URLhaus Database

You are currently viewing the URLhaus database entry for http://clevert.pl/assets/parts_service/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432657
URL: http://clevert.pl/assets/parts_service/
URL Status:Offline
Host: clevert.pl
Date added:2020-08-13 23:23:03 UTC
Last online:2020-08-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 23:24:03 UTC to abuse{at}nask[dot]pl)
Takedown time:7 hours, 43 minutes Good (down since 2020-08-14 07:07:38 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14XGV_6355053664067137318740928.docdoc 06df7bac6ad0bfe0e2874da0f352830adcdb6d166d3915df90c2eda581b1a7fdVirustotal results 35.59%Heodo
2020-08-14REP_PO_08142020EX.docdoc 6ab2c399c8174e97809e728dc331f229df5e7d30dba04a5b1658ff245c45a657Virustotal results 35.59%Heodo
2020-08-14REP_TRZ_080120_YWD_081420.docdoc 13425d91c0471208df6a06b23e5f176fea8637422e82c95f1ecd534aadda855bVirustotal results 36.07%Heodo
2020-08-14K_12059772.docdoc d14b37fdf7ad86b3794264b6df4bfd7efbfd5ae07b03e72a800be6d16ec8aa83Virustotal results 35.00%Heodo
2020-08-14BAL_60889640.docdoc d4fade764b1ae03f546843ff7b67176a1d7fca0c1cad66455d0770c364b5746eVirustotal results 35.00%Heodo
2020-08-13FILE_PO_08142020EX.docdoc ae61420aebc07da884917752dcdac62809ccd7a3eb2ed470a3b6c810e7635adfVirustotal results 36.67%Heodo
2020-08-13REP_93267413.docdoc fd5fb6d047e878aeb0cbaf77ebf7ab256a45e4567b7307dcba252777c3cda57cVirustotal results 38.98%Heodo