
2019-03-272019_03___US___ACC228952671886453___3738373572742651802.docdoc 1c6870532e5b6e13eaf11871daaa703fe93c206e7902bebe6ce58d270065b4b1Virustotal results 22.03% Heodo
2019-03-272019_03___US___HDZFI7754972790336752195___4846845118.docdoc 7bf68152579d01ba99862b61a91689e3507d8ee94024c729dda3e40635e3d671Virustotal results 22.03% Heodo
2019-03-272019_03___US___ACC161862301709606___994343867390.docdoc 46946372c81802503f01b6d9739fd4dd9fe39225973c8b9c22ef625666d48debVirustotal results 37.70% Heodo
2019-03-272019_03___US___ACC39636463799___559721291865929.docdoc 8ca56f45320ae34538a0bef0318e6c28b758017ba91e157369363b7dfa3f2598Virustotal results 37.29% Heodo
2019-03-272019_03___US___2463294390104___6910336778639.docdoc 6026ab30130b1065ac3d1bbd68b0d3eb29e79390ebd55e4d5c8e55313abfafc0Virustotal results 39.34% Heodo
2019-03-272019_03___US___ACC053609664863459___97630014157401227.docdoc 7718b1b4a6fcb490c5e5912dd0155a450de8a86586209b56695a1d77ca21425eVirustotal results 37.93% Heodo
2019-03-272019_03___US___B02538170186995396910___5074163416469108528.docdoc 7694d9fb1e7fe87f76527ae391e7b01fa017b7f27b42c9b92b889e03743917a9Virustotal results 35.59% Heodo
2019-03-272019_03___US___PAY68383575107___74169151524850293.docdoc 4f910d9c86a9f647fc2c9ee8018925b2c7bc974cab6331e252d5d17485ec1e06Virustotal results 37.93% Heodo
2019-03-272019_03___US___PAY5646362733___843632835996624.docdoc 4a2de059b24cde110ce822adef190218a365e9b41f0a96b06d5e45e6642faa23n/a Heodo
2019-03-262019_03___US___ACC06976750595___2160657394761.docdoc 07c63e38cb12e5e8e259602a0a04acb44cc372c7d09acd675b395be858adc06cVirustotal results 36.67% Heodo
2019-03-262019_03___US___INSTR0728815629339250845___4520858103.docdoc 3ce066794ab4c20945fec02a742d62964f0439eb067abb7144df55770e2b3fe3Virustotal results 37.29% Heodo
2019-03-262019_03___US___PAY03643367250966___3714156199948241677.docdoc 39359bd1fd059e7d75989074ca6356844a13145f2075dc6e2cafb20d101b12abVirustotal results 38.46% Heodo
2019-03-262019_03___US___ACC669053559524690205___088340652932574.docdoc 78ad7fface477d0c80f8e451aaed8f325ea725dceb195d522daccfe1b8a5ec98Virustotal results 35.09% Heodo
2019-03-262019_03___US___SPZE6980788875625___1855480754797.docdoc 12801117100fff39edbbc870c6a21e4f180a7dabb92168a0ebfc0abdb2617f72Virustotal results 36.84% Heodo
2019-03-262019_03___US___ACC87730925845___8390903107388001.docdoc 48d5c64139acde1dc8c38574f629fde4d28d4ce056062897672e0b7fb825712aVirustotal results 32.79% Heodo
2019-03-262019_03___US___UDZ8861670324265460190___6846099458289530.docdoc b722d6b36059fec99ce7a4b6ccf982819f03f1118257117ea104ab9246b11018Virustotal results 35.71% Heodo
2019-03-264194634537934019177.zipzip 89d52641dab799f09822b92de395b5a32e8239c885a5b41d4bc04dcd86a6f8f5n/a 
2019-03-26INSTR4409036761.zipzip 433cfbe15bd6a8b03a95d65510b3740b0a82da7ac8f3c031fb95ab7256c3342fn/a 
2019-03-26571404402365401.zipzip 9c35d5c382c66433fbcf524340e42ddad9fc7744ae887cf08e5e7453eefebd71n/a 
2019-03-2666187271231886724702.zipzip b4a1c736baf15d862bba43844238df5daf0fbdd0cba24de4fcb5ef51fde342ddn/a 
2019-03-26US69495838542632.zipzip fc1647d65a53b45b05871fffb12ffb889e728e9f28a6c097c3934844b7d70764n/a 
2019-03-26239995878249.zipzip 5cae037a977f595c1207abda7d040ac7ca573e4e3fe2650df51fffd4e6ce7890n/a 
2019-03-262355998850882906051.zipzip 12719cf47a4fd45ab48730824eb00d2937811c43af55d59060cf679a7bfc54c9n/a 
2019-03-26INSTR928732486.zipzip 67dfe5f368585ae1a21108c42f56d4d01613b011e925fc9f3be3371ecfa32c5cn/a 
2019-03-26BA8432520280169103755.zipzip 572acae0af8027385ea8379e62fb5fa91d59dbd0336d5bc33521565e903ba51en/a 
2019-03-26INSTR2544467468087.zipzip 8a82e17585a2002673c71c037f5dcd6a489f9d54f76a1c0c30947d473ed174f7n/a 
2019-03-26PAY36606633704621.zipzip 4f532a4b7bc59ab0973b643ccc572b4559dd8827ff4f6d1d5dcf6047123f9542n/a 
2019-03-26PAY6315606315710.zipzip 64bfa2aa8fc33c247caddd4435ed9da3eb90ed9d71cc807cadfc581fe2dc79b1n/a 
2019-03-26PAY2524276999209133.zipzip e8f141554f184829c5e5d4364330ab2b84b2afc1336afe83973359a7651ab542n/a 
2019-03-26F4315817634898078225.zipzip 42012d8984d992a5d092c76a2d86abbdc77b604cd62359535c4a425bf08d9076n/a 
2019-03-2651649378367971.zipzip 890f3e25d65f3acafcee55000aac6decb341a377607a2a12e5ac448a8092b1c2n/a 
2019-03-26PAY4972927112335808479.zipzip 5ba7e0b26736c7bbc2a6fae29e4cfceb2e60203604da85fcef185eb63dfe70fan/a 
2019-03-262600792568452401113.zipzip 9156dda3447104f9b6402b5d6a6514f1bbe73797b33de8e1ae3b7b133b860777n/a 
2019-03-26INSTR3360581977156.zipzip ed3434decc0dd68b587fc5bf48367f347ea76c3bd911c194bbd5ae15b8884d8en/a 
2019-03-26US00169339570.zipzip cec51434027ce20543a4d35fc47c53ede4ddad0ef621dddd2e0a348bd81d770cn/a 
2019-03-26INSTR7727030877579.zipzip c1731566187856684c79a6e26645a9b964de02b0c0633c20e3e73029abd81433n/a 
2019-03-26ACC59693900203.zipzip 5dec7178efdf5ce4753dee496c459e253da867830d77069863128ea3eb6ee1f5n/a 
2019-03-26PAY4080024432968368.zipzip 52c26f9ae63b811b9c7b872b83f8c88515dfebb9fb795722616ca36f8c1b7265n/a 
2019-03-26US42169680998531.zipzip 543d709f578d924f19dd600a0bebd147fd70a1ee800db3b5977040da556183f5n/a 
2019-03-26PAY866820372655451.zipzip 47aeba7debccbbe970d4e88c82b75b7aa676e0a1962a76b2dd4e77374d4d076cn/a 
2019-03-26US14636709762.zipzip 776581fec089d71815b44b437071f3b17b36685f8b706d812b5b756dabc416c7n/a 
2019-03-26304649548970273089.zipzip 4358c36e1426c4b02892f098887672ec10990213ff1cf62035d2438b3d871cfan/a 
2019-03-26FX04319941020654195.zipzip 30850ad4635704a2290ed0e510100a83bcd50606598e2d9d994a928f12f6525an/a 
2019-03-26INSTR130484431657.zipzip bd572a11ddecefcddc31dd90057d18082e39a880d70bbabad49afaa325b83b63n/a 
2019-03-26ACC8440387244877.zipzip fb771233a121419894b410f4c0aedf6f74f9710dc16dfb6b3a8816df85ebaef8n/a 
2019-03-26US80640113056022636.zipzip a0bff53b2f9c20eb7a0db8cbeb3029e52131bba16756c60846c6740cdfca8829Virustotal results 37.29% 
2019-03-26INSTR9309116851242683354.zipzip 7ed0420238f047f6b1b00adcc2df892cbdd8919faf99c28a7a4fe599d6a57a03n/a 
2019-03-26US10546713997041137638.zipzip 3c590430a5f550cdd3c730e93d96f21457e11dc7283d81ef436b4dad94fa3a05n/a 
2019-03-26US117575474.zipzip 03865f31c7a1da51130cca9e83331765f5f2750acaace28c670202a3308abb2cn/a 
2019-03-26LYF19032973994.zipzip 3b6f11d5887b1c97ea468be82836b09105d8edb06ea4f000cad5a86c66185339n/a 
2019-03-26PAY477983599521388956.zipzip ef8375383384bb8b96f4aa3f4b494bc70afadf2dd92e0d5a4cdd34b865c84276n/a 
2019-03-26INSTR7791633505479531.zipzip b0f28a742fa4588da0632d432de5894be0228ae5d9c0755c9a47b1ad23d4ef46n/a 
2019-03-26VQN878712122.zipzip 2ddf61cbb1a0ca55e6abf4c795f1bb2a5409a1988ffccfd16899c5f2104338b9n/a 
2019-03-26WNO78485377072417.zipzip 6285d96bc4cfac1fc8ce1b794c9cd7c2d291a8d319ff3cbaa43881e3146fd5c8n/a 
2019-03-2607796895916444247194.zipzip 9b786dd01f8ad9b79f570917b632e8967d39b382de36cc1a67d8ecc7ea411a5fn/a 
2019-03-26INSTR66296658248989358141.zipzip c8413044bcc0bdf6dde60e3d24f5fec6eb4b4cc3e46579612ece59dd36137e59n/a 
2019-03-26932117222748068.zipzip 579cb08057d0c9e3026dbeb3b0a47a956eedfb350733f125e59a28f708a492b8n/a 
2019-03-26US8900870756.zipzip 351152991380320094da4bdfef936e8f19c54bc3a0c83685a6ed61a706ed18c8n/a 
2019-03-26ACC8289462133203707052.zipzip 5378c073805141779960a12cc2a11570c51655a5f0832d73402da3482ac40005n/a 
2019-03-26ACC260191029679593237.zipzip bb92da4568ef39bd5d54fdcf1ad8a18d1a75cf1eb75b2a75017cc01f22c20290n/a 
2019-03-26PAY44363736382.zipzip bbc8f97909b2440a4e7ebca9e0f57ecf692a7c0ecbc5a2dd858cd75ac0a4e781n/a 
2019-03-26PAY75964667444789807823.zipzip a53282eb345541831e64e3e43e93a4f87af93e4c67ce369ae3a8ae9f976636fcn/a 
2019-03-26PAY519801110.zipzip 099a4ca1e1437110fa59b27987524b23a6cb93958fb480e4d81202790b3717f3n/a 
2019-03-26PAY711122635876132674.zipzip 61ef14772207e5a92c2749aef91b75e1baf59ba417149a5d05ed9b61f6c1009bn/a 
2019-03-25BFQ221962168448.zipzip a83e4ec5c7a601760b1b7b1ccbaea0731ee75bbd5d44e47b2da83fbe828b9ca4n/a 
2019-03-25PAY331492224772.zipzip 3dc0143fd77a54b4813e99d41caa50c986b84cfcdd281f7ed6556f277d457684Virustotal results 20.69% 
2019-03-25858804776.zipzip c5b85e681780e3a5251eb0832c2d530f7c889aacf55e55c048e20b5515858115n/a