URLhaus Database

You are currently viewing the URLhaus database entry for http://flexistyle.com.pl/js/protegido-seccion/831956149230-CBjEW4grRnZZM-831956149230-CBjEW4grRnZZM/18BgrBvclV-jgHMMwa9M321ta/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308956
URL: http://flexistyle.com.pl/js/protegido-seccion/831956149230-CBjEW4grRnZZM-831956149230-CBjEW4grRnZZM/18BgrBvclV-jgHMMwa9M321ta/
URL Status:Offline
Host: flexistyle.com.pl
Date added:2020-02-05 11:22:05 UTC
Last online:2020-02-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 11:24:04 UTC to abuse{at}home[dot]pl)
Takedown time:15 days, 7 hours, 47 minutes Bad (down since 2020-02-20 19:11:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07contrato_02_07_2020-D79202316304.docmdoc cefcb17ff5f62e0d7859f7657bfcb01c8b31f3dc62796a97af7cb92ae00c82d7Virustotal results 24.59% 
2020-02-07CONTRAT_1mo6071pop.docmdoc c59dc2c1dfeeb1396f7d5c6dd909f830da34247b35cb8610414414385eee6fb2Virustotal results 24.19% 
2020-02-07OFRT-77970-68565004.docmdoc e3adf368b634569aa1ca2545bb340ffb5df4c918cf629e3afec00b6f43d444fcVirustotal results 24.19% Heodo
2020-02-07Oferta_DM256294437.docdoc 4d46d038cd9f2a48555e70846240d75457b23f0c3a192d9a9bf8a498ea35e2ceVirustotal results 23.33% 
2020-02-07CONTRATO_02_07_2020 5299495.docmdoc 727a74581ea177c74d58882f69d1fe6b02c674fef0471ca4e98ea85f2b817a4bVirustotal results 45.76% 
2020-02-07contrato_DG7593927.rtfdoc 88d2e0f1e728a7142e0fa0f277f4020c91bb5e4222ccfd8162d9e0b6beb60e5aVirustotal results 43.55% 
2020-02-07CONTRATO-541m4152o573.docmdoc d1224e748233f603009dc6db10fa20f0ee0abef47b4cc1df204bcd5519c1a041Virustotal results 43.55% 
2020-02-07CONTRAT-N355143738-531309974.docmdoc d562f29bea1e4d4bc55ba156a65431f8a2cff0ee1dc9a10e774b53ac61d8b82cVirustotal results 42.62% 
2020-02-07CONTRATO 029465.rtfdoc 951c41a81d18a2577f97934a32f1a28463dc7cdf7b4118ed040c35ae62864843Virustotal results 35.48% 
2020-02-07CONTRAT_FS815051.docmdoc be0c63afc0d72cd11f7b036943c4c4db9acca7652db8ae5dfbcac19a3b074710Virustotal results 32.26% Heodo
2020-02-07OFERTA C06654.docdoc 0b77f417fffce47f34544803d4fd268dff1609253941fc9281331f4366e54de6Virustotal results 30.00% 
2020-02-06CONTRATO_067023997190_247535069.docdoc 4810daa4ccbb49abbb0e59e495561bb59b892d44fdb400afd61c2b9b78e047deVirustotal results 29.03% 
2020-02-06OFRT_W99951.docmdoc 76ed65f4166ab70a504fa0c58b5fa4d5afbbdf92c3b7770185b137ac87aa37edVirustotal results 29.03% 
2020-02-06CONTRAT 02072020.docmdoc 0f9546ef0fe98af36e43a06ae58080335e7051c19f85fa72157d75d7e85f12c1Virustotal results 26.23% Heodo
2020-02-06Contrato-02062020.docmdoc 8ac7ed36748d60e4e5b3dca6805c79094a27204108ab3ed019a23190df1a1c49Virustotal results 29.03% Heodo
2020-02-06OFRT AI74181201059.docmdoc 0395137796e0f9fe7c273562138c7e5f0c988214841e6ed4cda2e3978a98f1bbVirustotal results 29.03% Heodo
2020-02-06CONTRAT 02062020.rtfdoc cddfbd7b249d0e0ebb3f68697690544c6abb69af1cb46f3b74c24cae2d3e528bVirustotal results 29.03% Heodo
2020-02-06OFERTA_V6801421_9069579839.docdoc a1669f5f97291a5acd8d21be96ed7cfd97c28979e0e6bba5a111c21c657b6c71Virustotal results 29.51% 
2020-02-06Oferta-02_06_2020 458223284037.docmdoc 33b5e2a31a3000b7a3251be5436e451986568c1a93ace24fab40817786f5a2e5Virustotal results 27.12% 
2020-02-06CONTRAT KMD55458.docdoc 9d589a2e6c2556df3dabf97bfb5d53fbf92b2303d2b44b92b864eea6df244f80Virustotal results 26.23% 
2020-02-06CONTRATO-02_06_2020-C7H5605.docdoc 65f576b0c1da324a19bbebf66196d8600be044aed153c7d74c6df1ccee6296f3Virustotal results 22.95% 
2020-02-06CONTRATO_JK33664.rtfdoc b99125a74c2d36d2875478ee03096a69ad74f272c1ced98d2e22ea0f2a3d3191Virustotal results 22.95% 
2020-02-06CONTRATO-5274856539.rtfdoc 6b1d90ff1212f95e6fb72180e90a64d316ee24b22f2803c46dedaca64ca09914Virustotal results 22.95% 
2020-02-06CONTRATO_R3Q51794393-9563551968.docmdoc 5c65f21a3869e1e15433c2263d8dff3827f622520c972b12f4686250b8e68018Virustotal results 23.33% Heodo
2020-02-06Oferta_02_06_2020_D049623878563.docmdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06CONTRAT 294535119962.rtfdoc d0ba1020328bfa59129c6d94b6bfd8979bd652574b24407bcfdadc75fcf28fb4n/a 
2020-02-06CONTRATO_mnp176n48.docmdoc c163d2a385feadd582c11612d2692072b57c78c665520df24672437a2bd549e1Virustotal results 21.67% 
2020-02-06Contrato_XUS82901-99743446.rtfdoc 9bf2c6a167cdca17cacba485a4e8dbbc600518a91fb3286401f7b387123b2944Virustotal results 32.79% 
2020-02-06CONTRAT_02_06_2020-3F87496173.rtfdoc c7662c41a76803dcb646c8d920e316033baf7eaeda42b42305d4bab1a3a49fbeVirustotal results 33.33% Heodo
2020-02-06Oferta_o714007.docdoc 43e38902740c39567550fd0e4c87c00947c5fe577765eb00051f0212c05d7cabVirustotal results 33.33% 
2020-02-06CONTRAT-Z12331825751_8683765.docdoc 00788bb2b24d0e0cb6eb61a72e29440b474f722cd5c10a79b29d02bae8319929Virustotal results 32.79% 
2020-02-06CONTRATO_02062020.rtfdoc 9005832cf404bc1202dcad8865b5250a9826f2fa18a6e23ee0a7e705c1d63ab0Virustotal results 33.33% 
2020-02-06Contrato_m2055069p1113n.docdoc 74491fc6dd7ba85729f150a091baf5019a4a9cfcfa8e7bb6d450c9edf7762fb3Virustotal results 32.79% 
2020-02-06Oferta 8p6o4p.docdoc 77016ff9da8e219908f060ccb135597a6d365ce13a53cb4f40e13ec91bbc37b3n/a 
2020-02-05CONTRATO_54899223.docmdoc 061b77c1354bff1d5cafa4e10d903ee5feb16bb91c295298444e056ffefd1370Virustotal results 26.23% Heodo
2020-02-05CONTRATO 02062020.docdoc 85d825b74358c12b84824b2d46cf048e3dfe836a8c320d88d301331a46e62ec2Virustotal results 27.12% Heodo
2020-02-05CONTRATO UP3265_2460487.docdoc 23f4a774007e2fc64a2824e5973bb695a64667d8d832fbc29806976dad67d7f7Virustotal results 26.67% Heodo
2020-02-05Contrato-02_05_2020_H67310359322.docmdoc 47ca3de0e80a4e9571311ab0b2470ecc29d18c990b063b57aef1818e5a3c260aVirustotal results 26.23% 
2020-02-05CONTRAT-p82p291o6o8685p.docdoc fe70cef82c0a8acabe3289f5863a62b3bdf8bbd476ff9c0536600c40fcbbfb9aVirustotal results 26.23% Heodo
2020-02-05Contrato_7667.rtfdoc da0b1e331a89bd28e4338a886d224c01e9194a764a6ded30bac8b16670a589b3Virustotal results 26.67% Heodo
2020-02-05CONTRAT 6A5710_33825550.docmdoc 20b603562ad65e466c27733e3ba8368c3ed83caeec165555f4a935ed0cc6d4b1Virustotal results 26.67% Heodo
2020-02-05Contrato_17J40196821 1802.docmdoc f4dbeab20387f793a3dd0b39d717b27c6787e02951aa4ef7cfeb0d156b75697cVirustotal results 25.00% 
2020-02-05OFERTA-CV20530489343.rtfdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05contrato 8068nnn7o.docmdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05OFERTA_552766.docmdoc 6b95c7839354ae0b69e74737d37864c5c78048aab4fdbf7a4916221d675dc9d1n/a Heodo