URLhaus Database

You are currently viewing the URLhaus database entry for http://polandpresents.info/libraries/statement/i6bkyofwihoo/t22f7j-757073672-96-504wghr-so1m/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270376
URL: http://polandpresents.info/libraries/statement/i6bkyofwihoo/t22f7j-757073672-96-504wghr-so1m/
URL Status:Offline
Host: polandpresents.info
Date added:2019-12-17 06:27:05 UTC
Last online:2019-12-20 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-17 06:28:02 UTC to abuse{at}home[dot]pl)
Takedown time:3 days, 8 hours, 48 minutes Bad (down since 2019-12-20 15:16:30 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19T_600734138939.docdoc 238a73631d56f28f899e8f237880c21328fccfe54514936820b7847042314d5eVirustotal results 31.15% Heodo
2019-12-19SW_ZG4653533255BW.docdoc e4cff33774c6680c4f2e21c49fd53035033df8960dcdd09ab257f157f3bdbd09Virustotal results 30.65% Heodo
2019-12-19PAY_084522509464.docdoc dac88026e19503104c7460e82892bf8c80344dca9aa806f070a2c8c3a8c92c47Virustotal results 30.65% Heodo
2019-12-1976238596.docdoc 8e0c8ce71d167427a04e9522cf9e4ee7f7a9eca9261c0dfa41d4d8f48a265031Virustotal results 30.65% Heodo
2019-12-19PAY_NE1892553148KZ.docdoc 8b3c8eb862aaab49a77ea334b938fd4142a954791de1e9c5a0bdc4c10406b7a8Virustotal results 30.65% 
2019-12-19GS_CZ0423365847FS.docdoc 5b18866c00b22906fc732bc27e409bd65993207586b1ae8844ff238a8e7631d6Virustotal results 24.59% Heodo
2019-12-19PAY_PO_12192019EX.docdoc 7b59717378331890255ad1aee1b7581861360cc08cb8285756a7ba1bf76a6bf6Virustotal results 24.59% Heodo
2019-12-18RP_LRI_120119_ICF_121919.docdoc 2f37a55acc32e7d59e31d6c98effdc3171e447d51f5aceea59451fe493461b9eVirustotal results 25.81% Heodo
2019-12-18PAY_PO_12182019EX.docdoc a45047f0f1d3e5adfee3b948c9315ce6f33843332393e92539e96ba64d0ac9c4Virustotal results 30.61% Heodo
2019-12-18TX1395682732YW.docdoc 5918d3a8e54c11877499a689b13606c989fd60c7bb1aeef67b9f2e69506a4f4bVirustotal results 24.59% Heodo
2019-12-18DOC_35614995568517628.docdoc 1afcdcabd698b87d447a39a408db16d5df715f7cfbf829cea0ee739405cd572fVirustotal results 24.19% Heodo
2019-12-18Q_29937810.docdoc 609841765bdca3673054d3e84edcf7c59fb9d7536638c7982a594af0dd1cb04cVirustotal results 22.58% Heodo
2019-12-18T3DC50YHV.docdoc eaba35ab5117f3e4819de4a40a56a6a3949a5214888b4c846dd485fd390229b8Virustotal results 22.58% 
2019-12-18ST_51810749.docdoc 83e5d3dd6d2e1ae224de8d75ee08d3ab332823d3c845777db0e532bf80851c0eVirustotal results 21.05% Heodo
2019-12-18FLT_DE2499025542QU.docdoc 267c6b931989c13475cfdd22641b07a8fe42059c916f87d6c3f186981e675709n/a Heodo
2019-12-18PO_12182019EX.docdoc ad7dec579b66baccb60add9fa89d90d566f2715c16cef6e8031799536348b736Virustotal results 20.97% 
2019-12-18FILE_VA2M6ZAFF18KE5NO.docdoc 50209c549032c69468a5dc7394910611814028e0e99895f6490c62a6f830d0fbVirustotal results 42.62% Heodo
2019-12-18FILE_86303792.docdoc d373501a4b3b0a680538b71685799902aec68074038e2ea8114d3efdbfb1182dVirustotal results 42.62% Heodo
2019-12-180021875379752372300.docdoc 2175e92f59d8610b907e3989d6fcd6789e81855f2c86efb3a4ea836f934daa9dVirustotal results 42.62% Heodo
2019-12-18DOC_6824662977373634.docdoc 7c7fe6921fd0483b165be4f787c8d10c0cc92e33a275dee48ab6454ced2df79aVirustotal results 37.10% 
2019-12-17FILE_YNX_120119_CXX_121819.docdoc 30d32e0187649a1613e5227d8764a5cf550f6458d7af759be91949fb28206e5aVirustotal results 37.10% Heodo
2019-12-17ST_MHZ_120119_TJX_121819.docdoc 6360b48ad6657937e29c8904108773ec3f145c12ced3eb0df2a0cafb10484ff9Virustotal results 35.48% 
2019-12-17RP_ZO6385087806FR.docdoc 3ded526749a42b3770415119aba7d4244e56db4c337c81f1adde6fc9ada6ffd2n/a 
2019-12-17ST_PO_12172019EX.docdoc b052f303261ad97b693c92155c7f187664dd9c144538ac447d7eec82cc8f1cb7Virustotal results 29.31% Heodo
2019-12-17HN44A7FO3WU63UED.docdoc 61d08ddc5f05c5b7acb180a46e81e35aa35cc5f695211bc65c74de0429b99908Virustotal results 30.00% Heodo
2019-12-17KN6305202220YU.docdoc 672852f4b5ac5999ddf37a3f4c78bd42ba59f458157c8548dbf758c0d52d5c6eVirustotal results 30.00% 
2019-12-17RP_07153922.docdoc 42913e293b320e0565aa4f879d96b649c5d3e0c8ec7bd8688c0f31ba399228b7n/a Heodo
2019-12-17INV_41222941.docdoc 1eac1fb926b43811a85ecb61a6401b2e5b3468f39eacba70f039c289c323a5d6Virustotal results 26.67% 
2019-12-17PO_12172019EX.docdoc 1804de5289b4a78128f1270148c48699f0e756fb6ec4e14b17cac1bd45c05919n/a Heodo
2019-12-17DOC_89239131.docdoc ad7c1cd86f24b8b0bff6ab945a5c4d279156763a10b4d85f805baeba096cdb75Virustotal results 22.95% Heodo
2019-12-17RL5722620594CG.docdoc cb58a6837dedb9f1a8dcf5d0a37dcc35a2e2fd90010e49b7ceb644e77bb135e1n/a 
2019-12-17PO_12172019EX.docdoc 21fb791ba9108627682a7450513994fcbc0644182399573b5601be6c609f0c51n/a Heodo
2019-12-17L_PO_12172019EX.docdoc e0aca6901229fe14ab6616fc1fdc88bbba7ec6b600a9d26f1c63dd59d7c9e6b7n/a Heodo
2019-12-17I_PO_12172019EX.docdoc 1c1f8c21ca0ec906bf5286c8474dfa5202c11b49646881c9919f07c6d3e781b8Virustotal results 30.65% Heodo