URLhaus Database

You are currently viewing the URLhaus database entry for http://nodit.upol.cz/icon/public/0vjNkFyRrtWnq9DH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:703092
URL: http://nodit.upol.cz/icon/public/0vjNkFyRrtWnq9DH/
URL Status:Offline
Host: nodit.upol.cz
Date added:2020-10-16 17:47:09 UTC
Last online:2020-11-12 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-16 17:48:18 UTC to abuse{at}upol[dot]cz)
Takedown time:27 days, 2 hours, 3 minutes Bad (down since 2020-11-12 19:51:24 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17list_20201017_VXA013352.docdoc 294c6f87d8514072c30988bd55dd643c5c018b9f9ae05b9db1a97d034b31e092Virustotal results 55.00%Heodo
2020-10-17Mes_20201017_856.docdoc fd4a45974318a540bf249d7aa768f6d4ec1bb268bb05e5028935db34aff711f4n/aHeodo
2020-10-17ARC 2020_10_17 9884.docdoc ea4cb3d56a4e049d8d0e7d1e30ff96c6b4fd216860a4c48ed248940702f3b7acn/aHeodo
2020-10-17File-2020_10_17-QI40903.docdoc cbabf68dbf69bbc9e13cf1c4decc549416db53379348b45da4b5fedff65152afn/aHeodo
2020-10-17Inf 4225822.docdoc ba1aeafd7f85b7fe6d27c96a0fc87b47c20150c8adb74124716adeb6ef26a98bn/aHeodo
2020-10-17MES_645539.docdoc 1cee91ca2689e165e0a72614f98d0dc71da6671ecd0e7f32bb3d6d2710e8dd0dn/aHeodo
2020-10-17doc_20201017_086997.docdoc bf49014159c593f5f2cf87f3a240cb41dfb19400169039b8530fb844a82b722cVirustotal results 52.46%Heodo
2020-10-17dat_20201017_AI5376.docdoc 8b3323767793829332133050855ac69ea1a0cd1b5a51441f1baf16d09f47e663n/aHeodo
2020-10-17UNTITLED_TKY4359.docdoc 3fef345a1fa8f779f98589ca704dff21e59f8842175c3cdab8caeb16e5e61ad2Virustotal results 53.33%Heodo
2020-10-17Arc_2020_10_17.docdoc 78f2969b92269cd9a3e1cc7003b0949f47421d551c323dbeafa94ad0a836bf34n/aHeodo
2020-10-17File-2020_10_17-452835.docdoc 115b344de8011d635adae59417a4dab2f992101ce81619ffe1b1b0423d9df79an/aHeodo
2020-10-17rep 2020_10_17 X00251.docdoc ac172c6a7fb2f8004f019c9dd8d7400f660d58187ed3adcf2502c5effc15271bVirustotal results 51.61%Heodo
2020-10-173633725-2020_10_17-FS937.docdoc c64264c7336d7e9f516999fa287be55be63b634b63f5ebbf1bab24e38ada5e8eVirustotal results 51.61%Heodo
2020-10-17list 20201017 GLN082790.docdoc b5ea62943f3b8f07f8fc66e4e35a1d4d12022eae32ee901b016f48bf66fec06fVirustotal results 51.61%Heodo
2020-10-16UNTITLED_20201017.docdoc a9d9b8357ff803bd36d7bd0c12c770487fe774ccd22e81318606bad0f6ddaf90Virustotal results 52.46%Heodo
2020-10-16List_LSG72999.docdoc 528b63ef8c44d0a5b08974fb6ad9efa60e0021ce6993d25b30ef1b90c00df222Virustotal results 50.82%Heodo
2020-10-1686365882 2020_10_17.docdoc 5ee53916c491a77206e7a09eb75c02983fae90474ddcb7d0099a47113b4675acVirustotal results 50.85%Heodo
2020-10-16MES 20201017 ZF448751.docdoc 8959ae20797df624723d7bba61da21cc88ef3750df52dd083d9eefbc5d90c4dfVirustotal results 50.82%Heodo
2020-10-16Dat_5927.docdoc 164394c49305b99720cbc80504c003fa10b45232decac5c6e7ec20bf1827374en/aHeodo
2020-10-16List-20201017-AFI0057.docdoc 5c58c91ffdffd84690c6746f6afc2eaeacd03df2e4a83c6e662755624113cf5bVirustotal results 51.61%Heodo
2020-10-16FILE_2020_10_17_317011.docdoc cecc7a6d54b23fac9722185d9674512f5b51840e9909978de84128d07172791bVirustotal results 51.61%Heodo
2020-10-16inf_2020_10_17_4366198.docdoc 10b0ede6060dd0c9b69d6519e93f211c940959e36b1e98a6dcc1ad9a4093c4acVirustotal results 51.61%Heodo
2020-10-16Dat_20201016_GFJ4793.docdoc 0d613e3b8dd87abdca992787394ba93c986820dd46d13b63128699ff814aa6e7Virustotal results 52.46%Heodo
2020-10-16Mes_18447.docdoc 6db73d3f7fc4ac1265b81af31cd04fb1ef63de503ea603a20b93daa896e18c11n/aHeodo
2020-10-166864836_20201016_FS28272.docdoc a0851102c87a910c627e0d68a5e41dd1b448b75e66fab4bb0623715d71b6a43cn/aHeodo
2020-10-16Attachments 20201016 434380.docdoc f4af9d4a8529e7b2cc1ffc59afc271f35f63fd2f0b043cecdc60553c2ff8259cn/aHeodo
2020-10-16list_2020_10_16_6964566.docdoc 35359c56db6c6b554320c0f3f2f1ac6470ee849d0e7bdb20696c529df2a3336an/aHeodo
2020-10-16dat-20201016-1915396.docdoc f57355bd1efba81163d91947723bf0beb7e259ecb320963ccec0c38d46cbbbedVirustotal results 48.39%Heodo
2020-10-16mes-20201016-4063.docdoc efa2f9cffa55872a76e7c96262a7d1b6fefb7d09a0512dc93ce7ccbdca723fadVirustotal results 49.18%Heodo
2020-10-16LIST 2020_10_16 028736.docdoc cddaad4c09d5c497f3c53c286d7d3bef737c2e484a95701735a5b80175d92ee2n/aHeodo
2020-10-16WPH69097 20201016 23581.docdoc bddf126e79e9a62c235c0b9b763a594d8c49fc76d38f39400409262f43373d43Virustotal results 48.28%Heodo