URLhaus Database

You are currently viewing the URLhaus database entry for http://grandautosalon.pl/3256IHNHWDMG/identity/Smallbusiness which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:52983
URL: http://grandautosalon.pl/3256IHNHWDMG/identity/Smallbusiness
URL Status:Offline
Host: grandautosalon.pl
Date added:2018-09-06 21:54:38 UTC
Last online:2018-09-17 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:46:22 UTC to abuse{at}nazwa[dot]pl)
Takedown time:10 days, 0 hours, 52 minutes Bad (down since 2018-09-17 12:39:19 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-08PAY #10201PZH.docdoc 8fc9db0bac4cac546a1c3167777fd32da5249a88371eafa0ff44e70d48816ed5Virustotal results 38.98% Heodo
2018-09-08SEP #5NZVDFPY.docdoc d32eb38e419b1f359cbeeae9e386e183f20e7c7c7287449c67678766eaf49b83n/a Heodo
2018-09-08PAYMENT #5127TPHWQMT.docdoc d78e5fa04e2535406194b8ba7aed8cd91d14beca542f135f3abf9eafd15b19d6Virustotal results 37.70% Heodo
2018-09-08SWIFT #0BWFK.docdoc 9ead54ce0cdc2392fa6ec4fae1817c12e333f642e983ac539ff81b4b18ab64ccn/a Heodo
2018-09-07PAY #73J.docdoc 3546e004f012400bfc7577068b70b222d2c0c5553b40b45a248d280b007d221dn/a Heodo
2018-09-07SEP #9398408TBR.docdoc 56fafa24de262894e9918f00cec70d4ef2923b9b27b75f1796692c1005748508Virustotal results 33.90% Heodo
2018-09-07PAYMENT #7880672NSHLMVD.docdoc d0081433c37bcb2c3db0a4348a475885bdf68394ae8aefd18c3dd0228541b236Virustotal results 36.07% Heodo
2018-09-07PAYMENT #129XZSM.docdoc e57c0f195888041d1a54af995fa2f9a3641f6fba93a28cf03b9121349ae4d542Virustotal results 32.79% Heodo
2018-09-07BIZ #08784XEW.docdoc 39befda3ab64a62640b436fd8b9d7bc8a79b9bfc14d2710ccdd942b604d126a0n/a Heodo
2018-09-07PAYMENT #76801DVU.docdoc f7af7dade88cf1c94b8503133104eefd75f174098c7a43d32e402fdb9db9583aVirustotal results 29.31% Heodo
2018-09-07PAY #3YHQKO.docdoc b23c539340b5c958283cc559b754690ce6e5e6763c2e5285406e139fc7f3f5adVirustotal results 42.37% Heodo
2018-09-07PAYROLL #480364VROC.docdoc fe4054bd0e45e8f427208ef0d5c678507a9d95f59c22d465c15043077fa375d8n/a Heodo
2018-09-07SWIFT #627374QSTH.docdoc 5c944ed42ce7ffe7db789c49a89cb730fb4245adcbe1336aba3a15f5cbbb7f27n/a Heodo
2018-09-06PAY #5642YA.docdoc a9f4ff3d447fb2652cf343aa3452cf8f6a2504d56888c2f213b327e6991036feVirustotal results 37.70% Heodo
2018-09-06SEP #079694RFYCQI.docdoc 81c6cd4235a090d2a00213836027a956214aa1b6b8bc5e0f2c37ce797d5df019Virustotal results 36.07% Heodo