URLhaus Database

You are currently viewing the URLhaus database entry for http://disweb.sk/lfHCegwZndgMs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2120473
URL: http://disweb.sk/lfHCegwZndgMs/
URL Status:Offline
Host: disweb.sk
Date added:2022-03-29 19:50:07 UTC
Last online:2022-07-13 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 19:51:12 UTC to abuse{at}websupport[dot]sk)
Takedown time:3 months, 15 days, 12 hours, 58 minutes Bad (down since 2022-07-13 08:49:19 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31XDR-6248983382184.xlsmxlsm 36b9445ba8e049935f86955d9c9251334fa60c940b28d69da57f97926e54211fn/a Heodo
2022-03-31GYU-971844247731.xlsmxlsm 290c0e20e4f877da89d3afe0a9712332a45707d9c8a0e8303088cc72ac4285adn/a Heodo
2022-03-31JCM-39430423.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31LGX-059684595101.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31BKM-6087286266.xlsmxlsm 64c57c337892c7579a7c6d302233570e6f2450b0d0152b3b32de811347079a2an/a Heodo
2022-03-31VO-7106596573.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dVirustotal results 38.10% Heodo
2022-03-31FY-26464111995.xlsmxlsm 8ffdaa8f731fe2148ad8c7dd79ce44c3dc17eadb46af64c64a76395fd0e629acVirustotal results 40.00% Heodo
2022-03-31UYP-253225599345467.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fn/a Heodo
2022-03-31XBV-9319618063922.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31LHS-45600553.xlsmxlsm 4bf2a2327ebd2d1421b849168375d718ca7eedfca6a369b4d947836eba831db3n/a Heodo
2022-03-31PCO-023608287727564.xlsmxlsm 70c7353a1e172d428b42bed59b7ddb9a6d1b60c368ec7ae5eb64c0eeed368080Virustotal results 43.55% Heodo
2022-03-31PQT-775863678653.xlsmxlsm 93e06d8850641586fe31c662da490f8ff442f4f86021f50799e1174dcace1f72n/a Heodo
2022-03-30KYU-174926545495.xlsmxlsm 2b1f1f87033e83e264f05939f180b63165e067861f9c6f1253aedc9c9e1efb6en/a Heodo
2022-03-30AB-8970395.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30SLY-8846420503.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30IUW-93855189261.xlsxls 403c28ce1df56f185d0824575299bea20d7d1738e6a9688c551d039b6d1aaea2n/a Heodo
2022-03-29n/ahtml 15f2d2dc16656206cee150e91dcd2884701c706715949b81e3f02eaa24b12f8fn/a