URLhaus Database

You are currently viewing the URLhaus database entry for http://bf2.kreatywnet.pl/owa/sec.myaccount.resourses.biz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:171002
URL: http://bf2.kreatywnet.pl/owa/sec.myaccount.resourses.biz/
URL Status:Offline
Host: bf2.kreatywnet.pl
Date added:2019-04-03 23:33:02 UTC
Last online:2019-04-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-03 23:34:05 UTC to abuse{at}ovh[dot]net)
Takedown time:21 days, 20 hours, 10 minutes Bad (down since 2019-04-25 19:44:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-052019_04___REC_5567676826___77138300393.docdoc 6daf0a0a5112444b7ffa2012fd62794d1658e21a79018fc3a69d48d6c99d4a8aVirustotal results 29.82% Heodo
2019-04-052019_04___YO4493144331818205390___5050372826554.docdoc d72aab1ec1befb352a29892128bd8aba31531e6d965f903973fbb15bd2f71584Virustotal results 27.59% Heodo
2019-04-052019_04___YKZ6005634271540___126154044964317.docdoc c780a6f13f0470fcd095ed94d7c2e8a961d585b82b8e339646716658e9632e4fVirustotal results 26.67% Heodo
2019-04-052019_04___BIZ_459735888578240321___2695362330.docdoc aa4dbc44304abe8aa207e31f7f0eaabad3933dccd1c3d004ab68edc87e75cee5Virustotal results 29.09% 
2019-04-052019_04___PAY_554945148041___588509585.docdoc 60973bfc7ccac458d9ac4b7192a40774316b04d86cdb106b0c205d75778b7c65n/a Heodo
2019-04-052019_04___RECH_7467962970488065522___03111410549094684.docdoc e8ca6c66c79cca9404a9f6a6920ff02010dc799435381a97fd5c57cf0c3abb41Virustotal results 28.81%Heodo
2019-04-052019_04___RECH_255936700270___53163264761644629.docdoc 3a119906f5ccc2ff4f39245ba6d788209a21ae74131854b3347facc6854308c2Virustotal results 27.87% Heodo
2019-04-052019_04___RECH_548044115545___16524947299540838.docdoc 2b83ed3d9103e35ebc811b493ead34f4f60acaf05dbc67be7fcfcb8845863effVirustotal results 28.81% Heodo
2019-04-052019_04___PAY_189678460522604550___5427054887.docdoc 23d3fe9d332bb9159964b608c1099f18f980c434b600c9fe82c53b9db30a80a2n/a Heodo
2019-04-052019_04___PAY_0915828007265136185___461810394522237.docdoc 3cbf2d0b6a25ebefb9e39053c09ea1ada864ad2d2e2e6b20f97054ba14b35171Virustotal results 28.33% Heodo
2019-04-052019_04___INSTR_226466564___1482657003232198.docdoc 07be913ac6e2caf9d7104debcda9d259a8109f7f45693f51e7a8125cb8b87cb2Virustotal results 29.82% Heodo
2019-04-052019_04___REC_1145302285188240___45048867639.docdoc c6a61e437e4b6f487932736f0c5a8e7c78b146662073f7f66c07791c45e81eaaVirustotal results 28.81% Heodo
2019-04-052019_04___PAY_692767483991735396___5166513208427268.docdoc 83311ed9909cc46c0b2ef39058079c5eb695bf5097a2c558b021846c026cb1c4Virustotal results 30.36% Heodo
2019-04-052019_04___PAY_6231577549899___573449749582271995.docdoc 17dad3ebd5a305c0a8b9218d3bf755d6f335ee4e3f4f9eb28c791d8cc031f910Virustotal results 27.87% Heodo
2019-04-052019_04___PAY_34162875922___2464011033.docdoc a815f881314204ccc95a61305add749fc5bfcab40834f81c1dde379c1a925459Virustotal results 28.81% Heodo
2019-04-052019_04___ACC_214431869345___04096019983.docdoc 95e2fcbae5239d38b9f8e6ff9fcd7e564bffe3e6113318a4fa2dfbc05021840bVirustotal results 28.81% Heodo
2019-04-052019_04___REC_3288724828712199770___93107864974163587.docdoc dd734c5b35c341d12667dc02ed5968147fb0a5e3d863060ba689feabfefdda8eVirustotal results 26.79% Heodo
2019-04-052019_04___RECH_90153418109506883___352668684556874.docdoc 7a23ac39371c6f8221945e18a2fed9448cf4ba84d1568df78e322965fb6ff04en/a Heodo
2019-04-052019_04___RECH_14306720057708298967___629389547.docdoc b8db19d850436a52dfa3200aa0507556070b2d93b4372949c30305732683cc61Virustotal results 27.87% Heodo
2019-04-052019_04___RECH_47196441712___9509900557531457.docdoc 72f7d221856efa7923e2d504f4964be87b37c8717712d7a4bdcc4e5c1569b554n/a Heodo
2019-04-052019_04___PAY_309065463368949007___609439004107.docdoc 70c931d886b8ae950f3773bb5010c918bd26ed8892abc548a393616cf2993b97Virustotal results 24.59% Heodo
2019-04-052019_04___IVM193670504330752___800287089428.docdoc a34f8dbc40f159b861a1eae989cb790ae9b4d745d7e4c10f5f47dd40aef83722Virustotal results 30.51% Heodo
2019-04-052019_04___PAY_7777076615___770379900071.docdoc 9f1f0f2d2ce1829eefc8cb32e65c611afe318002fd3e4bff5c00c7d2b8c17e91n/a Heodo
2019-04-042019_04___RECH_16513755729125___16101707139489552.docdoc 70205a997c7f45f73a739e3bca30eeb77fee3e34c4fdf6d550c628be87493a68n/a Heodo
2019-04-042019_04___BIZ_61156462378___8557214696448910460.docdoc f47cf655028e2d8b1b1c693023bda4d52ae45719cde3a8da27732e53fca40ec6Virustotal results 25.86% Heodo
2019-04-042019_04___RECH_862944978595137653___4941826573287492.docdoc 846de79ac0303f0d112488d628f7ab3a7dafaf485b48fa2e86f227b72d6a3b1fVirustotal results 26.67% Heodo
2019-04-042019_04___REC_85884812968726767___561611339807.docdoc 20f91ba72b23055af90dbe56a8ce1d856e9f7a5747861f7dce96401daaa08027n/a Heodo
2019-04-042019_04___ACC_2391921177877255___6555197666179829.docdoc 2bc85560bf9dd14e7013cee1de0d62c8c505005b81fdd4531a0233e60cc4719an/a Heodo
2019-04-042019_04___INSTR_040835837597148___79919778944.docdoc d1e1020f26ddc8c35f4b8c38e71b1a1d4a07c8a5092c0d2a88196bc12cd40ce1Virustotal results 25.42% Heodo
2019-04-042019_04___RECH_679277302378270032___7531688115.docdoc e28a3f7f664601b483134a91e119bb156ed20942b2d24a075a427fa21f183000Virustotal results 32.14% Heodo
2019-04-042019_04___DOCS_41621603341935232___036392672605422939.docdoc a677aa9b7510a52a28d0e03a40e2ce79666477621c7d858b718cfa65be4d29d4n/a Heodo
2019-04-042019_04___REC_6835548862___984906058163.docdoc 7af8906e615fa16dbc9068ceab0bf4633d9b957c851f62b3d7c82c95fd68ca20n/a Heodo
2019-04-042019_04___BIZ_738017722___100039594476161493.docdoc 72c1db1cb5edccebd0b4145f49357ad68e5f570843ecaf001dec81bbfd8ff178Virustotal results 31.58% Heodo
2019-04-042019_04___ACC_9422825218066094977___883123424066.docdoc 66fae3eb56aa085c40dcf7654478c3aad5920549570ea215759f478698e6efe8Virustotal results 40.35% Heodo
2019-04-042019_04___REC_7127859790___0190600513579285828.docdoc da7ea362dcfaa616cf2a12ecb73daa9f6087f5a135a0ac13a2d5119a86d780e2n/a Heodo
2019-04-042019_04___REC_000788885891766076___894203152044794.docdoc 50f394e9b9ca8ab7439bc459b21ef08a5c3654ca49b459d113b10e05785dddc5Virustotal results 34.43% Heodo
2019-04-042019_04___INSTR_79581745889703757___071982290745687.docdoc 91afcbd38278ce562d89502a7e3e2daa8c90bf13ff2d490ee70bac8f24233bd5n/a Heodo
2019-04-042019_04___INSTR_714850334584___1199789676515265013.docdoc 3b27c9a4b443660f21426d9a1430a068c210f6fc757ba017f0db5143f7239dcbn/a Heodo
2019-04-042019_04___INSTR_1049398235___516055930429685841.docdoc f1b1dbb226dec92d179a1e42170a630f04adcb82c199437a5172a41a86ee7e62Virustotal results 32.14% Heodo
2019-04-042019_04___ACC_16800869247125280___638879409740.docdoc 0effc9bcdae3a1f1eb8f1d08f2b01645ffd8874837e2dce3673b0201eb04b840Virustotal results 29.82% Heodo
2019-04-042019_04___INSTR_03920598739564___994161718289303661.docdoc 02a856b38e7c32e7387f663af577ca0e854e1f2d8d8363697a7b9ce410b3a0baVirustotal results 31.15% Heodo
2019-04-042019_04___BIZ_688421868580___2810085246335513.docdoc 1232e66429c4b02677cc0839b9bb8011f3643b53d904641a2c5d14dade5e1f71Virustotal results 31.58% Heodo
2019-04-032019_04___PNC5336532780352763597___8007562803.docdoc 8793144bd36b01ff56228ab7714f0b66d8d99c60b009fa5740a21828efd2b38eVirustotal results 29.82% Heodo
2019-04-032019_04___DOCS_714466505923630975___01686391356.docdoc c546488c5f0a56ea6063a375ef7ea194df3020e92b724ac5f1bc14e7ea4ed9a5Virustotal results 29.31% Heodo