URLhaus Database

You are currently viewing the URLhaus database entry for http://www.zingicg.com/fewigq/iZsxF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295530
URL: http://www.zingicg.com/fewigq/iZsxF/
URL Status:Offline
Host: www.zingicg.com
Date added:2020-01-23 06:43:05 UTC
Last online:2020-03-29 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-23 06:44:04 UTC to abuse{at}hkbn[dot]net)
Takedown time:2 months, 6 days, 3 hours, 56 minutes Bad (down since 2020-03-29 10:40:58 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-25Inv 441_585726.docdoc 75014b9efcb14fb22591a986fdf636d6106b987d956ebbf793aa91c24dd67dc8Virustotal results 34.38%Heodo
2020-01-24INVOICE_GLRV7_838800.docdoc 9241b100141d7c3e09900b10983b71cdcac9b8e3dc438e04def914f93c2b5969Virustotal results 29.69% 
2020-01-24INVOICE 4380_034727.docdoc 92aee4fe44a0bfd796f4b3f432783adc1655c5003b208df89215f6544686df51Virustotal results 26.98% Heodo
2020-01-24INVOICE Z4_046854.docdoc 7dd53825b5d2ade36c33feb1492c3e52cd0a331948cbdb102e2098dbe2811560Virustotal results 25.81% Heodo
2020-01-24INVOICE_JLI9679_761676.docdoc e679ec52ce4edcc3ced6a95332462b84710b7a0f66626730ac15a25fe5ecf389Virustotal results 25.40% Heodo
2020-01-23INVOICE TIK6163_2468783.docdoc af8976ac691aa40327d9844ef283ec4de84fd38c56d57218befd747516e4e92eVirustotal results 36.51% 
2020-01-23invoice-KC1170_13772629.docdoc 7277e36560a048fc265784737613943bf13a30a15dbd425da9b8ceaab4d621efVirustotal results 33.87% 
2020-01-23invoice_AIVG0_161602463.docdoc 4d5db1070b65d514646e2ad56bc899612ce3cb4825537c0a802ce3bab2bcbd64Virustotal results 28.57% Heodo
2020-01-23Inv-Y3020_0069110.docdoc f7fd1bc385e801ea09e47dffb635b82ff487f4b83f694447946569117c848462Virustotal results 26.56% Heodo
2020-01-23INVOICE_N7007_520752700.docdoc 2b93a159bdfcbbaf171914a8c715d2211bf42fe88e7cd06c6d0be7ee9ae45ee6Virustotal results 22.22% Heodo
2020-01-23Inv_EOC5_078841.docdoc 1c244d818f2d1e8b44a21b46b36aa29b2a6de9b37ce8463210ced5c7219801faVirustotal results 34.92% Heodo