URLhaus Database

You are currently viewing the URLhaus database entry for http://bf2.kreatywnet.pl/owa/AdRx-rdzF_FjmDy-wF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:167550
URL: http://bf2.kreatywnet.pl/owa/AdRx-rdzF_FjmDy-wF/
URL Status:Offline
Host: bf2.kreatywnet.pl
Date added:2019-03-28 05:34:12 UTC
Last online:2019-04-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-28 05:36:12 UTC to abuse{at}ovh[dot]net)
Takedown time:28 days, 14 hours, 8 minutes Bad (down since 2019-04-25 19:44:49 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-292019_03___US___INSTR20761433583117534964___280743437203555152.zipzip c3b5207ce1d1ece717af3ea05342f3a3db7c6ae28bb713cf643b8e8b459c4c3fn/a 
2019-03-292019_03___US___ACC7490522982563519___1217721698329623.zipzip d652d6ea1a3e61bc8098f3efd6fa683e02c9e7225d4c7451e05f3906f9d038f0n/a 
2019-03-292019_03___US___VNAM963453848837223___0334782452295.zipzip 585e10e8ed72e5a64458a870bd92e15e3bbac662ae196e0c06a03411782f4c6en/a 
2019-03-292019_03___US___PAY3294729393786236129___14674369196475622.zipzip b56ce4f91e1d32f28c1b60ae026c967613b290c2cdcad9490112d8552a7eabb9n/a 
2019-03-292019_03___US___PAY750562696452___00007480573965.zipzip d2b487e838207debea967e6466c42c95b45c7c1ef08cb2833c89bf429b647d7dn/a 
2019-03-292019_03___US___OPXX9646592229861___29583342239541067.zipzip 7f6a639ae257c92c1e6d82e70f2014013fef97385eed5f03f1a02d998982325fn/a 
2019-03-292019_03___US___PAY72308302334805___6115303252.zipzip b1ded3ff77ccfa438266ee204bee3e50782a4b558e875156a22c52f93b88d9bdn/a 
2019-03-292019_03___US___0582189667707___122408684.zipzip f05d91562b8412587aed70ae5e52ef9482fea0a5d6e42ee220453f8210e9b3a1n/a 
2019-03-292019_03___US___PAY92573052080177896166___058617024066148.zipzip f5ed4c998285a45529dc52f2dd7bd3254965c2b71469a14714e82653ee0deb40n/a 
2019-03-292019_03___US___INSTR95948807951___0309675320.zipzip dc212f4e56f538dd298d9819a53ccb5eef44dd861d1eb43b256b13c6730ec56bn/a 
2019-03-292019_03___US___US208026771308635___40688269613380483420.zipzip 120dfb8017cdc042642ac300dd81b4711e9b4089844410f92076f9899be2e8b0n/a 
2019-03-292019_03___US___US59791990948___421655450389778.zipzip dab5fe6152d5df0af8e2838e71560d4d22ec7c480bd47037d826928d47978d40n/a 
2019-03-292019_03___US___ACC606022984853619___65578257368.zipzip 0cb8436b26dbbf2b40b50be834d541551375289b1478a59e6cf14cce7231b21en/a 
2019-03-292019_03___US___INSTR6403240990___1569735342737.zipzip afd6858e36061bb03d01a83b77bedc2072893073c92c157683a12be0bf69886bn/a 
2019-03-292019_03___US___HO8386854376___84920566007.zipzip 31503722645ed1a357f0b0897b651e239e8ec9deaa9890707b9e928716fd52b2n/a 
2019-03-292019_03___US___US8292185324___29219916009819479.zipzip e66cac21a895996c7b4e647e507782aebacd2383a27f844de2c9d69ffa615fddn/a 
2019-03-292019_03___US___US0779613878811___2668958773100203.zipzip 14a0ace0aa77dfbf8295570ba79166a2b895fd6d52a99a6939526bab52177997n/a 
2019-03-292019_03___US___INSTR340022078___888851557.zipzip 3c4a8c93b8c4c3eb76b39b048f17aca764f4ce1feb79bf49cdcf42a15618cfbfn/a 
2019-03-292019_03___US___PAY5061795512339657808___55791480717354062.zipzip f665119fac0fa454e00870ed59a9315333456cac8e21cdb4988d5ae94512876dn/a 
2019-03-292019_03___US___ACC040700484___42071656199.zipzip 53fcee8651f0a98d620510f5fd0429189c5a38836d5bb2aa4d2b9f523b77c5f4n/a 
2019-03-292019_03___US___US7644982039586___641441216440596.zipzip b7cb2431ac398293681314ebc4c31da04288e21a1b300fae2eee4b72c195ef24n/a 
2019-03-292019_03___US___PAY476897009551___467111015318775.zipzip fb51fcf324a66d6edba6ad7e2045babccc89304eb242ad71f2962365ec506dfdn/a 
2019-03-292019_03___US___INSTR52608551125___94196864299181069385.zipzip bfcf23bf2193dcf9204d21b5c00a3ed6743be73f9d7c96497edeec58f9c07291n/a 
2019-03-292019_03___US___PAY566233757803122___4678870642560288536.zipzip 67b15b0a247c6ce53e0ae456f1256aa3590f50ee5e628cde9ca4373b4e2449a5n/a 
2019-03-282019_03___US___INSTR55183174440086___2374952894276639721.zipzip c2a73b4560ef68938a54b98e4dbdd0fe30d6db248bbb1cb3a7a34ba132f86666n/a 
2019-03-282019_03___US___ONAW45733644011034___559758714185.zipzip 99c8a905a4bc0c8c8a073d8a4b1c0829805a1f37d4234a5119efc7322b1c85efn/a 
2019-03-282019_03___US___PAY1636295692166___61074828234795926.zipzip b66054f01f2deb06fb128cc48e929f9f738d4cc859831386b5fcbbd581c56b6an/a 
2019-03-282019_03___US___PELE0495338782216___85378373795542.docdoc 55272816d957c8d610f15e20aff8e0f30f8ae00e9cdfc521a58e7340c260f589Virustotal results 36.07% Heodo
2019-03-282019_03___US___INSTR6547346432___5556679659.docdoc e61cd73fd942c6d8d51c67996e8a694be145fd9a437f3bf641239e6b666a0b59Virustotal results 20.00% Heodo
2019-03-282019_03___US___ACC12371227385790007718___548252821082413.docdoc 5fb496b7cf14a06587beb677438952c01970f944074fd93fa7d766d2914f8d81Virustotal results 18.97% Heodo
2019-03-282019_03___US___CS2133473881864___007135283.docdoc 1fc29c69095fb42c2f1c55e5f7121de7e7c0c016686d6d0be538607ebb24bd09Virustotal results 23.73% Heodo
2019-03-282019_03___US___ACC4977863544___01817395017318.docdoc 3e871b698dc5613e3d7c241a32e8eb07f2a0ea98204e151cfb119255c6f28c65Virustotal results 17.54% Heodo
2019-03-282019_03___US___US847114992581274186___25242636049800029.docdoc efb1a538542b611b7775e9d926d74080f8e961862f7266f2f0b67fa868061e9bVirustotal results 18.18% Heodo
2019-03-282019_03___US___US6787525854873553___9704772629346382383.docdoc 39222e69f8f78afd9eb11b00811542e3a2d42ef2ce8888474ec6a584cbe41915Virustotal results 18.18% Heodo
2019-03-282019_03___US___ACC7577887104059___55219017888.docdoc 24ecfe71f85e9c8d734e8438171c62e5982fa9962e28600f2dea828b91d510b8Virustotal results 19.64% Heodo
2019-03-282019_03___US___ACC51249518510___88123471422734285.docdoc c6483d11cbc8b37ebdb393c4c01b38ca9354a09e9214a713e2354cfbc7728672Virustotal results 20.00% Heodo
2019-03-282019_03___US___PAY0240474633564750___09322515016.docdoc ad5faaa82a6caef20722faf6fd1efd2d441b0e8362210d6e57af6ed666b62769Virustotal results 21.43% Heodo
2019-03-282019_03___US___ACC218344071310707___930366179836.docdoc 7d805fd6032eb14134efe16f128638bb6ea296911ad55fac6340ace72707f251Virustotal results 20.00% Heodo
2019-03-282019_03___US___8466068656___275388146511114.docdoc 1da44ccc2eb250ca1283e6b12e92d326169112ae88c9b1b9800fa1868257628eVirustotal results 20.00% Heodo
2019-03-282019_03___US___4989168313525___5698674892729226.docdoc 084d0997def7560fa87cb31751f21177cc3d0efc904a4901472b2cdb5225ee5cVirustotal results 20.34% Heodo
2019-03-282019_03___US___US0054667079___26656866458.docdoc 0bb5157cef6593c7290de8585fc9de492de2470c795b0d8afe3806acd00c2ed7Virustotal results 18.33% Heodo
2019-03-282019_03___US___871096727505445___53129091061165199089.zipzip 0054aeb7acc483ae66b6def9dd1bfb20a102a2be47d2464737f6ec56a9eae4c1n/a 
2019-03-282019_03___US___DWBX480322711___155924181.zipzip 14253329b74456dba957d012aa7735364782ea3a48988cf5c48415d8b454845bn/a 
2019-03-282019_03___US___INSTR4604165022___2070472615.docdoc de63afa47476b9b004e6895584048b955b65c608bda044f359e654e9997fcd51Virustotal results 19.30% 
2019-03-282019_03___US___PAY125878446821___59929556758694.docdoc f7c389a98aa92bea8e2dc4f4c99a310a8351ab4dbc636cb4c41b00df79ea5c95Virustotal results 20.69% Heodo
2019-03-282019_03___US___PAY07827004993510574123___92666356644942.docdoc da6b8f02973ef4e3fd130c144e7051b7cd7e80a521ade52492b859ec517978b8Virustotal results 19.30% Heodo
2019-03-282019_03___US___ACC283048316141171801___58881092246934319968.docdoc 608c8116b1793b51d17786707efee242c6690456515005eb42a7b0cf56da386cn/a 
2019-03-282019_03___US___ACC0200655620186226422___0757882967636109.docdoc 9a86d9a82a87e2510fe2814eb2afa2c3af8c73077ebbaa6b785f23148e4901a4n/a Heodo
2019-03-282019_03___US___PAY191727237767865___96056701361323797950.docdoc c73b153ac9cf42cc3fada057a60486d5d9c55934621f5808ae659702c8f179c0n/a Heodo
2019-03-282019_03___US___PAY398739584586853921___0639643619758519.docdoc 2b9604bae3248d8a134c549e86ca36649cb5e558a08e9e2a60d476a31b0294e2n/a Heodo
2019-03-282019_03___US___US898379881448457586___02161829430.docdoc 939fd6d752669eeeb3bf135cf1a64fc38fb3ae650b85f1fe3fa471100bb28981n/a Heodo
2019-03-282019_03___US___57350509843___5217130057.docdoc d73ab573a6281e5c1cd6b4ecb2e7ee89e29686ceac30906c480d948a7ad1109cn/a Heodo
2019-03-282019_03___US___INSTR76815814327855___2586249157465647280.docdoc 6d8d966985206b4f06bad79e5bc13d92f0253ebaf7ec9bd60df7c0cf06589737Virustotal results 18.64% Heodo
2019-03-282019_03___US___03933801945469531___2858601007.docdoc 18553615f6a2067c0286de4003621934804eef8b983dfaf4a35768221f0878c5n/a Heodo
2019-03-282019_03___US___ACC93786709668337998262___4764383584876.docdoc 734d527ffa979b6019c9ac4a16bf3834739816d2ed3efd8154fbedd66be450a4Virustotal results 18.33% Heodo
2019-03-282019_03___US___US80484783941___3945251635838535978.docdoc 5aa86074410aa1b1c35bf87c5546c883a4da6b2bec413e06e42dc56a133cf298Virustotal results 18.64% Heodo
2019-03-282019_03___US___PAY7092473100169___90470718564.docdoc 3f4af62e65ef4eed255a1cfdd1a2bcd54ce49e3f7b80997ccf1184e0191b697bVirustotal results 16.07% Heodo
2019-03-282019_03___US___PAY616966419___9327196969788.zipzip 376eb57b1b3c2b901ebc4aaeeffff3ac90311005b523e3ad9df7075d79f1d5ecVirustotal results 33.33% 
2019-03-282019_03___US___INSTR56336819137886___197192978.zipzip 8e28db577e39bcfe89425f1e3346a166ff88bda1dfac0eee0194b06c3ed62efdn/a 
2019-03-282019_03___US___ACC804079021140393380___915906845.zipzip d8ffe15cde930efa7ea23195a2c99b1a0085ba05a1bb86f34b1692113d99d31bn/a