URLhaus Database

You are currently viewing the URLhaus database entry for http://www.vysokepole.eu/AT_T/IfV499OcwOF_xfOb2EN_zJNfM6E/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:96365
URL:http://www.vysokepole.eu/AT_T/IfV499OcwOF_xfOb2EN_zJNfM6E/
URL Status:Offline
Host:www.vysokepole.eu
Date added:2018-12-17 16:48:51 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL:Not listed
SURBL:Not listed
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-12-17 16:50:34 UTC to abuse{at}websupport[dot]sk)
Takedown time:6 hours, 42 minutes Good
Tags:doc emotet heodo

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2018-12-17AT&T_12_17_18.docdoc42f72d4b4d95a46450081cbfbb4fe046b1a556955a476242a3dd4a1a512bbc92Virustotal results 22 / 58 (37.93)Heodo
2018-12-17AT&T_Account_12_17_18.docdocb370717eac41b25da9e8fefc279c0e952a15e996a5fbc2983f306166c0169688Virustotal results 21 / 58 (36.21)Heodo
2018-12-17ATT_12_17_18.docdoc37cfad166cdd649fe76a657b06f786b0a6e200c711801835fa97210b4dbcedb5Virustotal results 21 / 59 (35.59)Heodo
2018-12-17ATTBusiness_12_17_18.docdocc042a0b97a58e96e5c9ba6fb20bebdfe76caa54ae1c769c80c64f6edc8ab10d0Virustotal results 22 / 59 (37.29)Heodo
2018-12-17AT&T_Online_12_17_18.docdoc844f55f6a4bc27b0c927918d78013e4196cf4baa6ba6ac75a51aebbe0bca8352Virustotal results 20 / 60 (33.33)Heodo
2018-12-17AT&T_Account_12_17_18.docdocfe8cf799c2eb432183f5ae3a4a23ca6f0a3a075e98f9963a747f7a97e6cf768cVirustotal results 20 / 59 (33.90)Heodo
2018-12-17AT&T_Online_12_17_18.docdoc45f9dac959237d833f6e4e4a9887f61614ee1f0aa666c87db01779d79c56c585Virustotal results 19 / 60 (31.67)Heodo
2018-12-17ATTBusiness_12_17_18.docdoc24e8ff986c68479210842aa6e7e0bf73308e8170ab11e2951ae47a49fa35090an/aHeodo
2018-12-17ATTBusiness_12_17_18.docdocac97368466632a03feb2e7533cac8ad8422bd9e182e282d8aba4b677797c8185n/aHeodo
2018-12-17ATTBusiness_12_17_18.docdoce8a06d9faebb561e5b33e6616484870d2e5c47e92dd4138d8e7f2d72f20f1a53Virustotal results 17 / 57 (29.82)Heodo
2018-12-17AT&T_Account_12_17_18.docdocabf57db83c704eb1330eff70afe8a351e3120cc2df6e9b114c55053222e97456Virustotal results 16 / 59 (27.12)Heodo
2018-12-17AT&T_12_17_18.docdoc2379f0a4dfe38ac3eb97b226bec456dd0695ade6c31ca839b1a37458f377dfe6Virustotal results 17 / 59 (28.81)Heodo
2018-12-17ATT_12_17_18.docdoc8c2403139277c4f89a353a95ab6ec2db6869d0a6726720e25d877d52dcac2053n/aHeodo
2018-12-17ATTBusiness_12_17_18.docdoc9e139297096f9656abb65f3cf3609509c19792454256dfeee25699067175ba69Virustotal results 20 / 60 (33.33)Heodo
2018-12-17ATTBusiness_12_17_18.docdoca59234379933f350631119d96dda90c455feb4139c8b61776f255975260d45ceVirustotal results 17 / 59 (28.81)Heodo
2018-12-17AT&T_12_17_18.docdocb3eb5649c5cb138c77fc85436663c0fe7d263cd5521f0abf463520afa1da25d0n/aHeodo
2018-12-17myATT_12_17_18.docdoc95b5ddf23759f205358d664fc5aa42d05b876c2710cd6692212821c1179072bdn/aHeodo
2018-12-17ATTBusiness_12_17_18.docdocf7e1390eb780df28e8df64cecf87f72464aa5e2627fac7c73e0c6c3d7d204b8aVirustotal results 17 / 59 (28.81)Heodo
2018-12-17myATT_12_17_18.docdocaef1faff92f2b985df9b91a8e70c1effab6fb8d48ab7c45210925c87d819b59bVirustotal results 19 / 59 (32.20)Heodo
2018-12-17ATT_12_17_18.docdoc71ce0dde99deb387a22f2260d05da9e019d560f1dfd74272404e83aca1e6a241Virustotal results 17 / 59 (28.81)Heodo
2018-12-17AT&T_Account_12_17_18.docdoca7fc4292a2199a88ccc065039d3c0aedc498363934ab5b44667aa40bc0c7a0d1Virustotal results 16 / 60 (26.67)Heodo
2018-12-17ATTBusiness_12_17_18.docdoc5fc837cec1abb150354341cfd7c63d4207320bf62164728c435cab8d8c953bcdVirustotal results 17 / 59 (28.81)Heodo
2018-12-17AT&T_12_17_18.docdoc1494e0e1b3d206505f792badd5b63ec6965f130cdaf95aa426a18dec1de69d36Virustotal results 16 / 59 (27.12)Heodo