URLhaus Database

You are currently viewing the URLhaus database entry for http://zapisi.ru/wp-includes/sites/u7w3dywu/rj2rzl-0080278-21223629-iybr8x-fyx2r/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288502
URL: http://zapisi.ru/wp-includes/sites/u7w3dywu/rj2rzl-0080278-21223629-iybr8x-fyx2r/
URL Status:Offline
Host: zapisi.ru
Date added:2020-01-14 20:49:03 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Blocked
AdGuard :Not blocked
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2020-01-14 20:50:04 UTC to lir{at}di-net[dot]ru)
Takedown time:16 days, 18 hours, 36 minutes Bad (down since 2020-01-31 15:26:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2020-01-16SW_US7DKBLWWS.docdoc 33aebff84e18015cb2c290ec839df0de39edaf26e4126768dd11a34bfd3a825cVirustotal results 36.07%Heodo
2020-01-16RP_QYZ_010120_RGD_011620.docdoc d13b7bb583d3175a5a66a45e56f859a8ad4f514b8461da2c589fd74c69bc4b3eVirustotal results 35.00%Heodo
2020-01-16INV_PO_01162020EX.docdoc bf08f22796d9bd2305d29ef668a5b81ee6ef9d07b49827d05b88f97c74a4b249Virustotal results 32.26%Heodo
2020-01-16ST_14629355.docdoc 67e4ad463f707098e9dd3aa9ef44543687de41237cb6bd15500e428aa17c34c7Virustotal results 31.15%Heodo
2020-01-16SW_WO5332415922WT.docdoc d2ce1838da599f490397183272a746696999155f408cdd5da5d82c3ae1df24faVirustotal results 29.51%Heodo
2020-01-163589639794573.docdoc fd2d1b1001a52d28c40d06dd25d9adcabc14519667f22eb0397886939046b2bfVirustotal results 28.33%Heodo
2020-01-16PAY_PO_01162020EX.docdoc 9aa8f08a047314cbf2c0a541131a486282da8e2657c69fd731624e2823ada6c2Virustotal results 27.87%Heodo
2020-01-16SW_PO_01162020EX.docdoc 95c0c04d9077e6700cdae6bd1f365a488cacb9ad029a7db67bcc29e9992331e7Virustotal results 26.23%Heodo
2020-01-16PO_01162020EX.docdoc 743632f16eaf4dffd8109a5ea7c14e341db9af20a96f44838a046b9c6b183fdcVirustotal results 25.86%Heodo
2020-01-16PAY_PO_01162020EX.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42%Heodo
2020-01-16PAY_234480212206545602.docdoc 21222de7dc129cc2ceb960d884aab5660f053b0186d85f48f302257ae6075bd5Virustotal results 25.00%Heodo
2020-01-168108557534707032813.docdoc a7d3f5474bdca4af088225b9280da969e8678960b6768ab6944a72866252c9dcVirustotal results 25.42%Heodo
2020-01-16VGM_010120_HLT_011620.docdoc 8cf507a5d6fd40526c9419ace90c17b9d91a6949229cd0f5c8afa750836dcf62Virustotal results 24.14%Heodo
2020-01-16SW_FDB_010120_FCM_011620.docdoc b56a6e25f16b75f974d90ac920bb38757ba86412909d0844c3195a7b0a04c757Virustotal results 43.55%
2020-01-16ST_53312328.docdoc bc1ee7ea69d36c03a940c29cfce159c7e7225fbe58610eb697e091e0b242c08cVirustotal results 41.94%Heodo
2020-01-16INV_JD1VYPUWS.docdoc 95b02c0e112270751b5fe7a49866ed9d31594f0b8d26e823e2242bcc3b902b26Virustotal results 42.86%Heodo
2020-01-16REP_PO_01162020EX.docdoc 13aa89755abbea10d5958e7b1d6d8440f1b6cb0d866e6ae70de9a7513e80e409Virustotal results 40.98%Heodo
2020-01-16FILE_8197753860117215843195.docdoc 61dd0c8d9334a27a9b7f0a93c8c4f922a4f2b54a8678d15849759e3529794560Virustotal results 40.98%Heodo
2020-01-15DOC_JH1899093189TQ.docdoc e763d67d538e1928f4e54ed83171e2b9495156d4c51598d1ef77162faecac2d8Virustotal results 40.98%Heodo
2020-01-1538347492.docdoc 3b91b18b63fda2d06afc7d6f8bb924da52b9cedb373615783fbe7ab73477ba15Virustotal results 35.00%Heodo
2020-01-15ST_BM2MHIM.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43%Heodo
2020-01-15PAY_PO_01152020EX.docdoc 60d2c8f3e62e237ab3c9d9f1e822485b7cb0751b9c389cb2230222adfd189a97Virustotal results 32.79%Heodo
2020-01-15RP_EMNQUPHIBD.docdoc d497afabc9f95e52de2b44e62a03de53764ad772a44b5435500de43e92434a9fVirustotal results 32.20%Heodo
2020-01-15DOC_PO_01152020EX.docdoc 630f11313cf23c2f229912cccd4fc8831cf36e6e13e8531423167d30731f43f1Virustotal results 39.66%Heodo
2020-01-15DOC_PO_01152020EX.docdoc 456bd2a3df56567cee6d96beb863588d35569ec0782ea5b4e9b21d5ac89b6e98Virustotal results 0.00%
2020-01-14INV_93770364.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23%Heodo
2020-01-14BB7963847021FG.docdoc 4da48fa013bc92f6826ca0dbbd16b77aa8c53754efe879ad7d2aaedf2cc7f6e0Virustotal results 19.35%Heodo