URLhaus Database

You are currently viewing the URLhaus database entry for http://jonathanfun.com/wp-admin/ZLicu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422056
URL: http://jonathanfun.com/wp-admin/ZLicu/
URL Status:Offline
Host: jonathanfun.com
Date added:2020-07-30 15:13:03 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):No
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31invoice_2357_70757402.docdoc cf43177e4d135756dfaf8e8d7aede3e7cad58a325bae51173fa0a409a5d5d493Virustotal results 46.77%Heodo
2020-07-31invoice CM479 013554.docdoc 2ffaeb1accf696b047193a4fb4a47238f2a3b582415a75cade2bfe9b69982a2eVirustotal results 47.46% Heodo
2020-07-31invoice-FZ764-1944124.docdoc 329ee2c468d88dcf1fbfeecc4f4cd304e2f5bab2e86ac85a7577f4e02f0f7067Virustotal results 48.28% Heodo
2020-07-31invoice_RB926_42761165.docdoc 1bbf1c280e0399776065e6c00e7ccc32e3dd3657069cf5d5f27ccda9a1e53d69Virustotal results 46.77% Heodo
2020-07-31invoiceOLU683888993.docdoc 8d4a6bbe8331ba2970792f5e37e044765e5a0c7df74b1e26d8e0af16b6390bd9n/a Heodo
2020-07-31invoice AZV1 082152507.docdoc 74ea191fd9dd8739f62ffc1cb8d3ba2aad0b198006c5e8aab604e362798cdd45Virustotal results 45.00% Heodo
2020-07-31Inv PFC177 200085517.docdoc 8f73071e0edbc9813f45554df26b3414e3650b0982700c2ddae27bc950c10d08Virustotal results 45.00%Heodo
2020-07-31Invoice QPLT7968 4767859.docdoc 1e78d834b4871e8021b0bdbff55c32e9a28bbb0f6901965f9c2bfe6c2ee9eae7Virustotal results 45.76% Heodo
2020-07-31Invoice N2 3628767.docdoc ffcca6f9140c3ff0a3f0e0b888148ebf2d55a3ccfa54636106362ea6f9045f0cVirustotal results 44.07% Heodo
2020-07-31INVOICE_UVBJ0{:REGEX:.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31Invoice_D0-114453.docdoc 007e30a2bba6058cf6bd8c583a16ca64c52be4d09886481b9d5df3c0dd9dbc7dVirustotal results 50.00% Heodo
2020-07-31INVOICE KH06_931092036.docdoc e98facde0dc82a3d26e7ceb7588d41b8a6246e4c74bc9fa68679aa9820ce91b4n/a Heodo
2020-07-31Inv-2732_062803.docdoc 2239e9dfea333b691ad7931b2f663ce27192aa0bfe9b4c7112e98eeddc00ae38Virustotal results 51.67% Heodo
2020-07-31INVOICE-RM49_797893054.docdoc 2789d1d3eea1e5dcb760faf9bbf395f267ec901bc7c52a67ae60133050897609Virustotal results 50.00% Heodo
2020-07-30invoice_ZGOQ0 5873474.docdoc 2e24bcec136a5b896e730820974bfa9162575d275b2ee669ece097f7b195e4f7n/aHeodo
2020-07-30Inv-HX4285-4308928.docdoc 1c8026d6bd75a1ea091d6a6676d3a7e3bcba3b17717e21607488b9fdb762fba7Virustotal results 49.18%Heodo
2020-07-30Inv-8 222146028.docdoc c83969e81859c8ba427abffea78663dfe0ea99293074096f42edd85903e45876Virustotal results 48.33% Heodo
2020-07-30InvoiceBONY4{:REGEX:.docdoc 2ccfe3cb5c9044e383e930aa33fb0e74fed092845982048455384c26475e9149n/a Heodo
2020-07-30Invoice_YLP67-55122708.docdoc 37e514cb14ca3f023b15dcb7c93568c37ff32da0ba32eacbf318286053027f32Virustotal results 48.33% Heodo
2020-07-30Invoice-ZYR7528 98295847.docdoc c26948855f4ff48cabef919e4728ee8fee5fed3d1c0a191b3bfcf7607a57e820Virustotal results 48.33% Heodo
2020-07-30INVOICEJRZU620_099004155.docdoc f2a8be2190fc82926a24c1d0bc6cd8f554949ebd1fba55ec585b40896ef68bbdn/a Heodo
2020-07-30INVOICE BHP3213-820905745.docdoc 54544faaa3f4d58e9a3cf296caa7f393e90d1cb77e1a079fb6e55c5399db9ac9Virustotal results 44.07% Heodo
2020-07-30invoice WNH86_2265346.docdoc d9bd2eb0111b6f7391edbb640b8dc6e6412e77d2fa3121149bded48f50d9e75cVirustotal results 44.26% Heodo
2020-07-30Invoice_XHHC6589-322276559.docdoc 57bcd0ce642158f431bcd37dc2223f9c3186275eefa03ad35deff1fcc99de5abn/a Heodo