URLhaus Database

You are currently viewing the URLhaus database entry for http://lightcraftevents.pl/lij/cpx-6f8e10z-sector/close-space/5003016-evH5iPgLn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299359
URL: http://lightcraftevents.pl/lij/cpx-6f8e10z-sector/close-space/5003016-evH5iPgLn/
URL Status:Offline
Host: lightcraftevents.pl
Date added:2020-01-28 01:44:06 UTC
Last online:2020-01-31 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 01:46:03 UTC to abuse{at}home[dot]pl)
Takedown time:3 days, 12 hours, 12 minutes Bad (down since 2020-01-31 13:58:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29doc_20200129_D50472.docdoc 1b043ddc5486e72740b53662fc26cca570e5bf2a62c8d792068bbd0945dbfc10Virustotal results 27.12% Heodo
2020-01-29mes-20200129-O7640.docdoc 0b0243567f8017cba7be007b4d797731af10a9c7e9971cb09881d0a646bf88a2Virustotal results 30.00% Heodo
2020-01-29dat_2020_01_29_001884.docdoc aad9025b37d955a0929dc76185e7b87d374e735e3a30a258bd549dcfc7a1bf27Virustotal results 26.98% Heodo
2020-01-29ARC-OGE026976.docdoc ff622f5e5e3370bc68d5d00d00bb610357cc7620c1ccc8a6f8edc051119621abVirustotal results 25.00% Heodo
2020-01-28arc_7018033.docdoc b02f5992112b97e3c27af09e9545d7c21b737aacc8915c8c4f5958b4ff93b677Virustotal results 25.40% Heodo
2020-01-28LIST_116588.docdoc fd375e3e635e2233a2c582c4aa48c277ad9d0bc9b9b8d498d9c632641e894c30Virustotal results 22.58% Heodo
2020-01-28MES 20200128 RFB45913.docdoc efd0700b8fc601cedf3404aecb9e26b1207bd865efc6ce6f872c42856c5a1b46Virustotal results 39.34% Heodo
2020-01-28arc-20200128-4651819.docdoc a021057a2d983bc13e1f6b1516cac0041546aa046e6822c87e09c6c8ba870b1an/a Heodo