URLhaus Database

You are currently viewing the URLhaus database entry for http://zhetysu360.kz/wp-content/multifunctional_zone/640221481864_5opPELZeS_CsXTmFa3J_DK4D0WXOWBV/9novu1nhjxqy59_uut2u5351v54yx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299252
URL: http://zhetysu360.kz/wp-content/multifunctional_zone/640221481864_5opPELZeS_CsXTmFa3J_DK4D0WXOWBV/9novu1nhjxqy59_uut2u5351v54yx/
URL Status:Offline
Host: zhetysu360.kz
Date added:2020-01-27 23:07:07 UTC
Last online:2020-08-18 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 23:08:04 UTC to abuse{at}hoster[dot]kz)
Takedown time:6 months, 23 days, 20 hours, 13 minutes Bad (down since 2020-08-18 19:21:56 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29inf_2020_01_30_UCY291.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29ARC-20200130-PAD919197.docdoc 2c7a2ffff7a4a2fcb7a86235dafda3b02ce67330155e00a22408d6c14b2f5cafVirustotal results 40.32% 
2020-01-29List V1229.docdoc de39c0b0ba341eb6a6c1cc3bff5a3dede93907976a77563396df5165f422ac7fVirustotal results 33.33% Heodo
2020-01-29DAT_20200129_AMK03557.docdoc c5bee30abc8770da84f8bbd7f058c8345679dc510a04e67ae7a663820250019dVirustotal results 32.26% Heodo
2020-01-29rep-20200129-HDU140.docdoc d9e6778d130d18c51ae971d9b67674e2efc88e36d86b1d08e74ff54214d601d8Virustotal results 30.51% Heodo
2020-01-29ARC-FH283372.docdoc b09c8d39fe17d600ac2beffd9540076f55d944b41ae3c11b26600252a272b3ecVirustotal results 26.98% Heodo
2020-01-29Doc-054366.docdoc a6f8d6e5f80b47b55146e82c61a78c5ed8c451bcb68d157dee574d02c768ba30Virustotal results 26.56% Heodo
2020-01-29doc_041676.docdoc 5c173b5bd9dd72485c7ad80a63bf004d2e29651ea43e8042b32d663c186416c6Virustotal results 25.81% Heodo
2020-01-29arc_20200129_175.docdoc 0b0243567f8017cba7be007b4d797731af10a9c7e9971cb09881d0a646bf88a2Virustotal results 30.00% Heodo
2020-01-29Inf_20200129_Q36921.docdoc 6765421b973c2bc3603b0f52f3ed514310bb83b678823614f845b6d4b1cbedc9Virustotal results 26.56% Heodo
2020-01-29REP 20200129 759.docdoc a4edb0742bb50f5c20c88508ef0dd1028d985dcf0b9ced6c6c9bdf800e1c6748Virustotal results 25.40% Heodo
2020-01-29Doc.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29INF_20200129_W47789.docdoc ab46f8f9b1905e64a35d9db9e9ff84df5eb21679b53d1291553d1b6a936554a5Virustotal results 23.81% Heodo
2020-01-29inf_75490.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29MES-2020_01_29-449808.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29list-2020_01_29-03085.docdoc b40831be7daa247208f2f37c223101e825eca3eaedbae7a72de040e21852ae00Virustotal results 42.86% Heodo
2020-01-29dat 2020_01_29 Q713035.docdoc d7bcb9c0a8ff27400a3e2a846976dd062129a404c432e34e4fd885f734300144Virustotal results 44.26% 
2020-01-29ARC_L35199.docdoc d0587297f7b5699b364592f59c0d93057b42defb42c714d6381d54a6142953edVirustotal results 44.44% Heodo
2020-01-29doc-2020_01_29-MR3983.docdoc 623303d6b597c92e43276ac21c6338a64cb078760e9a74bd08050666a3aeca13Virustotal results 43.55% Heodo
2020-01-29Dat 20200129 808544.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29DAT_20200129_JQ927874.docdoc e26c4466ac96339cf441036fb05d86cba2f624e2c7481c1ca86209c19122cbc6Virustotal results 40.32%Heodo
2020-01-28dat 0881.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28dat_W1505.docdoc f2a6a0283ff20ad3d0855ce7825d84920a0a27c55825a5a5b9ba91408388a402Virustotal results 41.94% Heodo
2020-01-28doc-20200128.docdoc fb2b108e0a60dd86b0478caee0c19cb0056953fbfdf00e100184e1a53a031948Virustotal results 36.51% Heodo
2020-01-28LIST-TG108373.docdoc fcb69f15a7e0e60e6d3b818f8c82d51c5a011ff2fa5097c6e85fdccc1781049fVirustotal results 35.48% Heodo
2020-01-28mes 20200128 SAD205.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1n/a Heodo
2020-01-28File-2020_01_28-YDW17512.docdoc e973fec4c3e5b5f599c5defe0c00df33eae0e9b00f1f8a1d8f9479d4e343e446Virustotal results 25.00% 
2020-01-28rep 785.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28MES.docdoc 17de704a282307408b556e2328dec5c5715d0cd7136dcdc1d6fe54f841dc2bc4Virustotal results 23.81% Heodo
2020-01-28DAT_20200128_8051145.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28LIST-2020_01_28-1275170.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28list_2020_01_28_ZMS78156.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28Dat_YQ1978.docdoc fccf3876128e78c8d3a6385aa312b1333c822a2b9efafb26daf1d2ffea296d59Virustotal results 25.40% Heodo
2020-01-28MES_2020_01_28_RAF5585.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28list_00551.docdoc c5666d80df3d2361122568d511e336c58a58b27576a1cd78b434c425d8b2e809Virustotal results 22.58% Heodo
2020-01-28MES-20200128-Z970686.docdoc 256954bf735b73749d5fd67afbf6e789abb356f02cec192954e129996801d642Virustotal results 22.22% Heodo
2020-01-28mes-2020_01_28-HCQ0622.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07Virustotal results 22.95% 
2020-01-28Rep_20200128_FY892.docdoc ae1c2a1ebc838f4092123a0fed626a10f1325e7796629f6d370111fd50d8154dVirustotal results 22.22% Heodo
2020-01-28doc_640532.docdoc 0827a2ab4aa1c0caddd493489b6197943bc03b6da0d9f52c54071449dee6538cVirustotal results 40.32% Heodo
2020-01-28Mes-20200128-1245.docdoc 33d3ef3b1fb0f8ed8ed87b487e184b207ff302b60481dac9da9487ca210247e9n/a Heodo
2020-01-28dat-20200128-FAH066.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28ARC_8852300.docdoc e7bdf4be9317b8d839471847ee5f1f19da2ad961abf58470bc22e3f345b93c24Virustotal results 41.94% Heodo
2020-01-28inf_20200128.docdoc 96a0ac595e820c4d5bfc99b40a351899b392f86b66e38142a1b6925a95424fa6n/a Heodo
2020-01-28Doc 2020_01_28 T978.docdoc a021057a2d983bc13e1f6b1516cac0041546aa046e6822c87e09c6c8ba870b1an/a Heodo
2020-01-28DAT_E612369.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-27INF_7967849.docdoc 8a5d48bf4570d69fd4c9398857cb6bde479600de838113e497e4d139720ab207Virustotal results 34.43% Heodo
2020-01-27Rep-2020_01_28-DAW98320.docdoc 23ede3170039d0b1ce55df2d6c33b3dce23469baf278d911859dcafafe0e5048n/a Heodo