URLhaus Database

You are currently viewing the URLhaus database entry for https://www.uniprogress.cz/urc6gv/available_disk/interior_profile/52821679672116_rEnp7p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299117
URL: https://www.uniprogress.cz/urc6gv/available_disk/interior_profile/52821679672116_rEnp7p/
URL Status:Offline
Host: www.uniprogress.cz
Date added:2020-01-27 19:56:04 UTC
Last online:2020-01-28 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 19:58:03 UTC to abuse{at}superhosting[dot]cz)
Takedown time:14 hours, 42 minutes Good (down since 2020-01-28 10:40:56 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-28list WOE224.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28arc-2020_01_28-L601473.docdoc ee9887fd294a87ab64121883286bb7719cdcaa2efee9f5436b73aeac0ded07bcVirustotal results 22.22% Heodo
2020-01-28doc-2020_01_28.docdoc 256954bf735b73749d5fd67afbf6e789abb356f02cec192954e129996801d642Virustotal results 22.22% Heodo
2020-01-28list_20200128_1226.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07n/a 
2020-01-28mes 20200128 738.docdoc 0827a2ab4aa1c0caddd493489b6197943bc03b6da0d9f52c54071449dee6538cn/a Heodo
2020-01-28inf-20200128-003.docdoc 33d3ef3b1fb0f8ed8ed87b487e184b207ff302b60481dac9da9487ca210247e9n/a Heodo
2020-01-28FILE_2020_01_28_475334.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28INF_20200128_KPH52892.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28inf-20200128-LNE753.docdoc a021057a2d983bc13e1f6b1516cac0041546aa046e6822c87e09c6c8ba870b1aVirustotal results 41.94% Heodo
2020-01-28Mes P61374.docdoc 96a0ac595e820c4d5bfc99b40a351899b392f86b66e38142a1b6925a95424fa6n/a Heodo
2020-01-28Dat-20200128-RZX165245.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-28DAT-2020_01_28-1216353.docdoc 3927da4014a56e521774e33625a1ac60e65e39edee26dca5fc703fc240bc0c99Virustotal results 37.10% Heodo
2020-01-27File_2020_01_28_WE757.docdoc 8a5d48bf4570d69fd4c9398857cb6bde479600de838113e497e4d139720ab207Virustotal results 34.43% Heodo
2020-01-27Inf-2020_01_28-1583.docdoc 2d501d68c1e225c67050206bd812c1f22671ec54a92dfad493ac47c632194301n/a Heodo
2020-01-27File-2020_01_27.docdoc a8c9af0be1439e2adf85b682b03a2fb83562da6dd8c40ed6a07502d1ed966b2cVirustotal results 30.00% Heodo
2020-01-27dat_2020_01_27_5902544.docdoc a7ec27918dc9a1067836c1f033edd079851ae4f730710bc81033ec5602c615ceVirustotal results 28.57% Heodo