URLhaus Database

You are currently viewing the URLhaus database entry for http://arkamedia.pl/forfundoit/protected-array/guarded-profile/meqTktmP-x250c976ri/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438333
URL: http://arkamedia.pl/forfundoit/protected-array/guarded-profile/meqTktmP-x250c976ri/
URL Status:Offline
Host: arkamedia.pl
Date added:2020-08-21 15:50:04 UTC
Last online:2020-08-22 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 15:52:02 UTC to abuse{at}nask[dot]pl)
Takedown time:15 hours, 49 minutes Good (down since 2020-08-22 07:41:18 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22Doc.docdoc ccfdc014f5b8bf807ed25ff4a346c9b8978a0aced286592abf737c87cb221190Virustotal results 34.48%Heodo
2020-08-22INF_ZL38183.docdoc 0d62984f302057e3206f8ffb7af2b01402726b9a6d7146509f4420e5aecd80e5Virustotal results 34.48%Heodo
2020-08-22Dat_2020_08_22.docdoc 888576b006def3935c63b3044add14aff8f8a2f56a1a52592f895f1182d25ce6Virustotal results 38.98%Heodo
2020-08-22Doc 2020_08_22.docdoc 41e117890931d05a1eaa233b22b71bd5de72311491f54ccd76c7141d37a2c2a8Virustotal results 34.48%Heodo
2020-08-22LIST 2020_08_22.docdoc eb03beecb5dbcd12f2191ec6980a4b9abb56b43907f1bff900378a80daa3699aVirustotal results 35.09%Heodo
2020-08-22Doc 20200822 L3334.docdoc 7e23b5d1c6802917ef79115b4b1a242be7cd7465aa52247ae9d01092bcb49da1Virustotal results 34.48%Heodo
2020-08-22List-1515020.docdoc 46821d694a7c94efbd9aa8cf863377946de88c036c813decd85ed3cd8bfb6cdeVirustotal results 34.48%Heodo
2020-08-22Rep YQD0541.docdoc 4cd4ea7314c2268401c1395af0e562dcb530b081eb42c55152e03990a62bc4eaVirustotal results 34.48%Heodo
2020-08-22Inf-Z680.docdoc 037b8124330acc05c14aeec4da5dd741dfc43260dbd62df806d84fb370ed3416Virustotal results 38.98%Heodo
2020-08-22ARC-2020_08_22.docdoc 6c07e097125602926df0ea025482c72e280b3f4b72f2fe5f0603c0b23811ef4aVirustotal results 35.09%Heodo
2020-08-22File-2020_08_22.docdoc 9171991027c772e7f4a0461492ca9a074c828f0647d3fb993b0b370dd233fd2fVirustotal results 40.00%Heodo
2020-08-22INF-N54709.docdoc 291edabf7bcfe01684c74241ceb62bc93ca60fb17a4beebc62d4acf99c9f15d3Virustotal results 36.21%Heodo
2020-08-22Dat 2020_08_22 JXT79877.docdoc 9c6e241a9a90edac415dda654252a69fb56e32a5f9894dc1e0e44f8d02e56d2aVirustotal results 37.93%Heodo
2020-08-22Mes 2020_08_22 UUC14535.docdoc 38ad7eca5e40a7294cfd489d269d4dae16920886c3e5b69674dfffb9e75daeb9Virustotal results 32.76%Heodo
2020-08-22inf-20200822-TA32460.docdoc 554418877730d4dee3eb89b119139b9525488871911b50e38b4264d4e02aedf0Virustotal results 33.90%Heodo
2020-08-22Arc 2020_08_22 KO3171.docdoc 3c425e91c6383bae63a5768f423894b4db16efeaa0224ff93d8e9878e0422ff9Virustotal results 33.90%Heodo
2020-08-22ARC 20200822 LJQ9921.docdoc f3910c447952615a78e47e19bb4d3f313f015a74e603c83b15fbe812d5437d4cVirustotal results 34.48%Heodo
2020-08-21doc-20200822-YP419831.docdoc 44be463c465e4e229df4dcea734d505a424cb65601ccdcd1348117882ad9038cn/aHeodo
2020-08-21mes_K39300.docdoc 5027992f3f1c092f72a1f03d8617eb280d1a262c52e16a3b3c06c09e2d2479a3Virustotal results 33.93%Heodo
2020-08-21inf 20200822 819.docdoc 06da47e8874c949c899c40bdac1c203ae60c6d0b6dccef8a9fd09a98d5b274e9n/aHeodo
2020-08-21rep-65842.docdoc e41c9acb24c7dbffbe881b62867bf6c7e1ee5c151509f7fa14b4004d0db184aan/aHeodo
2020-08-21inf 2020_08_22 FQ969649.docdoc 410274b2ca31ea3142f4fb91817422ccc1ca62617732458298145fae6d740559Virustotal results 35.09%Heodo
2020-08-21dat_G99648.docdoc a8c50cfa1146130af0f5fb5225f6ee606553cd2e869a7b0d4f3523bf464fd3acVirustotal results 34.48%Heodo
2020-08-21File-20200822-3422.docdoc 605a94a5d882c71dfe00f46a2f2206f95436ec9be3be78d13a2828dcd55a3935Virustotal results 35.59%Heodo
2020-08-21List-2020_08_22-Q87779.docdoc 9e69975dc06b14ef59f0b2b3c90ea60751f1b5a352c10e97eaf03c7cfbe7265an/aHeodo
2020-08-21Mes-2020_08_22-73726.docdoc 2f21aa81b394e0b43e1f6a75e671ac3df68135f44ba1ed1c982a65cb2d8bee9fVirustotal results 36.21%Heodo
2020-08-21file_E687592.docdoc 42cd1526e8dc5c2eb9e1cd5aa13c9dd5068358c7f29defbac1a97b67f59b36bbVirustotal results 35.71%Heodo
2020-08-21mes 2020_08_21 IP577715.docdoc 56bef1bf282fa02a255e909b0e6781db27f32150b1e87d46f52f71c22602b3b5n/aHeodo
2020-08-21File-TG9581.docdoc afae193e15a1015938b4d38c1c3a60e066a7de17e27e599fb8afe90d97dcf749Virustotal results 27.59%Heodo
2020-08-21List 2020_08_21 3607.docdoc 98b205aa6d8a1013d8472dadcbb5f479d702e147bb4a044ccd20fa494cee86ccVirustotal results 27.12%Heodo
2020-08-21Dat_293577.docdoc f2c0a9d43cafec33593c0c1b398666406637529e89fd4a4190490dba25ff71c1Virustotal results 27.12%Heodo
2020-08-21ARC-20200821.docdoc 0e02d0b64b76dabe7b25a9219045b162dab61e7b69e396213362d78484f3f9d3n/aHeodo
2020-08-21list.docdoc bb5ea6401f31e4c9a16297546ea7dc58a1b86dec75837de0e5ce9e9709a53919n/aHeodo
2020-08-21arc-20200821-3801.docdoc 3b17e737a54751a71b9d73e78868fe24f0033eac1b31dd744fcbc169eab139beVirustotal results 27.59%Heodo
2020-08-21File_VX0783.docdoc 6d50456c3290a78c53c586ad8eee0f6156fe29bcbf3e0af00e3646bb85dec3d2Virustotal results 26.32%Heodo