URLhaus Database

You are currently viewing the URLhaus database entry for http://zienoptiek.nl/wp-admin/http:/lm/3fjAz7jiWk4R/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452653
URL: http://zienoptiek.nl/wp-admin/http:/lm/3fjAz7jiWk4R/
URL Status:Offline
Host: zienoptiek.nl
Date added:2020-09-03 18:17:35 UTC
Last online:2020-09-09 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 15:20:03 UTC to abuse{at}argeweb[dot]nl)
Takedown time:4 days, 22 hours, 59 minutes Bad (down since 2020-09-09 14:19:39 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05rep_2020_09_05_RQ02459.docdoc 62cc3eedb06b43f8a3e286b0a9f04cbf36fe240a532b217d91950ea20fa0ba9cVirustotal results 28.33%Heodo
2020-09-04REP_2020_09_05.docdoc be5a076cc07b81d54fda54ef3c56f2d60ee214c3d1fe46de3dc59a1df619dc29Virustotal results 21.67%Heodo
2020-09-04P94109_126123.docdoc 88d669402f9cb6d3c39a7de76b5e16c45d5db2b7a4e5c5f2b9ec112d299f85d6n/aHeodo
2020-09-04dat 2020_09_05 INO469.docdoc 0f264ea12ac1b1f96e80c683d7aabce629b15ded57f43e29a4faa7cbf057d673Virustotal results 22.03%Heodo
2020-09-04427 351147.docdoc a8e4d449c8018f90196d3de6e14d75cdca5c5f76b989880e012890f87d43f6c9Virustotal results 21.67%Heodo
2020-09-04654696 2020_09_04 45892.docdoc aa3db031e17cd90af00951bc4d86c18c8e42328f47e9014b552993ff1b29c557Virustotal results 20.34%Heodo
2020-09-04H0409_2020_09_04_XO832.docdoc 623ee20c1b2e5a53a0bbf6eb21f4b87cb0e6392e023f1e08267abc08c26e5bbfVirustotal results 20.34%Heodo
2020-09-04Attachment_2764.docdoc 112b31f94d0408209223b109553273ff732fcd2f05b532c53d7ef7e4658bec80Virustotal results 35.59%Heodo
2020-09-04list 2020_09_04 5150.docdoc 9db91d669af1bf809886ca92ed83858aa55b59c031db7bcfcdb470ec77cfb0d1n/aHeodo
2020-09-04Attachment 947704.docdoc 09525f62505c8bf7a99dd08caa65a18ab1c71a0f291fd666b3c53972aa9f1466Virustotal results 35.59%Heodo
2020-09-04Attachments_22107.docdoc a49d6ff985f57e4d6e09893b343f97b9da664ae8c0b7c0e95f18f1a8f119f1a8Virustotal results 35.00% Heodo
2020-09-04Inf_2020_09_04.docdoc 8a87e7dcaf07545941e8f4859526c55f0b840dc1d051e86b09200a3a49ba5c01Virustotal results 35.00%Heodo
2020-09-046671TTT_20200904_0480.docdoc 07499f73c1b2290d3f1628c566a91f8f3bda896e9c9774c4de22d614a8b1381en/aHeodo
2020-09-04FILE-20200904.docdoc 4caf5eb87b69a8e37c3524c776870ace2c3a187f6d4956a9cf441148c4dc75cbVirustotal results 35.00%Heodo
2020-09-04Untitled_132.docdoc 5f507662f25de9c594d9c295a8fcd49bab262c3b83c2a470ca2a0303834b57d1Virustotal results 35.00%Heodo
2020-09-04FILE-20200904-MGU115502.docdoc 791553d28205023fcec3eb1d7b8e89736e5f99b90e7e8a1ddfa4452f1897a74dVirustotal results 35.00%Heodo
2020-09-04DAT 20200904 TUU4874.docdoc 20f0a0ba4cd0dac615e918dd489d36a9dbe9da8eccd28074379ccb9297f44202Virustotal results 28.33%Heodo