URLhaus Database

You are currently viewing the URLhaus database entry for http://www.elektromechanikachlodnicza.pl/wp-content/https://Pages/BQjRQoA5wixy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:505281
URL: http://www.elektromechanikachlodnicza.pl/wp-content/https://Pages/BQjRQoA5wixy/
URL Status:Offline
Host: www.elektromechanikachlodnicza.pl
Date added:2020-09-15 00:18:05 UTC
Last online:2020-09-15 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-15 00:20:23 UTC to abuse{at}ehost[dot]pl)
Takedown time:4 hours, 56 minutes Good (down since 2020-09-15 05:16:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15Dat-2020_09_15-899.docdoc bab404a66237f3796ffc9047bdac95d69e90bc166e8c2838affdd13e0efae9e7Virustotal results 47.46%Heodo
2020-09-15List 2020_09_15 847141.docdoc 722daad4788110079385f9dcb18317099000ff8ce70664dab44c0895dd127083Virustotal results 45.76%Heodo
2020-09-15Y62989-T8610.docdoc 35f29c3c4df1d0c6bd963255bd2be77283733d9d0e774926f51e9f2353a9cf5cVirustotal results 45.76%Heodo
2020-09-15LIST 20200915 D599.docdoc f15af8515126fa73c26c783a07b7b8102603af53319a2148b073ceefed8de267Virustotal results 46.55%Heodo
2020-09-1570006336 PL759234.docdoc fc660ee423a47e5bfab7297baf2765d0d511c0880936244b14b5ef3cb786f10fn/aHeodo
2020-09-15Arc-20200915-066940.docdoc e9fcb6031b256633694a632ff788b143b51d422749b4433952a0cf79d1fc3451Virustotal results 44.07%Heodo
2020-09-15570ZGK 20200915 F216846.docdoc 76d26557ad9344a10d718f60b088004f1335e8217a201641d894a46373bf73fdn/aHeodo
2020-09-15List_65003.docdoc 1edb5c54fee229f7a710437d7356d55d4343437e46e849802c75ae6101162c47Virustotal results 42.37%Heodo
2020-09-15Doc_20200915_MO1593.docdoc a5fe34f4f59c550793d6e628deeb7b0e77273be63dd3d68f950edcbbb2cc0d5cVirustotal results 43.33%Heodo
2020-09-15arc-20200915-HLV841.docdoc 89966dd362b436e2a9f2c8c60424c4d6c29197c7001146a71acdf9e29600a348Virustotal results 38.98%Heodo
2020-09-1589096L-60500.docdoc 2bced1a8302d817af06cc07010a27345146769b3d9ad0e86d246ca93e4dc8e69n/aHeodo
2020-09-15REP_20200915_WU5538.docdoc 9ce006bb0e752354b2374803060115dedb3f8239567d4bfa6a2a027a74bd9b9bVirustotal results 38.98%Heodo
2020-09-15rep-O680.docdoc cf8d757135f246e73646a6a72adfde896d3ed51271e7056596076d834e960968n/aHeodo
2020-09-15Arc-2020_09_15-172067.docdoc 0b92085e3fef4b9cb196fb9a8e9bf64d4eb8664184ea2bdf46132abfa7f72a3fVirustotal results 38.98%Heodo
2020-09-15ARC-20200915.docdoc 8a39aeeae70b5b869cf70b80cf2c4a4149a216d99839bc70e705f62472eea851n/aHeodo
2020-09-15dat S6055.docdoc 0fd1ea9df6c248cc1ef6ac65fc534db5ffb946cd912f8199503dd93fecbda5c0n/aHeodo
2020-09-15780_20200915_QRH494198.docdoc 95a565fbe3dd58781eef947d31d6de93257032734052f7402be980023742980bVirustotal results 39.66%Heodo