URLhaus Database

You are currently viewing the URLhaus database entry for http://www.zingicg.com/fewigq/paclm/z9ksqotf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289412
URL: http://www.zingicg.com/fewigq/paclm/z9ksqotf/
URL Status:Offline
Host: www.zingicg.com
Date added:2020-01-15 21:53:05 UTC
Last online:2020-03-29 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-15 21:54:04 UTC to abuse{at}hkbn[dot]net)
Takedown time:2 months, 13 days, 12 hours, 47 minutes Bad (down since 2020-03-29 10:41:08 UTC)
Tags:doc emotet link epoch2 epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-179GB31MD4XYM.docdoc a70ed72d206dd0f5a883182346366f068e2ae5a9eaaaf6ded8c157e2a70341ebVirustotal results 20.00% Heodo
2020-01-17PAY_PO_01172020EX.docdoc d195639cf92d525da10598b2d321c50679b53e87986f4e8f1f1ff82bde526638Virustotal results 20.34% Heodo
2020-01-17INV_TBD5G1KNM3UMN8IU.docdoc 5f79f8b85eaad48b9fb257feffe5c35f9a597cb602c6538cddc74e06d553ebddVirustotal results 36.07% Heodo
2020-01-16O_52372368.docdoc 45a15f8dcae6ff2b6be17230d49fd07404f234bda44280c5c2dc8da7efe297b9Virustotal results 37.70% Heodo
2020-01-16REP_84342513.docdoc e7ad3e073f6635851ecbeff17a6c6a8a5f05d2cfc0754b69dfbe0a6551dc6303Virustotal results 36.07% Heodo
2020-01-16TXRI_F7SV4TY.docdoc e69aeb3dae76fda77567b855c79ba92a565bcd02d68bed5da8fbc0e111ad70b6Virustotal results 29.03% Heodo
2020-01-16RP_0033056402276.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42% Heodo
2020-01-16REP_70499717.docdoc 770759abe2fb63619a77b6150aa284b8bc6a7149332b163f90a63fd3d7623782Virustotal results 21.67% Heodo
2020-01-15INV_69916558430438175872.docdoc fd94bb6118e4100b46c73b76b2806bb05deb7ff1c269113d78beea83e0ad9c7aVirustotal results 34.43% Heodo
2020-01-15DOC_10072530.docdoc 12ab5cc68abfb6224f3a261e8f75acfceb88288023db49fa25ccda6e6620bc76Virustotal results 34.43% Heodo