URLhaus Database

You are currently viewing the URLhaus database entry for https://preinfra.co.zw/wp-content/so/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414227
URL: https://preinfra.co.zw/wp-content/so/
URL Status:Offline
Host: preinfra.co.zw
Date added:2020-07-17 20:18:20 UTC
Last online:2020-07-18 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-17 20:20:06 UTC to abuse{at}contabo[dot]de)
Takedown time:19 hours, 59 minutes Good (down since 2020-07-18 16:19:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-18INVOICE F9683_2980484.docdoc 169f03cee2b674a04eb777235895e2e6d94f82785fac8764ebb330df2bf2448dVirustotal results 40.32%Heodo
2020-07-18INVOICE-XS38_910995.docdoc ae45c36cd420955b42fbfcd33461d38830fc732624a22faa6e3f0308685127faVirustotal results 39.34% 
2020-07-18Inv_FJSV2_9568162.docdoc 81cd5ce6123449ba648b0d4e9e5b254c223fbec0959ca04f739d278bb49e0761Virustotal results 40.32% 
2020-07-18INVOICE-OL35_8419802.docdoc 80e277e15058cc1c440200dfe3163744b701225ecedf6888dc08e9f77df37601Virustotal results 40.32% Heodo
2020-07-18Invoice-YIF141_36202324.docdoc 1930614813330328ea07ab82811cdce5464d3cbde53b3f4efc556b6d710ea453n/a Heodo
2020-07-18INVOICE_BGKF32_44093703.docdoc a30f8738c5c98b2de7d7eb1186fefa526d08737e091f8ea318c581c6302be595Virustotal results 37.10% 
2020-07-18Inv_JM699_550050180.docdoc afe17af2b3879fe76b895116463f7220940640a33528a0eef0eee6d5e175d2efVirustotal results 38.98% Heodo
2020-07-17INVOICE BMYH320_665479382.docdoc ad8ec7c667bb0c0c8f29d5da291048d0a7ec8f118a640c6e97788abc0ecad0ebVirustotal results 35.48% Heodo
2020-07-17Invoice_060_350196.docdoc b2d96cec3e229314dff1256d64085b45b1187f3ee72f8110cf23608d4f7baa9dVirustotal results 36.07% Heodo
2020-07-17INVOICE IOH9986_986648.docdoc 61a437bbed8e3ac3a4641ce788de7880516f124ad0a3223f107e92fb0cf969eaVirustotal results 36.07% Heodo
2020-07-17INVOICE V61_47855966.docdoc 656404db090356761eafa7b73c9528cc277067a7e77743bf9eaa8d17e7b3b522Virustotal results 36.67% Heodo
2020-07-17Invoice_IPT83_462838.docdoc 83f66d992e12fef5ce5f9bd4d34b909c05733fbc574d98eb9524003fd005d738Virustotal results 32.26% Heodo
2020-07-17Invoice-5128_260942471.docdoc 1e1fb8134d9ede5ca2e5b740ff81ef5e76206eed5933c5c2786ecbfa2dccf624Virustotal results 30.65% 
2020-07-17Inv-152_465902.docdoc f8c49170d4bb1c283994a9144581603bc6b9fe74cdb7f60b32806e6345ed035bVirustotal results 29.03% Heodo
2020-07-17Inv_U2997_0811516.docdoc 1ca54edf6c4dd0c896bea1dcf8000035c111adb890a2d2d395489c1c3b24d6e6Virustotal results 27.42% Heodo
2020-07-17Invoice-024_5675654.docdoc 4bc9be17841664c17490eef267f70c56282b93df28e99ed18d9707915b7afbc9Virustotal results 26.23% Heodo
2020-07-17Inv-GI247_35996949.docdoc 0ed6a205ad85adacc36105c44edce7d87431ff059a8227d3632aefff52781396Virustotal results 25.00% Heodo
2020-07-17invoice-883_67674702.docdoc 0c6fdbb83539fe76c8db143e036c4eca7464535d8b900318b5c0870b3b8024a7Virustotal results 25.81% Heodo
2020-07-17Inv-ZPA8_1007623.docdoc 82c401148abefde60b6f557d36ae313e40d65cb3902f6d0d4e94a14308a7e410n/a Heodo
2020-07-17invoice 6168_81363182.docdoc e37ed35ad92d7f72dd82ba694d4ff1b2811ed68857e2402e20f46bbeebbf8b7aVirustotal results 25.81% 
2020-07-17Inv-ERCU8_741983141.docdoc ea488cfef075f8314cbc01390816578b77f0f03778254e6a802d18e5e764daacn/a Heodo
2020-07-17Invoice-PTMM864_042236.docdoc 2bf7104daa2f9fb6b14ed29ae9754235ecaac0191bcaad03cce793808026ed3cVirustotal results 25.81% Heodo
2020-07-17Invoice-NOJE6795_879659.docdoc f83e196ddacc66388f92a4e8aec132445b3cf724beb962528c9b860e82bae6b6Virustotal results 26.23% Heodo
2020-07-17invoice_JQU141_93496306.docdoc d92cb1bdecd2ac46696a43f0a13682eddfdab906ae7430887a5dfbe33174b9d4n/a 
2020-07-17Inv-2_044498.docdoc d0fd2d71c1267d3ad20bbc348b043e49ea7eda9acbfbc30e64dafb296a1a9011Virustotal results 26.23% 
2020-07-17invoice OR391_5090870.docdoc 8b8ccd4f24be195ddf2b59efcacfe6486785230cc152b5a31a5f5e217050a8aeVirustotal results 26.23% Heodo
2020-07-17Invoice 96_073916572.docdoc 2c7595169fd5112718de088c5732bbd01072fc38297c809cb782f5a5dbfd6a87Virustotal results 25.00% Heodo