URLhaus Database

You are currently viewing the URLhaus database entry for https://zvarga.com/wp-admin/invoice/nhej7y640315997363a4l2mn78lsnamt2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431325
URL: https://zvarga.com/wp-admin/invoice/nhej7y640315997363a4l2mn78lsnamt2/
URL Status:Offline
Host: zvarga.com
Date added:2020-08-12 22:48:03 UTC
Last online:2020-08-17 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 22:50:09 UTC to abuse{at}ezit[dot]hu)
Takedown time:4 days, 18 hours, 25 minutes Bad (down since 2020-08-17 17:15:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-15MOR_33949839.docdoc 12fc9dae5d96ce0bddec914a8411b89358007d636b29089cc88bb4c36458d979Virustotal results 38.60%Heodo
2020-08-14BAL_534PKU6UXP9B5LN7.docdoc 1eab4b8358b5e4a4a4ab72ef778a37d4497534cb8fcd1f9b463c8ba0756a5342Virustotal results 37.93%Heodo
2020-08-14F_PO_08152020EX.docdoc cce611e1db8f4136123416dd47be47a254a05e9809b03035e8f4658a1a14d681Virustotal results 39.66%Heodo
2020-08-14DOC_MH7045043783DM.docdoc f868e00a4f8d182360784894248a210bb56e707c5a830c89485b157ff1a72402Virustotal results 38.60%Heodo
2020-08-14FILE_6BC98SCLKUI9A.docdoc b7a5233a4bac135e1d7b9c85e89cf9140cee08cfedd72993f82513c8ae8d7c3eVirustotal results 38.60%Heodo
2020-08-14W_SN7079250897EX.docdoc 2cc92eb221a22aae29a8ab8e91b0e71af5e3f60a1256a36dfb0f83273ca36babVirustotal results 40.68%Heodo
2020-08-14DOC_56014434353966644240.docdoc 739eab0c4f294e4ba8fff9f685d6ab8303b5e4ab1caf9482d846afec5aeab316Virustotal results 38.98%Heodo
2020-08-14INV_LQE_080120_VKG_081420.docdoc 4a4029474014846a17463695f4af7917f8fc4fd250f36e96bcc1964d4bce93d0Virustotal results 38.98%Heodo
2020-08-14HMILFK4M48DKHOU0.docdoc 13b77d42335eebbe42a2865518e7321b9b5ee20642398435eb99520169b95a6fVirustotal results 40.00%Heodo
2020-08-14U_64881084.docdoc 9f1eb23ca90933aace0c718c815307e1c8e1b391f2c1dd106a9dd69067c53477Virustotal results 40.35%Heodo
2020-08-14INV_SU2301429437IG.docdoc 87257c3d34ffa05f4d177c92995d8a973b2ebcdcf8ff92e46c85fc42dbef7724Virustotal results 38.98%Heodo
2020-08-14DOC_2210963001267.docdoc 3a6a5e8fabf3eba8321844d7c90ffa39fa7a8aa698d2ad2d99f108799e516840Virustotal results 41.67%Heodo
2020-08-14INV_6VJ5YNU38M5J.docdoc bd8ae2a2434e7741a6684687008dd2c59815c3dc6a31a3639493405e82a5cc8eVirustotal results 37.29%Heodo
2020-08-14S_YRU706U.docdoc 918cfbb38d3eec98be09e4787907e69229f9084bd77ee94c4a3b514a1035cbf8Virustotal results 32.20%Heodo
2020-08-14BAL_PO_08142020EX.docdoc 822dbd9ee80d66a3dd1c882add767f4b644e9083899aa8e81dc5cca461b2e26cVirustotal results 31.67%Heodo
2020-08-14INV_427183461139126818.docdoc 69c0f172c5f915aae73813afb13b0dea6ea5b676961d73b0b57614b1c0f24332Virustotal results 31.67%Heodo
2020-08-14G_GQ9112716169ZC.docdoc afbf98d583ab4b3930cfc62d7c78ee655ddf72359c70df788a150bbdb15fe405Virustotal results 30.00%Heodo
2020-08-14L_PO_08142020EX.docdoc 2958931d81ad10eb95bb3fca9457a800e9b4a9459d2727f30cb5d49d7bed0527Virustotal results 24.59%Heodo
2020-08-14INV_PO_08142020EX.docdoc 8f9649dab8ca8b9830c3cf160314bc7bf4c8e9e64454056eba927e3d8867ba77Virustotal results 25.00%Heodo
2020-08-14I_JL2059903869RA.docdoc bdbae02329ebe760f9cd3c11622499753afc8819a3dc69a61bf0af89493c7173Virustotal results 24.59%Heodo
2020-08-14REP_TP1422673954HG.docdoc 60c6203d9b7a2178fb3f76f12d896c8191aaef13c55973e5a177df215181683dVirustotal results 23.33%Heodo
2020-08-14ND8145501611KD.docdoc ef7ca96ffe6ec90acb92e8c9643a98c30154a996cbaf90a2d7f3a4a2dd6e1108Virustotal results 23.33%Heodo
2020-08-14I_ST6896321711JO.docdoc 2ba31bcf0605c3fb50f7855062c192023371778e906ddbc8f2f9c8812d07a2a0Virustotal results 23.33%Heodo
2020-08-14BAL_SYM5JHPF0KI3P.docdoc faa4c872e4e08e1146cc849b5a9f4302d22a6a7b88f28c20d267b44d7d6b0c5cVirustotal results 23.33%Heodo
2020-08-14LS_RPE_080120_OML_081420.docdoc 52dfa2ae84a796728c42db4f98cf77d399ec18ebd3e7a3876add7ca5443107b0Virustotal results 23.33%Heodo
2020-08-14OCR_46515773.docdoc 1b566e47879307c36ab6864f6877fbdf8128ab937cd837fe3050b24c7958c673Virustotal results 22.95%Heodo
2020-08-14V_XUD_080120_YUW_081420.docdoc 5acdc51f8a9177986bc3daaff77ed37a67acfa55f6b76fc8f3170b02ecb68306Virustotal results 23.73%Heodo
2020-08-14BAL_PO_08142020EX.docdoc 3813928dd0bac12320f38a077ff89695a08c2b334b3d57fd37130ae2040b3842Virustotal results 22.95%Heodo
2020-08-14BAL_PC7113265919AK.docdoc c6b7c7bfc887108475b13843c34397ce838e4338a8ced72d8b58d478631d3ff3Virustotal results 23.73%Heodo
2020-08-14V_VF6786116857HR.docdoc 015676bf9d7c61adca32bbb32d96fa37a913a64442c577859be0e39884752bb3n/aHeodo
2020-08-14LI4649216299PM.docdoc 184f481ac2e0638a5f29787df5ef317f15c5b1509de96eaef3f949c86c2f8b78Virustotal results 23.73%Heodo
2020-08-14INV_01645922.docdoc f92c670905c9b92334b90a5f812306d265e6e9e54c7b4ad16847d5c6234cb670Virustotal results 36.67%Heodo
2020-08-14INV_PO_08142020EX.docdoc e3492d2065690769a6a42df6b2d8f81e652704ea415f5438639668d023f8fd2cVirustotal results 37.29% Heodo
2020-08-14REP_WUYK2FTI.docdoc 022d18a79ba451e68a02a8c682623c79c30125f85a0735fe5453ba1232ffbc25Virustotal results 35.00%Heodo
2020-08-14UK8209252045WM.docdoc 9d8cb204b05c50b29d5686326f0332cfa34a339234c12d448aa14d010d0a41d6Virustotal results 37.29%Heodo
2020-08-14BAL_0GB4FVF0KH8VY47D.docdoc 3435e343b0a6c8e9196499ac3dd741f97bc11a10039d254d98a744d6fcbe3d2eVirustotal results 35.59%Heodo
2020-08-14677529430988031560726.docdoc 0928f7c9c557d9e232052edc5377f9986651f02861f1f90ae67a9bcdf3caa375Virustotal results 36.67%Heodo
2020-08-14INV_XX1516130225MD.docdoc 94c8419a57e163d01d78932f2246ad3427a18aae25869403b06980ba98cd1fcdVirustotal results 36.21%Heodo
2020-08-1486220181.docdoc 7f0cfcaba7df4371efff36fa780cd28015c7c1694c8792fa2f56dd86b7ce8989Virustotal results 35.00%Heodo
2020-08-1475422120.docdoc 6ab2c399c8174e97809e728dc331f229df5e7d30dba04a5b1658ff245c45a657Virustotal results 35.59%Heodo
2020-08-141293458078076150694424.docdoc 13425d91c0471208df6a06b23e5f176fea8637422e82c95f1ecd534aadda855bVirustotal results 36.07%Heodo
2020-08-14REP_IKU_080120_EXX_081420.docdoc a15a56ccd22c0949e8a50eeab2620d8613e5e5b23964c90ae1c08e2908063682n/aHeodo
2020-08-14YXS_080120_VRL_081420.docdoc d4fade764b1ae03f546843ff7b67176a1d7fca0c1cad66455d0770c364b5746eVirustotal results 36.67%Heodo
2020-08-13INV_97546726.docdoc ae61420aebc07da884917752dcdac62809ccd7a3eb2ed470a3b6c810e7635adfn/aHeodo
2020-08-13BAL_77356428.docdoc 668487ec145e75676c1a4fd6e0828331c412f7fe35709a3deb6d182debad6422Virustotal results 37.70%Heodo
2020-08-13BAL_OVS5YBBG.docdoc 0eebb848380c00975634d13afcb080cb6fc678874057e01d2024589bc443d5a4Virustotal results 37.70%Heodo
2020-08-13FPS_080120_IZF_081420.docdoc 5ded872455abe72f89fe59836761a2e78293c02d5af9a016a031be0af60e9c40Virustotal results 38.33%Heodo
2020-08-13INV_PF5696510390FV.docdoc 8829bbce815af3eb259bf395ab4bc8e41ed24c260d590c7a8253172b4e6ded79n/aHeodo
2020-08-1387258482.docdoc 949cdc7a7651181e62fd5756c8796aa5eca9253498fca6acbdea3b07d4805e89n/a Heodo
2020-08-13REP_XTJ_080120_JTC_081320.docdoc 0f56c76a4c47767ff9ff3f8a9fdc37edabf5d585992ab218eec6d39627dee63dn/aHeodo
2020-08-13Q_NZ6824666211NY.docdoc 181c8cee3b6463be02aa4dcfbcdecf6a495a03e0692a379e34467dd0ed5a6fdbn/aHeodo
2020-08-13FRQ_PO_08132020EX.docdoc b4a759ab982ab288dd6ab871610df205148b10cf4305cd15be190ceb1370e330Virustotal results 38.33%Heodo
2020-08-13REP_UAV_080120_FPR_081320.docdoc 964a86f95a2aa1d12b7e964f92102e67e609982dcd610666ee9de3ebe19dd239n/aHeodo
2020-08-13NZB_080120_JNR_081320.docdoc 6411bdfec957841d02b2697f3933820d3c41f39d1622b2f74d1fbd5b0f66b0e2n/aHeodo
2020-08-13DOC_VE0301928971VY.docdoc b8c7112d2672445960d4ca69da612b07b761b5119015c0dc4e75064b85978ff0Virustotal results 36.67%Heodo
2020-08-13REP_01515883.docdoc a4d0b1c2b75f14515784a678a437ffdd8b5542fe3c2d738cbe7bcde2d5b15e0dVirustotal results 35.00%Heodo
2020-08-13DOC_DA6448871052ER.docdoc b8748876a802240520ada4d1493ffef171a7e7a99ad42481dbeffec99b436c50Virustotal results 36.67%Heodo
2020-08-13SWFC_94301735.docdoc f2cfa3001f9b3f64a8c75cb726c5a894693ed9297adb5c97b35b825225bd4001Virustotal results 35.00%Heodo
2020-08-13INV_PO_08132020EX.docdoc 787b6d7c7eccdccf7041ef2028eebf0f8eb9691e1fc1561c6a6c13985156b1a7Virustotal results 32.79%Heodo
2020-08-1375831539.docdoc d567a4097feddecd5e5cabcdde2f997521126535222bec36e0514da36a9886b7Virustotal results 32.79%Heodo
2020-08-13FILE_YJT_080120_IVY_081320.docdoc 8c8c709e2b7cfd3dce74062f2564bef84cafcc329cbfcafbc2c056c35cc38c50n/aHeodo
2020-08-13ML7088285202SU.docdoc 5dfe99bdd766418f029d534146438a97818581f989d4b2ebf5f92179344000c0Virustotal results 30.00%Heodo
2020-08-13INV_58GZILZ4TQN.docdoc 3d9b7dd248282da644efce8e11e6933424e766ba770a6c0eb2f817b312367a1en/aHeodo
2020-08-130788691492174.docdoc 8a0a74b31fb30ce1a4adbaa3945c4186c7d467268e76b9ca802905b7cf5fa54eVirustotal results 29.51%Heodo
2020-08-13V_64105303.docdoc 3dd6562787c08407c9fbd639fc7e1b5a90251fbf8bc40b032135cf84a2243970Virustotal results 29.51%Heodo
2020-08-13REP_9173780295751481916660721.docdoc b51738d4d37c472d3b1b69c1f7cab2d120fd9f2e53a524e772a263e65a892c94Virustotal results 28.81%Heodo
2020-08-13INV_SQM_080120_PZG_081320.docdoc 22c4bc8c9ad10df54d22ae6a89c1b937d49982a7b9f6ed54798394dc9033c0cbVirustotal results 28.33%Heodo
2020-08-13YF_880346655679580.docdoc 44a4e9297c1d0191631e49532aa755b5a7928836c63b7a9f37deb77293cf2ec7Virustotal results 30.00%Heodo
2020-08-13BAL_DTF_080120_EML_081320.docdoc 09bd7f442749dac84e11577aa507719969f7eac112f256a50e5b9e8d823a3b78Virustotal results 26.67%Heodo
2020-08-13REP_PO_08132020EX.docdoc 79b609ddf074406de181d656544923255389ac44a068ddaeb858e6546d2787f4n/aHeodo
2020-08-13DOC_GXP_080120_TFP_081320.docdoc bedf54726f739f906db66965be55e05516b933ce872264751f3dd48f5b9db8fcVirustotal results 26.67%Heodo
2020-08-13DOC_PO_08132020EX.docdoc e9a1e08c1d8de096fd30cfc93c23d0037c4016bc7c4cad64c8c4c7b6fb3a717bVirustotal results 26.67%Heodo
2020-08-13PO_08132020EX.docdoc 0c4015de45653ee2f8fc6e338461a2377e14139b1ff879df5a2fe1d3c200a15eVirustotal results 28.33%Heodo
2020-08-13REP_36351079.docdoc 33dcad34dd7bf732f89c6d54880f01b2f952fd6f08f89062109af185e73d0e22Virustotal results 27.12%Heodo
2020-08-13INV_EX0099276886OP.docdoc 57077fbea2ccbc5464be5b94b7e01a59f4b28e6658a7a432645380f6413e8a00Virustotal results 27.12%Heodo
2020-08-13DOC_TY4619030998EW.docdoc 5194be1983e90239f9db2e155ceda0e8c3614455a64815f33ef7c8a1bac92cc5Virustotal results 25.00%Heodo
2020-08-13L_IV10EDAHQS.docdoc 3f9f641892bac263ede86f11632b4a6498dcc2b94b13727c5dc8c8c594e0f608Virustotal results 27.59%Heodo
2020-08-13Q_RK1219390556KF.docdoc 10fca9ba1908f85269debcb8f4416d4f67fd824d07b6f536e1e236b2f9444181n/aHeodo
2020-08-135DIKGG1EFS5.docdoc c5a0eac9aaeb84217b16d894a11fc533d9125f2c70cecb67dfd600b798295e1cn/aHeodo
2020-08-13175955411037.docdoc 9806f54f8d2769646e6a9caee3f1c15a1b47f781be6eef64c390d6e9ee867bd4n/aHeodo
2020-08-13BAL_6197142499591243.docdoc a8bba76a96bc1cc1852b0b70a3e75776d9dda9cdd9a5978c25f38dd031cd1d4bVirustotal results 27.87%Heodo
2020-08-13PO_08132020EX.docdoc ba510b5a0f97430a09efbd12acbb4c1be869e71e678adf5fa0b5498fb477068eVirustotal results 28.33%Heodo
2020-08-13DOC_PO_08132020EX.docdoc f3288815441008b2291c6b17d597d58fe606f7475c4641bacba49ad56c1b1142Virustotal results 51.72%Heodo
2020-08-13J_456047667580819702415188.docdoc d3cbf8eb26742271a0281233827b52ab52334bef5335d0f8a27c9db613de55c7Virustotal results 53.33%Heodo
2020-08-13XRI_080120_CWU_081320.docdoc 0938a3eb8d86fa634cbaa1f643bd2c6cafcdacba202e4683cf7245705bd11fb3Virustotal results 53.33%Heodo
2020-08-13BAL_D09S1R8LO54HMNF.docdoc c2bb5e128810c06abd15ad3ef0bc95622c20da154ca500892972305c94feabedVirustotal results 52.54%Heodo
2020-08-13BAL_D09S1R8LO54HMNF.docdoc c2bb5e128810c06abd15ad3ef0bc95622c20da154ca500892972305c94feabedVirustotal results 52.54%Heodo
2020-08-13FILE_PO_08132020EX.docdoc 2ec1025c3a44b35de74853b22998ea439d6eb5f0d92d9065256692f0deadcbd9Virustotal results 51.67%Heodo
2020-08-13UZZ_ET5130132825XU.docdoc 5ec2a412f6729dbbd84453b84c85ac56f93e865a1900eb514efedefedc56467fVirustotal results 50.82%Heodo
2020-08-12PO_08132020EX.docdoc a9af06ae735677ec282b4a66f7bc85a343dc7c71491658673fed6150e05ef3c5Virustotal results 50.85%Heodo
2020-08-12GAZA_OBU62JAWVI4JRE54.docdoc d0ecee1cad0e97af4b127dc23861ffbee329ef4a465840447b48e554801e6081Virustotal results 49.18%Heodo
2020-08-12AX_PO_08132020EX.docdoc 14e48779b1ba469e2d272fb8e2b07402cd7ecbabd3fb73d989fff92b530ef9ddVirustotal results 49.15%Heodo