URLhaus Database

You are currently viewing the URLhaus database entry for https://zina-boutique.com/cgi-bin/kfmEs6w2dAuZItVSQ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1868901
URL: https://zina-boutique.com/cgi-bin/kfmEs6w2dAuZItVSQ/
URL Status:Offline
Host: zina-boutique.com
Date added:2021-12-09 12:44:09 UTC
Last online:2021-12-11 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-12-09 12:45:59 UTC to abuse{at}versio[dot]nl)
Takedown time:1 day, 17 hours, 5 minutes Poor (down since 2021-12-11 05:51:38 UTC)
Tags:doc emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-093FL4E9BFC7W091.docdoc e167804a6f36dc99e96909bcededa8a733dd8633037b8b52e8d7881d20446c16n/aHeodo
2021-12-099DB1CGA.docdoc d69f3a0ab3de59ef3cd8461d88492993170d51dce254ee1097cb8abf5a0bf018n/aHeodo
2021-12-09Y52H1PU2A5EMJ.docdoc 31f74ee846fd6f95ef9d7b418cfd87fbfeaaee7caacb1c306d8747f85fae3f25n/aHeodo
2021-12-09KSA4Y6PZR.docdoc 4e3c2a99198c29669026c373ba3cff9a3238271504a0a89cf52a7f8c8579cdc1n/aHeodo
2021-12-091TUQCHEP8O.docdoc 0bd193c285d357f2d8207c3e78588727dd95c81425e8ff31e4f6abb76923c470n/aHeodo
2021-12-09U8Y2RHUO1PIOGS7A.docdoc 60070dc681a9f7c4a79a3637402a55b5c3e8fba4a2df0ce681f0b1ff311a360an/aHeodo
2021-12-0904VQ00R.docdoc 4f44ffd049b3a76216c9ce38ece3241e925a214381ca202ead5b666272965d63n/aHeodo
2021-12-09I0JR3SO93EG.docdoc 6db713111922141d1e216988ca94471878eaf0cdefb37f14a61a6186c9590e19n/aHeodo
2021-12-09FKTHK4V.docdoc 29ab4068dac49ad35bee5d3ae9be67726d2ea73c28d437bcbf827bfc5ca372fan/aHeodo
2021-12-09DRYTK4SMFT58Q2DS.docdoc 5b0eadb028eafbc9bb1285c63f7a0fc68a235c037f04e81324474972367ccfe1n/aHeodo
2021-12-09KXGK0ZKK.docdoc 7d50155f2fd02aa6067f653d01ca3cd296b9851974f23904b601fbffdff9fcden/aHeodo
2021-12-098IUHPE19SSKLT5Z.docdoc 5aee37b45c0c6370d6c4b8046356675ddbe62d8cb42dfcc602bc350600df64e8n/aHeodo
2021-12-09D5SX1X3O4.docdoc 052fa4aa100211ec170bc835ccee15ab601aafbe131ec86a16b553a0b2f17b4an/aHeodo
2021-12-09T8RMTTQHA.docdoc d88dd396f704e6960eb6137eb6c8ef401700c2b021f80cdaa0cfa9e34ea0ad88n/aHeodo
2021-12-09KLY0GHQG9H.docdoc 422cdaf95ec5f430f907c9acf9538f9b76473c10d984ea3370753d2bd8a5d7fan/aHeodo
2021-12-0923MNPFON5BA52.docdoc 0be9d6cb334fc62f10b751c241c8f21645a12c17e1ad1ef4439a9ca0ef278ebbn/aHeodo