URLhaus Database

You are currently viewing the URLhaus database entry for http://qzltrading.com/receipt/4161793752/SsLte-Wv_ds-DH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:124534
URL: http://qzltrading.com/receipt/4161793752/SsLte-Wv_ds-DH/
URL Status:Offline
Host: qzltrading.com
Date added:2019-02-14 15:44:23 UTC
Last online:2019-02-15 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-02-14 15:46:02 UTC to report{at}parspack[dot]com)
Takedown time:13 hours, 39 minutes Good (down since 2019-02-15 05:25:29 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-02-15REFUND33182345614.docdoc 2bbf03b597e2dc3ae4fbd2958109e6f9a198d2ef04dad0bbecedf8ffdb93b35cVirustotal results 28.57% 
2019-02-15REFFORM276441884611.docdoc 35a4c8ee4228e816bd4eb08f3b0a88c8a7c0d59979dad87c9cc891e0a9554ce2n/a Heodo
2019-02-15ACC0983767056.docdoc a98ea85359c668c0f734b3b93044d2b3b9d1bc8d04359905f616f2099b82b038Virustotal results 24.14% 
2019-02-14FORM_REFUND440603076163.docdoc 5ede447198fd9790905c29e6810244fa57fbba49dfe1adcdfc3b9eb0be5f8fbeVirustotal results 22.22% Heodo
2019-02-14ACC375344042772.docdoc 93d436758cc24dfad3d575c3794ccbed12ff44d6d9f0d76bc428c470d5b89608Virustotal results 19.30% Heodo
2019-02-14RECEIPT9621236385.docdoc 5e09937233d3be286d6935cedca2ff4954e7b36ecc582a2150d89686357b77een/a Heodo