URLhaus Database

You are currently viewing the URLhaus database entry for https://z-r-law.com/landing/romIlSQqFzR824ezJ1nQyl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912361
URL: https://z-r-law.com/landing/romIlSQqFzR824ezJ1nQyl/
URL Status:Offline
Host: z-r-law.com
Date added:2021-12-23 01:06:13 UTC
Last online:2021-12-25 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-24 17:31:58 UTC to abuse{at}upress[dot]io)
Takedown time:2 days, 8 hours, 54 minutes Poor (down since 2021-12-25 10:03:50 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-24040346471629192713654.xlsxls 7a1108c5d9c895654aaec57e2d820d848b928f2ee8140a87f67dc877cc186738n/a Heodo
2021-12-24X216829501231584413.xlsxls ffe92f7aaf260898f3df88606385aa7439c7398c65f9a1e559e3b8fe2057a026Virustotal results 14.04%Heodo
2021-12-24F2545911286593008818.xlsxls 3fdfa8fca0397d424779a3ce7f0e46682e6fea8603c388108a5f5d09800310f4n/a Heodo
2021-12-24V38572672306612J.xlsxls 2cf8e31889bc2fc3411cd90cd393663c25286cb24d94b2fd009cc5936d7bf8fcn/aHeodo
2021-12-24K142104593277370.xlsxls 40325be64d0277f1d44bc5fa218ea5a5acf338b5daf6b5ccad3e39d4dfa3a5a8n/a Heodo
2021-12-244522760153.xlsxls 3317a4e30189b050f520cbd8b91a5b1d205b0ee92b7f9249fa05283c1833dab7n/a Heodo
2021-12-2459242896057B.xlsxls 90b7cceec2847da6f3d058a594cde1c8a5b723a133b45746f0ee240ef37dd67eVirustotal results 14.04%Heodo
2021-12-24769613733992.xlsxls 7dacb839aaebd399571b719580bbf80651e75209464b8ceec4a6563b964b8f3fVirustotal results 13.56%Heodo
2021-12-24786277860859452.xlsxls 2d1a9e680faad9427e7bf65e180a0b666cf952ea1853232e4a4ace7eec43b15an/a Heodo
2021-12-24Z9002423296904.xlsxls a822ac244946d74de9a6d4d72792fe0c7beea3f0bf8257e5d1a2c019ee320e58n/a Heodo
2021-12-24T28217451917154557.xlsxls f996e0b743efaea3a433be0deb64a90ab1333b17170819c677f6d91eacba3177n/a Heodo
2021-12-24721383465936320858963.xlsxls ab6f1003eb149818984e3f59fc72f4146a16ca1fb99f80f128b29f2681190e9en/a Heodo
2021-12-24X7569160B.xlsxls 942cf47bc37c1cd12b79363b561b7d9ab5bb327700b26f9775c4014d903e1713n/a Heodo
2021-12-24H5711546.xlsxls 4925c4e6ebfc4a1527aa27571593704e38d106751c517f19677a1bb100a1b7a6n/a Heodo
2021-12-24P354744709J.xlsxls 52ca2106b29802043f3b5295e65bff2fb7c6e40510bacdf11ad7fb12c194a48cn/a Heodo
2021-12-24C87353228.xlsxls d6987bc82da66d589bc494be71837529a2ebee4bbc7261bc94c0c4ce6be08053n/a Heodo
2021-12-24446264728428999.xlsxls 9824333920b7b927b51675fad13b8078434cb5dfc0e795e0448656334d222666n/a Heodo
2021-12-241808019002992.xlsxls 864e888739c1db69ca9571e14d935805ea8699b691845000ba85c5f1311eb2e2n/a Heodo
2021-12-24F1000297387190341610.xlsxls d3608ac6d5e7dd6cd5087f173b3352d64b5c34dbc7d8fa0d2d5ef040a066f200n/a Heodo
2021-12-24I0992388819582017.xlsxls 3c8d49a046157a3efca16ecd5e1786f4e1a169c2937572c322165f0048c34ed8Virustotal results 27.12%Heodo
2021-12-24G163578471332937087818.xlsxls 40027d0ef9f117e225450dd036834a009471833d4941317124256319a4da1f40n/a Heodo
2021-12-24T0336216096.xlsxls f9ebb3b7f652ca818c4394874d8bab531f34bb748fe010497e53c79f62962bd5n/a Heodo
2021-12-24R500941675208873814017.xlsxls dfd7779828492c51dbf83bfe709e2b29ae854940801beea6a77ad5734a9bd1eeVirustotal results 11.86% Heodo
2021-12-24E1937357606814187917.xlsxls 00a0231a0404a3d34c4e1ac3b596de550e696cccae94c7d26fcb9b997eedfe6dn/a Heodo
2021-12-24V725518475554.xlsxls 4bc6426e9b3e82b0f2a8472b28dd62d91af6800f6bf24bfa295d2ed71085514fn/a Heodo
2021-12-24Y117649124.xlsxls 88c5d701915407e6b24d8e53e41b428e1bbb0aa2d884fcf827ae1cac5e5a5754n/a Heodo
2021-12-24P345987504.xlsxls 96b1e0959f08cd6ff91e59c2555eed096a7d25a5a58e7749cdd105ff71c82d5en/a Heodo
2021-12-24M7378901429009.xlsxls c9ed7cd28c8f21e2ac04b27a30cb61da8793b1597871922a524ff42d467d8396n/a Heodo
2021-12-24M195805790762242.xlsxls b890dec1230f36728207c1188371965690acde07376030e28b3d563144c2aaf3n/a Heodo
2021-12-24N2955099308.xlsxls cdbb955f375a588fa658c5e4b65fecca4256c01531aeaca4dc573ae0f22aa96bVirustotal results 16.95% Heodo
2021-12-24U113792279400216360.xlsxls 40312f1abdb015946505d6e1e979cd664541d0f80dd892247bdbe578a47343f2n/a SilentBuilder
2021-12-24W602050667993796.xlsxls 1877211be5c8aab1a2548c48de3e59ae0c82e2519d6cf0e867b1c96ae170dea7Virustotal results 28.33% Heodo
2021-12-24Z580370212210677.xlsxls 5dd5d028f230eebf3fce6cc37b76fd84532db7511e0567336b92bc563a5370can/a Heodo
2021-12-24F08852964810912769.xlsxls e3107603083a6d759ddc850614107753492874c668f138f2adc2e08a0ff6548an/aHeodo
2021-12-24K434873891.xlsxls e5d54c7b48b69567be57903ee78decb03f41ef42725eb8143f386a6873e1d13en/a SilentBuilder
2021-12-24I7070131839.xlsxls 1044e20d92ba2de92d1f6d4bdc5abe76df396556e51952b83353cf9421a30663n/a Heodo
2021-12-24C8052971394988.xlsxls b162f10f8147c6dfe4d058b3b753572f71897b6df59a67216468d0754e54891dn/aHeodo
2021-12-24Q660135395390266.xlsxls 954b6d66e38fa57ba1899919adf37a030cc4acf3879c300ba5309fc20edd6e25Virustotal results 26.67%Heodo
2021-12-24X22506150662198.xlsxls 751b4d3397d981fa9b9754f6865c4afef0845dab67264651de9fc51156affa13n/a Heodo
2021-12-24P157569160716904744945.xlsxls 989761fa0d490c736b7991b5d81906236aa176cdb5e1d9462a6982d29751e335n/a Heodo
2021-12-24V91928567508021721439.xlsxls 26d94b73b15f33bf95bb66650d5301c55998c58910c22f3eac6544524b29eaecVirustotal results 10.34% Heodo
2021-12-24G502831713452152628891.xlsxls e816b8af8419f2ff9402737cf33c8a97c8c9f1ea64bdc49898c5e3879b49278dn/a Heodo
2021-12-24W09684208741.xlsxls 7859496c99048f59656e296bed199b8e52ff3d9d5cee44a2794e52858caf19d4Virustotal results 21.67% Heodo
2021-12-24Q84366611.xlsxls d7b1cb1ae00dca8fee12505663178144a9f6e73485e53b9e5bc644597514c2b7Virustotal results 26.67% SilentBuilder
2021-12-24P9308201.xlsxls 824a3f0277b943e71033fce00144f02f387109b820629795a6004b19b78504b4n/aSilentBuilder
2021-12-24Z106248945312.xlsxls cc99b256f4bd99f566c2e661dad0467b3be777012a49e0d95cbc80c80a8cd491n/a Heodo
2021-12-24C8351599729590410.xlsxls e1acc3c3226bb7e587798b540b427813726c832ae977843915fa820def5d4406n/a Heodo
2021-12-24J0700563293.xlsxls 6cad1d9ef68b473f6f5f62f4fbc6742e81a8f967d9f242996fe49cb7c5eacf6an/a Heodo
2021-12-24X971968101.xlsxls 287a7ef27eed8371f56478d165928ae0ea26a650a32d3d461220b20dc696a43fn/a Heodo
2021-12-23T0052895337418.xlsxls b2af5bbfd6076126cdf53ebd3d6a7f2ab27479ff5157a841a6a41bda99aec50fn/a Heodo
2021-12-23T03978650093.xlsxls c40d34e4a36e023913b611711194fee37a9cd7a63feda45a49387e897df904e0n/aHeodo
2021-12-23S01593867235321.xlsxls ae275aba1d935bd3045e9cd3f258b72636e6759506e183423341a992faf47f80n/aSilentBuilder
2021-12-23W7843459516490097.xlsxls 945deb86efd203ed3d615fce5604a879cafb463bd1a754d2eaf4b369961dee84n/a Heodo
2021-12-23P94074321440.xlsxls f5636a67c71d59ffa42ac87611bfe0c7161dec9d5004d04377528d41ae630e1fVirustotal results 20.00% Heodo
2021-12-23K1526015999650.xlsxls 1f5252bc724a264578c9a7e4085d19f80453627a4329a0e7c5733a699ec6f400n/a Heodo
2021-12-23S2878500099324152688.xlsxls 6b91c74b0d9289320dc3bd15ef9eb3a130db4442a976774e433f9004d656fc78n/a Heodo
2021-12-23W67767465194572.xlsxls 65d219b297e96b026b875c52560360f48d01fe25ccc78f5fe739804a4b4f05c6n/a Heodo
2021-12-23L9864954830126217080.xlsxls aa64beebc522dbbe289a6079db2bba77eebd7ec04ecae92c168b69a997433a8fn/a Heodo
2021-12-23K0028468013504923.xlsxls dc1641158c36eff2c4d91bbb19781d1af7344fa0f7caca62597bc783e242fa5en/a Heodo
2021-12-2362098859624.xlsxls 90115998772138bffb8e1316af9f9b63cda8d85f8f3aaca09ee5e79153831822n/a Heodo
2021-12-232312391449.xlsxls 95972f16bcf8cd10561dc8b65c0d73c85be8fb37d98dfd14ce088d7d6f2ad53fn/a Heodo
2021-12-237525930236.xlsxls a5fa2e29416d63ec073466d556f1fa42d985d0438600e8422de2de87e26c3371n/a SilentBuilder
2021-12-2399565106618840.xlsxls 7e621b111bf07463db0eee68a3fadaac1688642aa36f1406be1215547b36d7c8n/a Heodo
2021-12-235106651362.xlsxls c57b5b0f907c2913aa78ca6b68ceef15dfb50e8a109427f3554d203d65932182n/a Heodo
2021-12-2315378694.xlsxls 09a0c26818f83cd912922688f32145dc3457a678a5494ea4ff48f01efbe81179n/a SilentBuilder
2021-12-23915219497135.xlsxls 60aba73bffd4d8285cd0fd090d2ae286e12fe0011cdceb5a260d731b58677462Virustotal results 10.17% Heodo
2021-12-238107248321561395.xlsxls a481d58b9b01954ee8c6c3d44b8297c2cfcc3895f07f9beda648106cf39462c5n/a Heodo
2021-12-230286815494783.xlsxls 3fcc643de96cc8f42515929e84f68cfb36f28537b37a1fa152bab2898d161a0fn/aHeodo
2021-12-23154860341.xlsxls 957e2e936bd6ccfe9ef8d01273e933fee42bbfa89142d57f2e4aa35c9f7c701en/a Heodo
2021-12-238914204527807405.xlsxls 0a1a9eb7e560b07a4193785740228d849600670776c5c9046279adb52c35bcd2n/a Heodo
2021-12-234274409.xlsxls 1abb015e73fe7e537eb6e24b839ca986ad28652e1f65c4a5f557fd37249253f2n/a Heodo
2021-12-236280832787408676.xlsxls 2a170f15029d9d55b7dad42d14f58e962f45df96879073456075ca40bcbdcb68Virustotal results 25.00% Heodo
2021-12-238917714765.xlsxls 09cc1626b7035fceb82fede2fc19b9df65357eb5630793a34689999428696598n/a Heodo
2021-12-236297115804.xlsxls dd50d59e8cac9895813154ed63dc4c845636e1a3de76904f6eeac5705a5ae9a8n/a Heodo
2021-12-2387026814567900.xlsxls 65916858fdb5070aec22ea8b657a21ea61852283555116ddb92f9c7b83433982n/a Heodo
2021-12-2308709437.xlsxls 38990b98bcbe75f670a50ad5bc99c0f1e88834d51c84e93f221b88b4472c1a04n/a Heodo
2021-12-23988073483942.xlsxls 03359a1154c46ed7fa375c6d220c5f9b236f8a324657b3898d86eab19256913dn/a Heodo
2021-12-239217522.xlsxls 180264d53532243c05c249958ccd328feeb47ebd7dc9cc816cced55fd22c288fn/a Heodo
2021-12-238770764213968.xlsxls 96db156560d85a9601b70c1a695e9e2c1f1a7553af38397f29d6e426528663can/a Heodo
2021-12-2303347606751.xlsxls 5d1f5d444aa2f95ecc107aeda2aab52be49b64103bc947cca075ef765e8deacan/a Heodo
2021-12-231438947.xlsxls 1cdf3a619c05c0721bc6b9a6f7e9153c9ff4d2f47118ccd0ef47afea64427d13Virustotal results 32.20% Heodo
2021-12-23606783750.xlsxls cfb91f4910d1b97c2d722dbb1d10b841a79af5011be3ee5dbcf47468a6db5083n/a Heodo
2021-12-230349497528751791.xlsxls 02f8f694d0b0c1188dd29591de21f625cb608a8d54487c1c7f5a68340b09f57cn/a SilentBuilder
2021-12-235214329553476407.xlsxls 2957ba9f049e25eabc2b1db094df4b4e0f8062c60f1d0483c722095c163ad263n/a Heodo
2021-12-2329137979.xlsxls b332f811bbd708b5f415c650da7ed0dc66483c140ae16e2fc8879d77be0be661Virustotal results 23.33% SilentBuilder
2021-12-23425181705.xlsxls 06a7f7a6296b774253c7bc810254dac777e521daaef2ee031849b9194c635529Virustotal results 25.00% Heodo
2021-12-23927330332.xlsxls 296e3773821633c66d27b4c4438ec9ae76ee2cad7fc00a9f6b852394ca2b1a41Virustotal results 22.41% Heodo
2021-12-2375169043691.xlsxls 99ed0d39c05e7f5c0495b4112cdf0cbc2fe07e88066b644524f134b0450a87cbVirustotal results 25.00% Heodo
2021-12-23660844573023330.xlsxls bf9c5da5a619725b7e1236035d41d5bfd7d3aa3d88d0be766d31deafc00bf5b0n/a Heodo
2021-12-239581511183231755.xlsxls f5c3b27d88339e8bab3bb47ce63b717a99264bc1e8c1d6866dd12260138ad2b0n/a Heodo
2021-12-2312167331.xlsxls 0e32a98533816d8ab208379bcabce2d48d062e0de5cc36835e883bdf74bfdbe1n/a Heodo
2021-12-231599421.xlsxls 3f281c52f76f37ec6c7af45149aa8ee290cc1a5c57589290447e8cb2a4bdce9dn/a Heodo
2021-12-2335106072326694.xlsxls 91d4f32d6a37e6013639cd5e523e6328604a95436f8d3b266480f57a97599f2cn/a Heodo
2021-12-23416204663213.xlsxls 435a3b34c0bd974f368bce0cc95457050f3e727c580c104534377c66edfc8ec2n/a Heodo
2021-12-238217335074950.xlsxls 2cac0d0653467c80cb207bfb43d8d6f57e7473aeddf92a47e10c2ae62556f3bdn/a Heodo
2021-12-23797176260582.xlsxls f9d1b2ac0446fed5d00c61bf9767fba85018d86908c3a74398d4f2c30f3d080fn/a Heodo
2021-12-234121457467943531.xlsxls 38b0a1134b4dbc0535e2af788c285b2a9a920118a4c467b12de6841242437041n/a Heodo
2021-12-2318076496.xlsxls 9f16e116a70060507f773bc94da066aed1c061ee297187782804cc292e0bb11dVirustotal results 25.42% Heodo
2021-12-23643508586.xlsxls a830905d19c1b1a262f5b6484dcbf74166b52e6742b363f5049fa03cec849557Virustotal results 25.86%Heodo
2021-12-2367424261.xlsxls 4d8d170d7e4981f57bc7f628b4ac01800a7c97e9edc66396e79bb788781ee407n/a Heodo
2021-12-231828545376.xlsxls ef628739521d7af4df6459f02442985d4a9a3f122cd55c98540bb3a1d648cae5n/a SilentBuilder
2021-12-234342781288720.xlsxls 2991e95d6d3b92341bd33e2c9dc75dab521b1e38be10120fdc3e542ee4eba881n/a SilentBuilder
2021-12-235584732448939316.xlsxls 11bacde63fd95e99c4061fabbba6c504fa4e782eb0923513bb8e6433857ada23n/a SilentBuilder
2021-12-2304520140277934.xlsxls 0934d436a87cc83e019e9ee2949ead8c647bb4c26738be5c91f568dd6f023c2cn/a SilentBuilder
2021-12-239328882175810.xlsxls f43334acc07f6a013334b7399e0e4ce391fbfd6a73dd40daf68397d1de426731n/a SilentBuilder
2021-12-237978651413.xlsxls b4fdc798e4c49df58164144b8bc115b1f9757ee3ca92832554dd921e65ea5e24n/a SilentBuilder
2021-12-23011056661581233.xlsxls d518f3288658ae304b6cf729edc4df00aa31c18bc6ddf5586518d077bab48b71n/a SilentBuilder
2021-12-2333162650979131.xlsxls a36fe3a855e95e22df1200bc1678183cf6e56215d765ae39d4e7728cad9971c6Virustotal results 20.34%SilentBuilder
2021-12-232473850375096662.xlsxls 35be18251c8a0a0f21b6db45c2238f65f17a18168556f31e146652496bf60926Virustotal results 21.05%Heodo
2021-12-23108622701108110.xlsxls 52a5a4d7c1aa0abcc55b9f88a4f0879c142237774c175dcb7f448f08561ce2b6n/a SilentBuilder
2021-12-239035635998207.xlsxls 7322337b79e75a1a0b494af3b323e8c60e134eab541ab836ee4a943ada51a268Virustotal results 11.86% Heodo
2021-12-232392408566923762.xlsxls 2fe52a04ad50a62b3c0248ad8a319bdc8e22cf9ec351f2d2c21b3e433e41d5c1Virustotal results 11.86% SilentBuilder
2021-12-23330110066002.xlsxls a74a6a8140c11fc076d82f4a808994b267aaa839b9076dd2bae14909922e7efdVirustotal results 15.25% SilentBuilder
2021-12-23690804254.xlsxls 1aa52da08de6b2732f449f29515ec792060270972541fe18d3494b4dd4779c7eVirustotal results 12.07% SilentBuilder
2021-12-233303272212.xlsxls 9fbef3bf291c5ce45854de786b83be78d6d79172da8f3dfddc8c752dbf5390bfn/a SilentBuilder
2021-12-239968620.xlsxls 22f3dd823009e3b1c3547eaf2ae78c54fcb499e4a0055c5db099ea28bdea93acn/a SilentBuilder
2021-12-2327000842570892.xlsxls 190fa8d2b5297aeb55c75f696f69cf1a0ea1ab45703e4047dc6baed4708833c1n/aSilentBuilder
2021-12-23490138163124.xlsxls 7ab793a1270a4fb7bd09fb7de0de1e7b5888d779d754cad8c37e66f9c67324d3Virustotal results 10.34% Heodo
2021-12-230338293098514847.xlsxls fc427adb111a2cdd28c3799b619887f125d8c79900419fdd0918cb4f09084ab9n/a SilentBuilder
2021-12-2324588367484452.xlsxls 46549909e329faf4ef851f602d8c1091c253897e0292ae05d83b73da7914077en/aSilentBuilder
2021-12-238479914727391.xlsxls 46d6a384fe1773327c74c5e6daf03b4e1346cfef7e79d6e16045eccea064acden/a Heodo
2021-12-231429535961331.xlsxls 5eb66d76f40bfc2a8b27ae16d451f2f8c3eddb77bf14e8fa7006f0d7ed9925c2n/a SilentBuilder
2021-12-2319042313199333.xlsxls 4ce312179df139b3a8bcaba9729f79e9c54413e250d3124b94050b9656c6c993Virustotal results 8.47% SilentBuilder