URLhaus Database

You are currently viewing the URLhaus database entry for http://oknoplastik.sk/index_soubory/common_sector/external_area/61551354147_t4d0KY73JJyWFfGY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:267913
URL: http://oknoplastik.sk/index_soubory/common_sector/external_area/61551354147_t4d0KY73JJyWFfGY/
URL Status:flame Online (spreading malware for 6 years, 6 months, 18 days, 5 hours, 34 minutes)
Host: oknoplastik.sk
Date added:2019-12-12 22:13:15 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-12 22:14:24 UTC to admin{at}webglobe[dot]sk)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-04-27copy-59354070035.docdoc e4af70663a54d31298346ce3a84df867b260971e1242fa6e828682ab84378793Virustotal results 71.43% Heodo
2019-12-28copy-59354070035.docdoc 45e6bdde1ce127f43d33064edca9f74f3607027bc0d118c209f87222dbe7b63an/a 
2019-12-19copy-59354070035.docdoc 95569babf24186967f5d1ed9fc71f0985088a2ae27f720ff36016d2a52d06787n/a 
2019-12-13copy-59354070035.docdoc e4af70663a54d31298346ce3a84df867b260971e1242fa6e828682ab84378793Virustotal results 26.23% Heodo
2019-12-13INFO 0HM285359266967.docdoc 7e1d21e28dd1ad9af0a41622b3314c31e13926a44259a0c910d4f96b76e13a19Virustotal results 39.34% Heodo
2019-12-13rep-m32516rm2s9.docdoc 5dc9d118fef874a4dda79dcbe80c8a8e28be90e0d4b72ff505cb8fee2a66f939Virustotal results 34.43% Heodo
2019-12-1312_13_2019 519374459.docdoc 7e3fc66767007b391fedeeb939e62faf80c36c687d5847534fa3fe6c4cc2ffd3Virustotal results 35.59% Heodo
2019-12-13scan_FK35125101.docdoc e1ee794f404259882f7673fcab080b0fe33ce2765440db4d9398428c517518abn/a Heodo
2019-12-12rep-DA1197322149_55141.docdoc 1e552daec9804fe9794e69685e19dfdfc09b3d8a775697479ae755db4b1a6bc4Virustotal results 35.59% Heodo
2019-12-12scan L6891495.docdoc df0157b80618b7f71ca0304515b2c5689832d1bee6adfc4aad34d346193f0a77n/a Heodo
2019-12-12STAT_048459.docdoc 8fee6aa50549c270426eabb76131dcf93e0be84d92ef280856c6f761fa3753adVirustotal results 35.00% Heodo