URLhaus Database

You are currently viewing the URLhaus database entry for http://zeroz.org/cgi-bin/ywvLHJtfcSPkOB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:204199
URL: http://zeroz.org/cgi-bin/ywvLHJtfcSPkOB/
URL Status:Offline
Host: zeroz.org
Date added:2019-05-30 17:48:03 UTC
Last online:2019-05-31 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-30 17:50:05 UTC to abuse{at}strato[dot]de)
Takedown time:18 hours, 18 minutes Good (down since 2019-05-31 12:08:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-31DOC_70241163054US_May_31_2019.docdoc 58c47c1e48d2560fe96dc03eeaec4ef61cc4b057eabc323ff140d505ec9b2358Virustotal results 28.33% Heodo
2019-05-31FILE_49454770747US_May_31_2019.docdoc b8ffba5933a7f1ab10640674515407df874291c9b965091706b22960b3dadaaeVirustotal results 36.21% Heodo
2019-05-31INC_904055852370US_May_31_2019.docdoc 96e2d1631b87443d845db9feb1cf3afe3bfa55759427a709cc4889a20c4dfb29Virustotal results 35.00% Heodo
2019-05-31INC_179562731524US_May_31_2019.docdoc fd069522510ea62adff60131da1c05ab3f96f3a55626d8e55366139d50604bb3Virustotal results 34.43% Heodo
2019-05-31SCAN_72077830735US_May_31_2019.docdoc 604e7437bdf0853595db1c977dd317397071a5836d0b61387a9b4d4374468837Virustotal results 32.79% Heodo
2019-05-31FILE_485954919231US_May_31_2019.docdoc 38950a41bb0d5c61efcd0dab8ffae15d49454a792dd55507eb3fd2cc1d1a2a3eVirustotal results 27.59% Heodo
2019-05-31LLC_09445536698US_May_31_2019.docdoc 841ea7eed1c264c08b46b6feed248dbe7bc255773c0b06a9bf565a43ff54e808Virustotal results 30.00% Heodo
2019-05-31Document_06225246439US_May_31_2019.docdoc 9fffd9f534100b5348a4ff4ddf6b4da08e29b57344393753149036f7255db790n/a Heodo
2019-05-30LLC_494858066432US_May_31_2019.docdoc 7a973404b546486366191a83c0e04aaa83a732b2133883f1a9246c296318d79fn/a Heodo
2019-05-30FILE_382609071091US_May_31_2019.docdoc 3b8afd70befb29f9b95436a16fa5dca6193af7788369d026e065f70872078604Virustotal results 30.00% Heodo
2019-05-30DOC_19687920660US_May_31_2019.docdoc 7199fe3252da097c2d34bc1eecb2244a3dbece169e34f5674b24ad11234b6895Virustotal results 28.33% Heodo
2019-05-30SCAN_608214542215US_May_31_2019.docdoc f4a07f1a4cd30e9347ee1ad7f30e1924786dadb1d6ed788fb2fe7348a928e623Virustotal results 30.00% 
2019-05-30LLC_43180444807US_May_30_2019.docdoc 59c2d27bd9acdfa4f8097b8252e06faee7f0affcdafe972f7d0defbe57428fd7Virustotal results 28.33% Heodo
2019-05-30DOC_37695450613US_May_30_2019.docdoc 2a378777103ca9f6260ddf24452a45f249bdf207026d595f1cf47c1a85de1b61Virustotal results 29.31% Heodo
2019-05-30FILE_904773597933US_May_30_2019.docdoc 0cf70cd6e3ce218ca6e0fb3bb7a79d13b176b75c4e29a332fad0aaee559f6970Virustotal results 30.51% 
2019-05-30FILE_3193848252US_May_30_2019.docdoc a0d3dd45a0be8ee20a71761edb88f95567392034577c0de2a7b43c3977f1a1d7Virustotal results 25.42% Heodo
2019-05-30INC_94339648553US_May_30_2019.docdoc 230c0ba0db8fab4da33517e2b6a245c359cf04fa1ac17f877bcb5aa30ca1b0a5Virustotal results 25.00% Heodo
2019-05-30DOC_6571798866US_May_30_2019.docdoc 70b6d041f2b2be97e5fb0986bcfe40882c2f567e20b2c5d8dc9328f718293ce2Virustotal results 33.33%Heodo
2019-05-30DOC_9912162302US_May_30_2019.docdoc ff60d17aee6a178f5d9506325bbece194f115bd4e8e16eabab54796247372617Virustotal results 30.00% Heodo