URLhaus Database

You are currently viewing the URLhaus database entry for http://egpp.pl/wp-admin/oWzWC4teU8698559ttLNAy1ETg7des/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1850469
URL: http://egpp.pl/wp-admin/oWzWC4teU8698559ttLNAy1ETg7des/
URL Status:Offline
Host: egpp.pl
Date added:2021-12-04 02:53:09 UTC
Last online:2021-12-06 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-04 02:54:19 UTC to abuse{at}tech[dot]ceti[dot]pl)
Takedown time:2 days, 14 hours, 21 minutes Poor (down since 2021-12-06 17:15:33 UTC)
Tags:doc emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-04RT6SDPM3.xlsmxlsm 1daa8dd90dce88a681b2f1c0c90f91872345beda7e72d6097ebe7fad40b1350fn/a Heodo
2021-12-04572MJ1YKY3Z05.xlsmxlsm 314e3d1e7346c183ea8fc1d5e99dac95786c5e7fc9bf415af7ac35882715ca69n/a Heodo
2021-12-0476WE0GNMIFED3IJ.xlsmxlsm 7f9b39a20fa33c77f9dcd15092cb393c3eca8869d02b437717a50d7872a2f718Virustotal results 16.67% Heodo
2021-12-04U1YSVYO20QMX0KMQ.xlsmxlsm 4392f053539c61c480e7128d85af7c7a04683066bbc965ba5f5c0038df7db369n/a Heodo
2021-12-048YW2YHTFZ.xlsmxlsm 42d0546265b3b06b9fc877c0f1b96ce12ad6fa739ed4e7c2bd3440ef432f475en/a Heodo
2021-12-04ZDST068ZI1B.xlsmxlsm 3df3407f4be66b2e6a46a434459f81cd519f680370c74b1b4493fd3db002a15an/a Heodo
2021-12-04U9XEKOG9ROD0V.xlsmxlsm ed6576577aed9e1fa7f17c290d5e4e62940e610bcd35080c821213c168a0e48en/a Heodo
2021-12-04HZEW5294N1.xlsmxlsm 172af5646f781093249052708a1971c35b4f78a66bdaeaa459aa3470a7301597n/a Heodo
2021-12-04LHASCIPJBQO.xlsmxlsm 40c783f354619be528e40820a0a7f98888ce228aaf88551732c6a2b66e60bf7dVirustotal results 23.73% Heodo
2021-12-04PV2LOG1NR3EN9D.xlsmxlsm 4cd06ae56d216f369c0fc1956d794e869e403b789872ac8ddee9cac00e9a653bn/a Heodo
2021-12-04G4HRM46P4.xlsmxlsm 3deca071fef4995683e7971915e8db86dee177c3332743c0b110abefdc49e909Virustotal results 23.73% Heodo
2021-12-04HLNBZ82ET.xlsmxlsm aadc859ad87c5f31121568585d28b8d34dd2c70301f30505eb8932cdee5e0683n/a Heodo
2021-12-04OCPKJ4FQOLMUY6.xlsmxlsm a76b0161fa986a158dd0e6a5c3507acef568c54ccdf88c23dbf992af167685c2n/a Heodo
2021-12-04DXOEQOITE3UO.xlsmxlsm 8d1341df99965e796a6ce6f0370620ebee7242b22673a90cfd1d2f448a3eb0ebn/a Heodo