URLhaus Database

You are currently viewing the URLhaus database entry for http://zakahlife.com/wp-includes/P2Anjqkwlc4858/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444183
URL: http://zakahlife.com/wp-includes/P2Anjqkwlc4858/
URL Status:Offline
Host: zakahlife.com
Date added:2020-08-26 06:17:08 UTC
Last online:2020-08-27 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-26 06:18:05 UTC to noc{at}databasebydesignllc[dot]com)
Takedown time:18 hours, 13 minutes Good (down since 2020-08-27 00:32:04 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-26X2KPTw00083314.exeexe bfbd0e443a105f4b104be158bd6ba72e689359b3f13e159e523809560ce0adecVirustotal results 15.38% Heodo
2020-08-26py04.exeexe 953f7f72b213e174df8696e0618ec792fe90fd48f9e4ee1462ebc27b2f3e15aen/a Heodo
2020-08-265KT3Srz0490787740.exeexe 6a296d05d98a0151c5313c07df2ddefd48bae5f1b89d29cca0f888eb3ddcf356n/a Heodo
2020-08-26ilPB1BVL00.exeexe ffd21dc3b4cd243da4a4e206a70a2a42527a75596679ff0ff7f3ad53da7fa7fen/a Heodo
2020-08-26TMXVZ0002027997241.exeexe 63f46dac698a9e271cdb886535bce093076a60e9399688b35d0e204f851d8bc5n/a Heodo
2020-08-26p839348582300.exeexe 2247fcc2f3d604d7fd00cbaa0035a6cd8e13c4b52c747f146cbfe96103344ba8n/a Heodo
2020-08-26E7K6uv000002410.exeexe 730516c2119fb79d69b5b8ec94ff0b7f4e65304d144264b9e6ef005e6a839732Virustotal results 13.24% Heodo
2020-08-26esOZEwX049.exeexe 0171a88c288e22fd70cd03d96a2ce260c6a7d5b8cc567df521b5497e2d246b63n/a Heodo
2020-08-264eh00006735363333345.exeexe 5739ea0f0d1b7554d2bfc2814c58cc7f0614ae8b85b583dcac690ff23bbe53aan/a Heodo
2020-08-26TQ4X9YlxzdcY0000293007.exeexe 6ebdca5934e52214c3a69a31db846c7199d98051bbfa134807eadb26ce4fc964Virustotal results 13.24% Heodo
2020-08-26x9Rph5lpR0004.exeexe 894798e433c775081e4838a7348d6dafc32db771673740dce2b0ef837daf07baVirustotal results 14.49% Heodo
2020-08-26QKCLOdumDtLI088000751.exeexe 601158a7ef524b17b9fd8d92cb78b03488ab947483e03d7fca92de64d57b37adn/a Heodo
2020-08-26YO937113.exeexe 5a1ac3df212d1a7cb75db1076ff63401419574d19447ddd4bd7ed2e0e9c518f5n/a Heodo
2020-08-26HcdnWPt7000037207.exeexe e13c24800567dae69849629e5dd5b685c18d42e7e2d072ac661db7785e40771bn/a Heodo
2020-08-26WQh6868594.exeexe 46b76fbf3b0b98b24635f42f8a2749159863920b34cce0f4717c51c402a7b0d6n/a Heodo
2020-08-26GXctf97QPEYe000046063.exeexe 55714e221243dddbdd0dbcd6f0be09909be2bfeaa0aee8ec9b2799a4b47aed55n/a Heodo
2020-08-26tfo0rfUo9Gp00878150.exeexe f587f085906340211baed4f34b00f59aaa78bad6933b90e313244bcc99d86867Virustotal results 10.14% Heodo
2020-08-26818rOz0000200178066251.exeexe c52790024ab783bbe7d099ae73f99b7f359f70af8605d780013ebe73aa5d5cc1n/a Heodo
2020-08-26ISUC0120823509257.exeexe f58b8e080f207eee969f183bfab13785db644860d7d9614065d7dd8ac671d8e0n/a Heodo
2020-08-26Ym8041j6UO7o1657674.exeexe 8a110ea67759a9425bf1b29b85adf651f497281513fcbd5ea4f7517b9745e751n/a 
2020-08-26ipIseY28160499.exeexe 1c8d14560b98630c69f9e89de6913d57012fed32836da0cb5961a476bb275e2dn/a Heodo
2020-08-266kAoBsvogSap07.exeexe 78aacfc35ad3df0bbe30fdf5cfbe8a6b5a905a23613e9a12ae154383279346c4n/a Heodo
2020-08-26g3KV1938.exeexe fde3a000b851712aecb8393399fb92129d8a3f9804a2a5ec7b88adc530882d96n/a Heodo
2020-08-26Bw0000828.exeexe e1019b28480e051aa80760d0202f452b932669e7852fd58c3d9f1263ef355f9fVirustotal results 8.82% 
2020-08-26rb09752927397177.exeexe 96171ca0c44e58583364b8bbe137376928c0cbab2fc136482708cf3b46b242c4n/a Heodo
2020-08-26cSiXj7Yc9QQr068718035.exeexe c43f161d76aadc626453a5f9e3dfe432d70adbbafd350a4244141e997e09b27dn/a Heodo
2020-08-26xc000657536478769.exeexe d527d49f3d788e1525f78caf64329d9e33098e4671cb08aba49360e3f6a18894n/a Heodo
2020-08-26yVxEv10785094315369.exeexe 477c9003567266cefbb56323be8744f24d62472ef7ad364e43200974cbea0b59n/a Heodo