URLhaus Database

You are currently viewing the URLhaus database entry for http://klem.com.pl/tester/paclm/ul24w9051518724376lybxtewqwzpkp/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436734
URL: http://klem.com.pl/tester/paclm/ul24w9051518724376lybxtewqwzpkp/
URL Status:Offline
Host: klem.com.pl
Date added:2020-08-19 17:25:04 UTC
Last online:2020-08-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 17:26:04 UTC to abuse{at}ehost[dot]pl)
Takedown time:1 hour, 4 minutes Good (down since 2020-08-19 18:30:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19FILE_FLB_080120_XBM_081920.docdoc e8ce0eb277704e4e5a4039958561ed3ac356ca43bab67fd398cc9edb82072faaVirustotal results 23.73%Heodo
2020-08-19INV_95140143.docdoc 543c33664c0023f112db5e33d85ecef70d375848205f72b2305c648abd21137aVirustotal results 20.34%Heodo
2020-08-19INV_10702127.docdoc 6e24d40dd2ab39e102c07369124f050fc0b0f2c103fc5acd2fcf280d8048b1bbVirustotal results 18.64%Heodo
2020-08-19FILE_25969668485809.docdoc 627b49f0092b200a0b8d4fcaa8e324a834cb12ae1b712050e2551a8d1976b407Virustotal results 16.95%Heodo