URLhaus Database

You are currently viewing the URLhaus database entry for http://flexistyle.com.pl/js/nkcZU-2sXPtH-36724/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270280
URL: http://flexistyle.com.pl/js/nkcZU-2sXPtH-36724/
URL Status:Offline
Host: flexistyle.com.pl
Date added:2019-12-17 04:00:03 UTC
Last online:2020-01-22 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-17 04:02:04 UTC to abuse{at}home[dot]pl)
Takedown time:1 month, 6 days, 9 hours, 36 minutes Bad (down since 2020-01-22 13:38:22 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-20Bonus Payment Notification tUc781687.docdoc a14b07968da3e1a9ffcb312c2f65d9718242da2c6b3b8a98a6dbc7140fa23a31Virustotal results 73.77% Heodo
2019-12-18Bonus Payment Notification H21278848.docdoc 7ecd418f499c379ce5e26a430ee6b3c012aba02686a78c7bb652336666fa8873Virustotal results 43.55% Heodo
2019-12-18Bonus Aw2125.docdoc a3586470404b553e9048f8b822a362d419e170a2249ee10965f8f597d12a60feVirustotal results 41.94% 
2019-12-18Bonus Payment Notification G9302367.docdoc bae97d7f1b776e06c4425f1f40209eb0f9be839818b4d38ddcd4dd9148bee55fVirustotal results 39.34% Heodo
2019-12-17Pay E328.docdoc ffffede7ea632982a76b1b3afa34b322ed75cd9eea5dd11dcc43bacfb0d10917Virustotal results 37.10% Heodo
2019-12-17Bonus Payment Notification C353.docdoc 41a08ef8f1c194750f269c5f26c787e405d4002a3a091c4f95656005febf321eVirustotal results 36.67% 
2019-12-17Bonus Payment 496065.docdoc f0d160ab24154b700025e2af3a42551440b47b9628338808f823d77b8538f3a3n/a 
2019-12-17Bonus Payment jV1719892.docdoc 64e2f49cfdf6fabf6bce465fe1826c47f3dfac443dcdbec6b92e908f07dee278n/a Heodo
2019-12-17Bonus Payment Notification 794746.docdoc 29d697765067c3697dfb256faa280ce17731733a0aae35d2e86cba06d898ad2cn/a 
2019-12-17Bonus Payment 203590.docdoc 4debd65e5eae6541f0ce1a0e039ccb8a59438c9cb515820b6260f77b08f02065n/a Heodo
2019-12-17Bonus Payment Notification Y213749.docdoc 6b7c34d5cb597e4144608ceb867fe0ba1ff6a94564da88d1db8cbd050397bc90n/a 
2019-12-17Bonus Payment Notification E509278.docdoc 11609d6fef162c18390a302feed05a4ecdb2967762a2dab7dadca59a5526efedn/a 
2019-12-17Bonus s14541.docdoc a1e17db1817375edd6735f442bb2e7778952f5bce34d02f42059aeea8f672e11n/a Heodo
2019-12-17Bonus Payment Notification cwS4339.docdoc 9dc1afce7d2bd7ec6d7b0da2d7eff6b3dcfe34620272b3620ae299e4396a5e3bn/a Heodo
2019-12-17Pay Payment 6015006.docdoc f02bbdeddbd63128dca626ebf310781748d96d3d662873bd212e89a37851f086Virustotal results 25.81% Heodo
2019-12-17Bonus Payment Notification ky69383193.docdoc 61238acfcc8bdd6c0bfdb44167021cd20457a4b50e10e0aa4eac11a9172dc59an/a Heodo
2019-12-17Bonus Payment Notification JO200.docdoc d559467faddfd252937be53ec6b8f8f182cbdebef502484860f4f7ca575f1282n/a Heodo
2019-12-17Bonus Payment FNs67968512.docdoc 7e076bec50d066d433553b8134f680ecb65ec425a10535dd8ccb52d6da3e16d0Virustotal results 19.35% Heodo
2019-12-17Notify X233775339.docdoc a0a0e9f2908955f2e6533d1c10a96868fa4992f37397a64071260f4726b602aaVirustotal results 30.65% Heodo