URLhaus Database

You are currently viewing the URLhaus database entry for http://z-bai.com/wp-admin/z772u-sl-26148/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:428435
URL: http://z-bai.com/wp-admin/z772u-sl-26148/
URL Status:Offline
Host: z-bai.com
Date added:2020-08-10 15:33:14 UTC
Last online:2020-08-23 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-10 15:34:05 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:12 days, 11 hours, 25 minutes Bad (down since 2020-08-23 02:59:22 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-12INVOICE74367877576.docdoc 6c818eb9af4ba3479156ffdddedf9e68f03dcc98579d8a7df9cdac88c483335dVirustotal results 25.00%Heodo
2020-08-12Invoice-K7-3033140.docdoc 24d695ee5d47e6fc47afc097c1c09639443097d9fddb06851d8cc02e19aa6509Virustotal results 51.67%Heodo
2020-08-12InvoiceMKO966288832520.docdoc 0bbbea7a2b309d9aba95c407c00367d4fe0aa1e0fdc2a0c7098c4f99e49040e9Virustotal results 51.72%Heodo
2020-08-12invoice-CMGS661-0119834.docdoc 2f20ed3e86d25bee2fc86cfef8577a1392ff6573b368c48c7611b7215f15323eVirustotal results 53.33%Heodo
2020-08-12Invoice_DZM6855_768224831.docdoc 49f84ff8599ef44db2d0ee39c6a82739d5a9d663c0b011960b67747dead85d57Virustotal results 51.67%Heodo
2020-08-12INVOICE86040008.docdoc 2af6225a3063a9ae0fc86eeeee41ed900c7b3451d72514b215516935500e5109Virustotal results 54.24%Heodo
2020-08-12invoice_3887_03176958.docdoc 200e0814e4ba5a7af1e2c9a1c629e96b601779babd96e566f65a912f03467620Virustotal results 50.82%Heodo
2020-08-12Invoice-YTPL67-9028471.docdoc a3c27802860cdc8195b53a7a9a0308f67c631bec4c450329dc8421a206c65d08Virustotal results 54.24%Heodo
2020-08-12invoiceWXB23388481.docdoc 5130c2b92fca78b92aa03684b7110c4e341f9d8ca4e3a20bead042e888e45873Virustotal results 51.67%Heodo
2020-08-12INVOICE-C84-17245660.docdoc c57f8830d597b05f0dbf9031092be52ed1ce11f9f75f530bfd698f46f624901aVirustotal results 52.54%Heodo
2020-08-12invoice-C41-403513461.docdoc 8e282ef570d12f5e1cce05e717449fa995042a179640c3d603856110e779be54Virustotal results 50.00%Heodo
2020-08-12invoice-9910-054016.docdoc 6e9b1ad824b0bc35792a2ec92fabb0456af70c654e99e5f6d0067903f3c771ceVirustotal results 52.54%Heodo
2020-08-12Inv_JBN3778_66706363.docdoc 9d49d327fa9d96671e507479a7958bd3d51fd6b28b575f43117cd3796950934cn/a Heodo
2020-08-11INVOICE_UC46_82768364.docdoc ba44f106713979944843774380c0f9975db8ac9c9e7bea15df6b1523729f8e8fVirustotal results 50.00%Heodo
2020-08-11Inv UWC4964 821894813.docdoc 98891f34f0962ebc73b8be9c5a37aa21ad42fea2d08629bcbf84ff00595fe02cVirustotal results 50.00%Heodo
2020-08-11invoice NP655 7925826.docdoc 994db52aefaf0bc495521d0b5b29b59aa7e5c5aa4d6bc221e2808f21247cf19aVirustotal results 51.67%Heodo
2020-08-11Invoice-GX688-616087.docdoc 4e7dada550866484045928cef6fdd4d7ccb5d19d79febe490ed7da33d3491b01Virustotal results 50.85%Heodo
2020-08-11Inv 943 6557834.docdoc ba9a8497f8d62ce6e51e23f89f045998e57f187f7b8b9ff3168e5289d1758e80Virustotal results 50.00%Heodo
2020-08-11InvoiceKP20377386086.docdoc 58fd95e7b27451366d5ea9b0aefeeaa2230636fe086c16bdf49d07824bc70a0eVirustotal results 49.15%Heodo
2020-08-11INVOICE-0-8204413.docdoc 543cf094f7405fdf789ebab79f0ecc906db7db7863bb7a144003fbf42f692dacVirustotal results 49.15%Heodo
2020-08-11INVOICE-BP4-47456726.docdoc a333fa244b433049bb35cd2d2b8a2ee2c904a26033a1f55f967159b4db8e49baVirustotal results 47.54%Heodo
2020-08-11INVOICE-OCRU2-984436534.docdoc 50ec0f5012c83993533de48a638157f8879561483c54242f0c74cc2c57ce3917Virustotal results 46.67%Heodo
2020-08-11INVOICE-JWN2-65089320.docdoc cb5234b6061bbdf400ee2833eaeba7a4f39a5d883194f1c0bf3c317267799d27Virustotal results 45.00%Heodo
2020-08-11Inv-06-958845.docdoc 8842c702204c3c0519e59f4248067259ebba33688fac6942d0dd34026c1df46eVirustotal results 37.70%Heodo
2020-08-11InvPJ59363338875.docdoc 037ac6663cc663afedeb54cc2424400903cff00417fd70e5ad9b648a50eeae83Virustotal results 37.70%Heodo
2020-08-11invoice_KO869_36244540.docdoc 7e26116f69cbd33eb090b2c6aabc23a78e55948b52ff9059abdccbd3f4f5f66bVirustotal results 38.33%Heodo
2020-08-11INVOICE-R1-598158587.docdoc d88d96cc358261f1924dc023ccaef2acc858bd460564cf04b70d80a5569b7c78Virustotal results 39.66%Heodo
2020-08-11Inv-ZDMY4200-3310824.docdoc 416b04dbb5f2fb151e68ccc4196ac95f258814cd84eb822b016bc3dfb9ab8836Virustotal results 36.07%Heodo
2020-08-11INVOICEZQQ980560979124.docdoc 361883f66d3ba57b06154969450d80a60534d4c926201f523875ecf69bb474f4n/aHeodo
2020-08-11Invoice 5759 028369.docdoc 914abd85dec0d71dc282fe97279075ef7229f967f7723b24b40694d34702b721n/a Heodo
2020-08-11Inv_OR4677_979478.docdoc 519dfcfc8df38f6cbe0e60280784fe52817df6a4d22343ae006687f6f5595296Virustotal results 29.51%Heodo
2020-08-11Inv387695795.docdoc b4bee32dfd12960ffd21f88d8d912458f95bbb2c083603319d4a083b9d341f4dVirustotal results 30.00%Heodo
2020-08-11invoice-QL299-003090816.docdoc 05fac21a4430186852c51837d7f5787747aa9fb1afa75cd3f00b2505dc79351cVirustotal results 28.33%Heodo
2020-08-11invoiceTEF616812894.docdoc 08c803b50f7f39e19f42600f5eb40b891849cce060fc514a261a4512d8084725Virustotal results 26.67%Heodo
2020-08-11INVOICE_UOH39_3657109.docdoc e9f69f15fd98a0a59f7dbdafe214d65c61ad968c7a7bc3bf77c9f357af0c5f0bVirustotal results 26.67%Heodo
2020-08-11invoice_NET8698_99238993.docdoc 744f82770d4c090be9a6bd6e9d2ab09a760ae5cdc58ba11385871d2660555586Virustotal results 27.12%Heodo
2020-08-11Invoice NC69 6192610.docdoc adc570c9c03f23f75052f2e89b9654a9b24be3c30e954696e875ea34157fab88Virustotal results 25.00%Heodo
2020-08-11Invoice-34-364375455.docdoc 156de71ee7302f206931d449e2a043089fe19f6b595c0413cb2619bba9484358n/aHeodo
2020-08-11Invoice-275-785443.docdoc 43048cdd340fff0306fb245a60aadab8b1f8ecbad52db75e5a31771d36796e75Virustotal results 25.00%Heodo
2020-08-11invoice_CEE798_03731459.docdoc 6bc1e3ac932ab1cbc6359f9bf1af246523f8fa7050160994440732dd1a41281dVirustotal results 25.42%Heodo
2020-08-11Invoice-SB0145-785596876.docdoc 4e7876b5c5c8158924c347d181e19fb3d15f7642e7a645e7587d9e106888e6faVirustotal results 25.00%Heodo
2020-08-11INVOICEDIPP55915595722.docdoc 50a973f6d0e0284ed5cbce911ba01e39ab74db72d56ac520595f474a0eef9af8Virustotal results 25.00%Heodo
2020-08-11INVOICE CG9046 0527131.docdoc 9f5254aadc7a867d60371d269a9dc5700029302284d6d0e9b152fa0d5b27c67eVirustotal results 25.42%Heodo
2020-08-11INVOICE_JPHH051_10444786.docdoc 920f950bc61e9c48ea08d7d68d5b1d5f8a96a323a027f67380f61b63004a2048Virustotal results 43.10%Heodo
2020-08-11InvoiceKNLQ0836036871.docdoc 3d67e2d51250c36cc9e982d2c244daddef2075c3776d37bb1d56e09186b2ebb7Virustotal results 43.55% Heodo
2020-08-11invoice_IEUI69_12392784.docdoc c64d68094224e580747c4707691e50c77046c7cc9e226b2ad20ff1d38ff3299eVirustotal results 45.00% Heodo
2020-08-11INVOICE ZP8 71843680.docdoc 47eeaa6e638b28556d75d986cc2a8f88bae892b3a0341a4a8799a8ff94eff6f7Virustotal results 45.00% Heodo
2020-08-11INVOICEZ26924639.docdoc d9d5afd0f83aa28a06f4a1b5dc642926301d0b9bb7cd9dc22dc75ef49fafa296Virustotal results 45.00% Heodo
2020-08-11invoiceJQ3080558827.docdoc 4809328436efcae1791fa4770d4f7158cc69e9dcf26dcce66189e3ce63af2a44Virustotal results 43.33% Heodo
2020-08-11invoice-AVAH653-467679.docdoc d49792fa43cfaa2d13e6bab3b87374314a2cb9ab1ef794d1caa38a9b588294f6n/a Heodo
2020-08-11INVOICEJ61648529.docdoc df9751edb6d3f6da4e475cc3b05844cb0833623d6e9f3d268a38611dd8bd15a3Virustotal results 42.11% Heodo
2020-08-11InvSYG33867593215.docdoc c1fc85d3b078b060a5335fd6ccf06322f2e7f97c39ff74defd85719891c024d2n/a Heodo
2020-08-10INVOICE-607-70469495.docdoc 2ed80e234eddcbf09463cc2ef0009ebe173d3a21995aa99dbdbc3764bf9171f4Virustotal results 40.98% Heodo
2020-08-10InvoiceYJU2460854148.docdoc 96379d3c95f98bfe9120778d7b62fa83e9ee5f7f151ae6ba8c6b169dd1a94d14n/a Heodo
2020-08-10Inv_0_81279348.docdoc fd4a3abaeef0f14c5df818296353fc22cca15439026cf73373152b3554d243f2n/a Heodo
2020-08-10INVOICE-YDO4-241466604.docdoc 9dee7b99229da39cdbc49e96e13a04cc9830de7c5049cf4b3da0ce59ce9caa35Virustotal results 40.68% Heodo
2020-08-10Inv-STN1-7797653.docdoc 2eebde5c616671da6343d79250d741278cdfc7b19af5ee5a43fdbb115b906077Virustotal results 40.68% Heodo
2020-08-10INVOICEABA5681729380.docdoc 705e718dccff08f8277bc1b0272bb945ed6346a0bfc50f80558691982c8e9c39Virustotal results 40.00% Heodo
2020-08-10invoice JCT7 3648066.docdoc 64bb69df285bfc15e253fc705f5505032d78b1a10ee212b5194a376b2fe1eb2bVirustotal results 40.00% Heodo
2020-08-10invoice79396971.docdoc 14045c2a1f8106f62cca9878b82b62d33cbe757e36d4f41266e905a0d3db4121Virustotal results 41.67% Heodo
2020-08-10invoice48917970953.docdoc 774530c33388236c1d8ab53566cbeeca0155a6e56f23a1195721e3f400869d9fn/a Heodo
2020-08-10invoiceLRJ072991990.docdoc fed41332f44d68eaf298af68e820e28755d75934d375f489944912de15ffcc5fVirustotal results 42.37% Heodo
2020-08-10INVOICEPX614691189.docdoc d72a3b83f3949949696ba8598cf1e000eefbe4ee9a0aefcdd16ed6d93c7d33edVirustotal results 40.98% Heodo
2020-08-10Inv-NDZD23-2981364.docdoc 89ead6f9c85112aeb271281971e9eea8e97e24c0c986bddda7eb5ed00ccab09fVirustotal results 40.00% Heodo
2020-08-10Invoice-EWGY25-7470031.docdoc ca1d19eef36f5b2041a86e5970bb48cd29a172b7b07865692c22ce3ba7eea015Virustotal results 40.00% Heodo
2020-08-10invoice KDA8567 71586553.docdoc 97a12872e1a90576545f3e2f3e0a49751b3f666b1cb16148177733fb58f87bd7Virustotal results 40.32% Heodo
2020-08-10INVOICE-015-242105878.docdoc 4d9722695a297b0deafce38a38f1c8f9866d52cc0451601e9e11dfd5373a3518Virustotal results 41.94% Heodo
2020-08-10Invoice-M4-12182801.docdoc 837235f4d4509f8d6551f724d18d3a6c133038c7194abb3c65c7364ec33a4a31Virustotal results 40.98% Heodo
2020-08-10invoice-BQQG1-24932069.docdoc 0a154b50dc2bae7f87f150bc548317b27924a3be1d7075d7ff0bf3e8fc919c8eVirustotal results 40.00% Heodo
2020-08-10INVOICE-99-39030458.docdoc c551d180dc10561b46eae6a365f4628634e78ccd49ef892b002ef69f1f46b20bVirustotal results 39.34% Heodo
2020-08-10INVOICE AYEK2468 4975372.docdoc 6d5a5990ab99c306a055ef95be68d613fb75b5c4adc108843e7caa1562d96348Virustotal results 40.98% Heodo
2020-08-10INVOICE-DG2-9237600.docdoc 848f65be05bc10cc19b1a693ab2c26ac3d7307ac7bde6b7b0ccfd35167159bb5Virustotal results 40.00% Heodo