URLhaus Database

You are currently viewing the URLhaus database entry for http://frankbruk.pl/LLC/JYA21937TVB/Aug-07-2018-7673380834/ZZOE-VYHQF which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:39188
URL: http://frankbruk.pl/LLC/JYA21937TVB/Aug-07-2018-7673380834/ZZOE-VYHQF
URL Status:Offline
Host: frankbruk.pl
Date added:2018-08-07 00:57:14 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-08-07 01:05:47 UTC to abuse{at}domeny[dot]pl)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-07PAYMENT 39V Aug-07-2018.docdoc e7d99cf53f2328ba4585028e7bb9d4f347419d4f9c8730371eec4842009ce8a9Virustotal results 32.79% Heodo
2018-08-07ACH 677XQISP Aug-07-2018.docdoc 09b0d092666fb12a7b8ee82be7fd876250174bb317592438a7ad1bbe2059e529n/a Heodo
2018-08-07PAYMENT 8691OMFVBYDF.docdoc a9eaf48e4c339f53264a5d10b28641baf808ff290727e9066266ccaba2df03f9n/a Heodo
2018-08-07PAY 77347AWY Aug-07-2018.docdoc 61a3876a4861e42a439af82e513e252754e7042dd464b507f42f4d339b8c1e8dVirustotal results 32.14% Heodo