URLhaus Database

You are currently viewing the URLhaus database entry for http://euro-kwiat.pl/6UIZ/oamo/Commercial/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51927
URL: http://euro-kwiat.pl/6UIZ/oamo/Commercial/
URL Status:Offline
Host: euro-kwiat.pl
Date added:2018-09-05 05:55:04 UTC
Last online:2018-09-10 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-07 11:35:52 UTC to abuse{at}kylos[dot]pl)
Takedown time:3 days, 4 hours, 46 minutes Bad (down since 2018-09-10 16:22:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-05SEP #59639YSLUKZ.docdoc 6c6dfcab49a55f450552f210124f1f75cfe878f6f8ef2cdff9baacd80e177938Virustotal results 33.90% Heodo
2018-09-05SWIFT #71489JGDMI.docdoc d0f71c391c1b1fb724c288ae368de757e5c6f0301d4efeeb51397054480e9d99n/a Heodo
2018-09-05PAYMENT #77122YEE.docdoc db3cc7177e7a94494bfbe8169aca696977a8b6982ab0df6ba43f5de8ec7b0734n/a Heodo
2018-09-05SEP #5TUX.docdoc d722fc2d2b66226a8d9f5ed480ed967d3f5eb973efed235d1e51c636664aeebbVirustotal results 29.51% Heodo
2018-09-05BIZ #9323146VHHJ.docdoc 333b0d1588c9988b6025fc411e5a7540e49bfc3af2c4fc78d3dd4ff51127422bVirustotal results 45.00% Heodo