URLhaus Database

You are currently viewing the URLhaus database entry for http://horal.sk/lm/protected-GwJhA-F49HcaNS5gWP54/security-forum/mdvdlAG9bV-HLI0tI7ztmNvm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308943
URL: http://horal.sk/lm/protected-GwJhA-F49HcaNS5gWP54/security-forum/mdvdlAG9bV-HLI0tI7ztmNvm/
URL Status:Offline
Host: horal.sk
Date added:2020-02-05 11:13:15 UTC
Last online:2020-04-16 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 11:14:03 UTC to ripe-abuse{at}swan[dot]sk)
Takedown time:2 months, 10 days, 21 hours, 38 minutes Bad (down since 2020-04-16 08:52:41 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07rep.rtfdoc 9e0f471dcc7e1f874dc550fa5ea840391bfe33e8576e26218351b6fdbbd75b33n/a Heodo
2020-02-07inf 2020_02_07 B2370.docmdoc 9f2b441a576b8b1d1a2af975d5d53633a4000ab8ca1f6df2e88312e175a47595n/a Heodo
2020-02-07Rep_22950.rtfdoc e3adf368b634569aa1ca2545bb340ffb5df4c918cf629e3afec00b6f43d444fcVirustotal results 24.19% Heodo
2020-02-07rep-XH07872.docmdoc 132db44bc08611c35e13cca6b1bf4d7592f107cf9c0126aa2bf055f0953f0975Virustotal results 24.19% Heodo
2020-02-07ARC 1896987.rtfdoc 006766d9879f75d74de2c385ce8418fb838989af2046d8d329ad6ae7dc6d26ebn/a 
2020-02-07DAT.rtfdoc c8a251f2d070fafec42b79dbdd0e73a0993c8cfd2a5f1a69722327dd810742bcVirustotal results 43.55% 
2020-02-07rep 2020_02_07 641609.docdoc 60a2db35f6a200f89387811492bf70f40551c72578c80be36bc21dc7abbcce67Virustotal results 43.55% 
2020-02-07FILE 2020_02_07 3112.docmdoc ae0dba6208040d7656556bb876279d0ee3708e7cba62fdf3777e81466021bceen/a 
2020-02-07inf 20200207.docdoc dda86e610dc7cd7c6dc32877c7933dc7c341e6e57f35219c82c674fb4f85f7b4Virustotal results 35.48% Heodo
2020-02-07List_2020_02_07_39348.rtfdoc 4de743bb5a807944570907fec4e4ca12efe2016c5c50e04f718ed117b26a76eeVirustotal results 32.79% 
2020-02-07list.docmdoc 92b8d8f3f3a3e0ad2e5f751cc4b2df9f4d01027617eedbc44823360bdcf35491Virustotal results 30.65% 
2020-02-06LIST-20200207-4181.docdoc 2ab5454468bf092401bb674e12f9577b0102b97450e07cc6ffdbaec61eb40953Virustotal results 29.03% Heodo
2020-02-06File.rtfdoc ac7760c7ac85f9e8058a9af1862e8b503ba18efe9bf1ebfc820845a33714ea8aVirustotal results 29.51% Heodo
2020-02-06doc_2020_02_07_134718.docmdoc b7676cdb8dc6fbbbfb658a4eccf03a5c3290883a4fda239945b7a3c012950ed1Virustotal results 27.42% 
2020-02-06arc_555.docdoc b6a866cd6767e85ce9779e18601e4ff38f6a25e8bf459d47936489b9d58ba9c9Virustotal results 27.42% 
2020-02-06rep ER468.rtfdoc 69caf04e8e1e56614bea23015c10066190147415d1c1699accdc79c49531cedbVirustotal results 29.03% Heodo
2020-02-06MES 2020_02_06 036.docdoc e62205f9ad8ce110e6f628a4622e7f12d9db3b4c2cc100e1d464b06f2a2b0afbn/a Heodo
2020-02-06mes-20200206-624240.rtfdoc 43f10fe26a0ef0775cf82202ccdb01f65cd38e6aab4086fa49b4b2391da9f0a8Virustotal results 29.51% Heodo
2020-02-06list-5507156.rtfdoc 00810a12662ed1714ce797c700855a606ab35c246a1c1a2ada47b503d612a82dn/a 
2020-02-06ARC-2020_02_06-HB2933.rtfdoc e2242f427a47cdd239a61505c64bb7956f2c451a95ae9dfcf44f845fafeab46aVirustotal results 25.81% Heodo
2020-02-06arc 20200206.docdoc 3c9d9f7c089af3d74e37371950a676a966f7160c531930a218fcefda342beee9Virustotal results 26.23% 
2020-02-06Mes-2020_02_06-910.rtfdoc ad59ca837e5e359b406767791e57fab4f0d74cf3247166885df2167e442cba64Virustotal results 23.33% Heodo
2020-02-06file 20200206 2777727.docdoc b99125a74c2d36d2875478ee03096a69ad74f272c1ced98d2e22ea0f2a3d3191Virustotal results 22.95% 
2020-02-06arc 2020_02_06 644101.rtfdoc 6975ed31fcf619923b119bc26d0f005ef935aaa2e20b25553b47389844f6005dVirustotal results 23.73% Heodo
2020-02-06arc_20200206_US6386.rtfdoc 413a1918fa059d5be9e47bd9fb404c1f58c2c5262e3c2f4371a88f4cab9a9c93n/a Heodo
2020-02-06list_2020_02_06_SEQ13421.docmdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06List 2020_02_06 Q404.rtfdoc d0ba1020328bfa59129c6d94b6bfd8979bd652574b24407bcfdadc75fcf28fb4n/a 
2020-02-06MES-2020_02_06-JFU516.rtfdoc 7713e180e8a62f6041738a796b29f6efeab8431f8b6425016a4242f64df7061aVirustotal results 20.00% Heodo
2020-02-06doc_20200206_QN09495.docmdoc 17593bcabe9abc1036651dddd696d02cb77c94ed237afdea9922c48880b9ef4bn/a 
2020-02-06Mes ESV88443.docdoc c7662c41a76803dcb646c8d920e316033baf7eaeda42b42305d4bab1a3a49fbeVirustotal results 33.33% Heodo
2020-02-06Dat 2020_02_06 H3048.docdoc 43e38902740c39567550fd0e4c87c00947c5fe577765eb00051f0212c05d7cabVirustotal results 33.33% 
2020-02-06inf-VK376776.docmdoc 702b22d598064f664dd6fbf97fb50364269f0215cbeabf867165861dd0b7d82eVirustotal results 32.79% 
2020-02-06LIST_J8739.docdoc 9005832cf404bc1202dcad8865b5250a9826f2fa18a6e23ee0a7e705c1d63ab0Virustotal results 33.33% 
2020-02-06Doc 2020_02_06 3879721.docmdoc 24bc1b322505611fc96f657f00be75ad4a096d02fc3e78d4b45369b13358575fVirustotal results 33.33% 
2020-02-06DAT_N38819.docmdoc 77016ff9da8e219908f060ccb135597a6d365ce13a53cb4f40e13ec91bbc37b3Virustotal results 32.20% 
2020-02-05mes_690039.docmdoc 6ce8037ede79b5758219b73a2ec4cc67731872b60410bf0aff7b7cbd8e9a5964n/a 
2020-02-05list_20200206_X9714.docmdoc 335e92129e141d12928fdc17fbb6c1dfe8b6fa59b2ff2a4ad0c60f4f0637ee83Virustotal results 27.42% Heodo
2020-02-05arc-O455387.docmdoc c1d36e9aab2030f23a10178cc432f92255b74c7e2382840bbae1ad7c099e97a9Virustotal results 26.67% Heodo
2020-02-05Rep_355.docdoc 1566745273aeac5249400c456f82b70e870825a50ee2457479f734c7686dfb54Virustotal results 26.23% 
2020-02-05arc-2020_02_05-0241822.docdoc 79b3a51440b181671112045cb234739a360169bc4c6ccdb30a3907a50a055963Virustotal results 26.67% 
2020-02-05doc-20200205-GY358133.rtfdoc c0b9c90ce017a4e5196e744c7948464ff57431da4a1d820793c5aea57cc0a095n/a Heodo
2020-02-05inf-20200205.rtfdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05INF-A07049.docdoc 15323460179dd0de74e3613b5cb65b86ab486b8c92c062c9c0a5756ce96b4e2fn/a Heodo
2020-02-05ARC_20200205_69546.rtfdoc 593ef299e4bcf8e836dd1522653ec33230104646f6e8c376e9c4a9957ca5ca3bVirustotal results 24.59% 
2020-02-05Inf 2020_02_05 38113.docdoc ab556aef3f7baf74127e682541cd5bb674af38a62c4c1f89ff43f09388894af2Virustotal results 25.00% Heodo
2020-02-05arc ZU959380.docmdoc 03b3fb6363d17eaa9f38facff48a244fc5b897afd2e74f173a3662616f4583cbn/a Heodo
2020-02-05LIST 2020_02_05 W668854.docdoc 4d87879312946df36ab67edcf0f7a77c8cb8051a479d2639049760e4df5a22bcVirustotal results 25.00%