URLhaus Database

You are currently viewing the URLhaus database entry for http://smartstationtech.com/zohoverify/BI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299565
URL: http://smartstationtech.com/zohoverify/BI/
URL Status:Offline
Host: smartstationtech.com
Date added:2020-01-28 06:30:08 UTC
Last online:2020-01-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 06:32:07 UTC to support{at}servermania[dot]com)
Takedown time:2 days, 9 hours, 2 minutes Poor (down since 2020-01-30 15:35:04 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29Inv-UBJ9_136892.docdoc e8f8cbc324e2601a0d32232c887aa398adfc45984b6a254666b95a1c00ef496aVirustotal results 31.15% Heodo
2020-01-29Invoice_XVM3798_30110320.docdoc 7cbcad4d6e9ad8438e5febd3830bff9aef4729b98d23935ad7f9e6d290272732Virustotal results 32.79% Heodo
2020-01-29Invoice-CCA76_3080837.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice-TWI458_99267725.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-28invoice 06_95415591.docdoc 1c709b435880a2eb4158ec24ed2fb3751d3b5281781cd81173bfcebc53a2bc62Virustotal results 20.63% Heodo
2020-01-28Inv F3_165315453.docdoc fad431f81e098efc657ea4c9787427f6080e70ef1ea7631dbf51f35578e79438Virustotal results 26.98% Heodo
2020-01-28INVOICE-R1_732371.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28INVOICE 43_119036.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28Invoice 152_508987565.docdoc e10df6ee554126d0dd5b5697d3c7a143ca1bb9409a47bfcd5b02b8afc96425dfVirustotal results 23.81% Heodo