URLhaus Database

You are currently viewing the URLhaus database entry for http://www.bagiennanarew.pl/libraries/UFZYuWwNM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:32708
URL: http://www.bagiennanarew.pl/libraries/UFZYuWwNM/
URL Status:Offline
Host: www.bagiennanarew.pl
Date added:2018-07-16 10:20:15 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-07-16 10:23:03 UTC to abuse{at}plus[dot]pl)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-1711557417.exeexe 51e818a1fd082ab82631a3a512bc9bd9228260b93600d6cd02672ca77dce4a59Virustotal results 20.90% Heodo
2018-07-1737160975421.exeexe 12ea02b03dce423544a4feb4b48d01ceb7480aa406909b47f713e0819dd5e00fVirustotal results 23.88% Heodo
2018-07-1769780763.exeexe 97ed515504588125f99324a9b817f979b6f86351f745a3734d3f3fd3f212bdc5n/a Heodo
2018-07-17239113293731.exeexe 6a1cd2af82faf40a8908c539f6fd086502c8a401e078cd041a53c6080d82de0dVirustotal results 19.40% Heodo
2018-07-1754476929.exeexe 68fbfdb0ab87a6136d8fc8e6d50330b683aa18bebf49f24fa11537d01653b332Virustotal results 17.91% Heodo
2018-07-1776674839593.exeexe 800df8714d8f25d3a7e755e5b1eb377ca3e32accecbca21de6aaa7f9a5e587dan/a 
2018-07-172942561085.exeexe cbc45b96fda8dd49f9d20f596e92def2d05e1daac9800e745222cca1ca50912dVirustotal results 19.40% 
2018-07-17068645869.exeexe 47b82ee9ccae6942591408a20b4bc6a3d1b05efdbf258a514cb8841f82a2c1a5Virustotal results 23.88% Heodo
2018-07-17820805274.exeexe b2758093c31e302cb4ee036130e27b5cc227e3014c7e0b3a4c1d4dae772077b2Virustotal results 19.12% Heodo
2018-07-166597587350.exeexe 129f021c58ef582feb90a7aa009990e87e2f4eb50ade0668523f9559734f09f8Virustotal results 19.40% 
2018-07-1658725413.exeexe cef1c97ae53a29ea34bd9acd2c7a8056e581adcaf8c23eb73020d52cd9199da4Virustotal results 19.40% 
2018-07-16610786889.exeexe 10c16f5a34a464419346ef5d6cdffbe6507b9f7b11b1bd908486a109569c53bcn/a Heodo