URLhaus Database

You are currently viewing the URLhaus database entry for http://elementum.edu.pl/wp-admin/invoice/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:590493
URL: http://elementum.edu.pl/wp-admin/invoice/
URL Status:Offline
Host: elementum.edu.pl
Date added:2020-09-21 21:58:42 UTC
Last online:2020-09-22 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 22:00:14 UTC to abuse{at}hetzner[dot]com)
Takedown time:8 hours, 30 minutes Good (down since 2020-09-22 06:30:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-2221275878840243109842.docdoc 8d49090e5ad1ca487645e8dad8b6e90d267b4a7f5d4cdf4d9c4441d969f088caVirustotal results 45.76%Heodo
2020-09-22BAL_PO_09222020EX.docdoc 313348d434b780af86ba7a2d374246c8188545ba67cafdb86907a445c2052df6n/aHeodo
2020-09-2239882288692.docdoc ec2ce44f2fbd4e3dae1a7268da4de197bd006a620ec08af7122f25557cd49196Virustotal results 44.26%Heodo
2020-09-22INV_59857010.docdoc 61b104c81d6e07bc38102631a844c6247bfb16ff720fc134b3a95d601df23fabn/aHeodo
2020-09-22DOC_T1LETC94XBN.docdoc 3329e54a271ff895664104546d9af52c00ce1284be48322d3ebf1cc34db74169n/aHeodo
2020-09-22INV_PO_09222020EX.docdoc fb096cb018d3c66f22c322028f9e8f1f049e9a9eb3531f9e893c3d2522f35951n/aHeodo
2020-09-22INV_NK7737680948YK.docdoc 863a67fda8f1051e42a5caca1a89f4bd895d01947127dceebf7acb4eb4b881bfVirustotal results 33.33%Heodo
2020-09-22BAL_39XK5H1T9I.docdoc 76d7ce6a12f4c9d03615c5255b79835bb2cff27e86deb3cb790932cdca164ac7n/aHeodo
2020-09-22INV_GK7114172044LC.docdoc 9e25ce36733cb087f13b4a1c744a28856f2e1e878782893ac18e682ad0f2e842Virustotal results 32.79%Heodo
2020-09-22PO_09222020EX.docdoc 7c15b14e3a1a2b381be48aa601e40dbbbc0b493b584c13314459e7e5ca57a953Virustotal results 31.67%Heodo
2020-09-22BAL_63140803126145378835583.docdoc 7aa7d38a55d5f7d01ee40a977a2df63d0cd4c938482a2fba3c73e1844405a0fcVirustotal results 31.67%Heodo
2020-09-22BAL_52565250.docdoc 23184d215b3db4bb670b2c1e70e1b7f81760cdec7e35b8a0a90cebc4a6797eccVirustotal results 31.67%Heodo
2020-09-22W_VS9736753930QN.docdoc ed6598e7e6d37524439397ed78a735fe41117f47c0964cba780b5800d4eb5146Virustotal results 33.90%Heodo
2020-09-22K_AJ2765934768JV.docdoc 0489a6b94e2c6206bd2730cc32c8f873d1ac1af2ad02bdb69a77a8078460741cVirustotal results 32.20%Heodo
2020-09-22S_GNO_090120_KOJ_092220.docdoc ce04dad796a1819d846a6a981c97426c43b0943deed734991bc6780eb54ba074Virustotal results 30.00%Heodo
2020-09-21DOC_WMN_090120_XKG_092220.docdoc 4b79ba0096d15d6a7c759fdf3e094194707f88072e8aeb0d53979a88db734ae2Virustotal results 30.00%Heodo
2020-09-21REP_WL3542365250YT.docdoc 61ba6999ffd23a0f22f6827b577e773e9d6a79ef366b3260a6b55a792c98d519Virustotal results 32.20%Heodo
2020-09-2131020354803.docdoc eed638e68fb63c08e3dbe230dc2a66544170ba12c92aacb9571a99fe355f0878Virustotal results 31.03% Heodo
2020-09-21REP_OL3243043422QV.docdoc 75aacb9b9e0f3b4113358caf49078bb79286fb9637c523807a8f533d0df7c834Virustotal results 30.00%Heodo
2020-09-21INV_XDX717P.docdoc 04b6915557c386d4219e56049dca6eeef6f30b41f45fb525d36977e248fbf4ecVirustotal results 31.15%Heodo
2020-09-21REP_69646132.docdoc 2d560e72a8bbfa60a7f05d58048f8174de084d6ff4a53531d9582e251fc067c5Virustotal results 30.00%Heodo