URLhaus Database

You are currently viewing the URLhaus database entry for http://psotm.pl/wp-includes/closed_zone/interior_area/963338392_kCrsPUBs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414157
URL: http://psotm.pl/wp-includes/closed_zone/interior_area/963338392_kCrsPUBs/
URL Status:Offline
Host: psotm.pl
Date added:2020-07-17 17:41:27 UTC
Last online:2020-07-20 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-17 17:42:11 UTC to abuse{at}home[dot]pl)
Takedown time:2 days, 14 hours, 56 minutes Poor (down since 2020-07-20 08:39:09 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-18DAT-20200718-69615.docdoc 8a20c5d41b0ea80165d9d900936696ea0d6e1aff5e22ec84913d2a8663f4c063Virustotal results 43.55%Heodo
2020-07-18arc_2020_07_18_9566754.docmdoc 40ff69629d016b471e8d629757c3cd4ab76c1958b851d9484fe5b9f12bd05b20Virustotal results 44.26% Heodo
2020-07-18File_GM4968.docdoc 7b109398cbf73b6ad4911a37a8599dce651c0580ddbf0fb4bd7d6ca4d429b245n/a Heodo
2020-07-18MES_2020_07_18.docmdoc fdb43ef55c448c1ddfb8f3f4285691274726e0ebea7bb77329da28e47d9e9eb1n/a Heodo
2020-07-18INF-2020_07_18-7484.rtfdoc d83dda004c1f5cc3b6af587c3ceace1bb5f2e76e8cdb013a30c0078e100b2e07Virustotal results 43.55% Heodo
2020-07-18File_20200718_31477.rtfdoc 49b1db3ab05041bbb1b9a2cd6c9b4e33f1c3dc4771d4e5b35ca7e19135c5006fVirustotal results 45.00% Heodo
2020-07-18mes_XI75102.docmdoc 98ff83d44d2a1d8e59aa9c90d56ac4c6fb1bc08ccf6320d7e0956075e7f8d059n/a Heodo
2020-07-18List_20200718_R52099.docmdoc 0282a9682b4c3f016f4cd84847a3973d205972a75993feb753b575895a162a46Virustotal results 43.55% Heodo
2020-07-18inf-Y1209.rtfdoc f6059b68359fc971b85eaf15867042805b0246083140729de8830fc239c0a4edn/a Heodo
2020-07-18Mes-2020_07_18-838.rtfdoc 0f62fa0eda89b4c7e9907ff92c9cbfcc2639c16eb162c40311c4bf40396c47e4Virustotal results 42.62% 
2020-07-18Dat 20200718.rtfdoc e4f83f5b3d38b5bbe3b2372980bdb5303c74b1938b66e40288e0ad6c2c79d9b7Virustotal results 41.94% 
2020-07-18Inf-874086.docdoc 25bda46f24b9ad3a6070206abdb225178d5c0372e2ac3cc27657dff36eedd7d0n/a Heodo
2020-07-18MES-562.docdoc 2f2bf71ff720e834455f232dad3c4c5a0b4e7a0160fe14230fd7d73e3b394883Virustotal results 27.42% Heodo
2020-07-18FILE 2020_07_18 QV902300.docdoc 1fe6bff652bd2ae7803b24a5de11039367bea29f7f8cfd00bf212cbc841cd784n/a Heodo
2020-07-18doc-20200718-773.docdoc 5239c9a098468e61c38a839792ada20222fe9fc976df4b9605c5232033be081dVirustotal results 41.94% Heodo
2020-07-18doc O719.docdoc db7f888bc27f3625e1d2aa8dcd1f473d1b6c3f18425041aeb9d6317a5cf977c4n/a 
2020-07-18rep_2020_07_18_245454.docmdoc 10c77e4b6a5839e58d182a67152db5b25a31e943cb0fa06ce266b27e8c4d06e3n/a Heodo
2020-07-18File_2020_07_18_83022.rtfdoc 44737c7b4475fb2a259af5c0b23c7f14945dda0d119491a61f2004f59cce8105n/a Heodo
2020-07-18LIST_2020_07_18_R1997.rtfdoc b5e3dc0a53062058a2b13ef1d82f7c2b7ff5fe9452fe4cfd534eb6acc3844a26Virustotal results 40.32% 
2020-07-18Rep_2020_07_18.docmdoc c4fef70e62aafcefd6600e91edd401ccd941dae7472d89fd2cb164219eeb34f3n/a Heodo
2020-07-18File-2020_07_18-602589.rtfdoc f821386a84c5ca5ce96218b63990b6ef7ba0016e43aae95ebd78c9bda997b6f0Virustotal results 39.34% Heodo
2020-07-18Arc-2020_07_18-OIP518523.docdoc 91c02fe37317be17fd879fd63a10cd9da611ae6098948f77ccdcdc94f83b5ccaVirustotal results 38.71% 
2020-07-17MES-20200718-WFL68859.docdoc d0a6228f0457c0dab131d8c3cbcc69b48575c993d2c1e3745087337415144d9cVirustotal results 37.29% Heodo
2020-07-17inf_2020_07_18_H286487.rtfdoc 2fb80003eee9d2ded738ae5260c96a5b0b71ab7620f7b2e2d74344de868027d4Virustotal results 38.33% 
2020-07-17ARC-2020_07_18-214752.docdoc 2fdb794642d195e0cf37d232ed02d37ed74b1b5ffa324fc9251b5cca3de8ed2fVirustotal results 37.10% 
2020-07-17REP-0746.rtfdoc d12ad51a2c2b91323324d970ffa092041ec804bd5a52d66c75ba5af96b22afacn/a 
2020-07-17FILE PFQ009.rtfdoc 3f054364f4de6d79966887c8d95c9c4bbe25fbb622c1163ff73ac7d345f73731Virustotal results 33.87% 
2020-07-17mes-0601509.docmdoc bca758b7d4b4ef0f896d55923f06614531cb7f2372d99536a5edd0aefd217c1aVirustotal results 32.26% Heodo
2020-07-17List_2020_07_18_QDS8089.docdoc 4f650fae13b2f497c92dd327ff98b5126875ea6741d5e9db7f7f74bb2e471f83n/a 
2020-07-17Arc.docmdoc 4efb5eea71e20c735df86a96e1cc7d69fc118ba4e71b69c98811dbe49742b755Virustotal results 29.03% 
2020-07-17File_109713.docmdoc 15823fbaaec62d56050309844e01b51c68e70ea470896e571eb673938c147a81n/a Heodo
2020-07-17Mes 2020_07_18 P71036.docdoc 3f69f8a5d85615b90542b5460bd5298315e40c5e29978ab420bb67620f2422c1Virustotal results 27.42% Heodo
2020-07-17arc-IXI991508.docmdoc 49088549ea21b7efe6c56213380cbb654728fc95e51aef16b0b44ae181907e03Virustotal results 27.42% Heodo
2020-07-17List-2020_07_18-725708.docdoc 0fcd9e5cdbfd7704545e03dd7c7a3deef28f11ae26911b0f86b20687fd46d2ddVirustotal results 27.42% Heodo
2020-07-17File.docdoc 7314748358ee31f8fdfdc7972cb282d8675c0e843b07383c52e124ae3b937a7fVirustotal results 27.42% 
2020-07-17LIST-20200718-ECW320.docdoc 328a1ddb0998b010e99d5314354fa47de97745a0e09b6682e043ffba500f19cfn/a Heodo
2020-07-17Doc_2020_07_17_979454.docdoc a64f2f02a7bb03fb55ca2a301f702c810582b38347ba2d3aff39c93e40df5d3fVirustotal results 27.42% Heodo
2020-07-17ARC_MX4318.docdoc deb9182b6e138520576458d85048d5069a4e20f11acf4938b081ba4e8765365cVirustotal results 27.42% 
2020-07-17List 2020_07_17 FF12888.docdoc 770fd6643c934cc3aa0fddf589d643b7b59e18a005ff89fc9113bd8181c21a2fVirustotal results 27.42% Heodo
2020-07-17Rep-2020_07_17-NOH224.docmdoc fc5976ea9262dda7f7fe8f62ede24a9fdfbed454fe8b0679e2e15a64243afd17Virustotal results 27.87% Heodo
2020-07-17list 20200717 52110.docdoc 5e20f76a136e863a01416716795a90ee97d009b2ce86b33ad78019ee5ea647b5Virustotal results 27.42% Heodo
2020-07-17mes 0235.docmdoc 493accf3563320001bb8c5d727fb01bd790bdd20df7f179b12e771330274ddfcVirustotal results 27.87% Heodo
2020-07-17DAT-20200717-O865755.docdoc e90c88a5cbec9eb57a69658a28abc2a72c188a4d8b491e8df5b855fbb1ba950aVirustotal results 26.67% 
2020-07-17DAT 20200717 187.docmdoc ef1f1a7527cab97e8d41b6308210121f218d42c9c052f000d0eee0e79924ab7fn/a Heodo
2020-07-17Rep_20200717_C1757.docdoc 7472c7e89fb0f2d1c2c6b136bc5f151624ac96b92297bc63baad78b84d7d4e07n/a Heodo
2020-07-17list_2020_07_17.docdoc f3e53a7b56004f0f594f871c8a7018cc9fda70e48cba425a53373eb52c5bec46n/a Heodo
2020-07-17File-20200717-FPH5558.docmdoc b559130a7e571ca280d62de701538c0b16f51cb8b29c0cf49fb6ab023c34e98cVirustotal results 24.59% 
2020-07-17MES 20200717 727652.rtfdoc 1a9f759bb9bd81dec9e2703f6969d9e4f7698200c8a5589e6c22bda4cbafa086Virustotal results 22.41% Heodo
2020-07-17Doc 20200717.docdoc 91912df5301c614ae4b9eeac155f25f93b243a8176975524fd84f1782fb9040cVirustotal results 25.00% Heodo
2020-07-17Doc_20200717_CVE754.rtfdoc d04e0e7daf8c94bfba623e60a2eff22f97e5b71026cac2acff4c2e77f835efc6Virustotal results 24.19% 
2020-07-17Mes.docdoc 61f184050c876f25f8c486f3efbdb25230876854fa9dd371610d212f7c738850Virustotal results 24.59% Heodo
2020-07-17rep W56789.docdoc 517476e80a66768db74eae2de0226011892f476ba4fd6fc971a1066a66d6149an/a 
2020-07-17MES_2020_07_17_8655608.docdoc 811764707e5bc193447a4f036205ff93e720d5944ecadf19e6ffbcec65d94b2an/a Heodo