URLhaus Database

You are currently viewing the URLhaus database entry for http://zhafaro.store/mail.zhafaro.store/report/5hfruu3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:453197
URL: http://zhafaro.store/mail.zhafaro.store/report/5hfruu3/
URL Status:Offline
Host: zhafaro.store
Date added:2020-09-04 10:28:05 UTC
Last online:2020-09-05 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-04 10:30:03 UTC to abuse{at}microsoft[dot]com)
Takedown time:1 day, 5 hours, 7 minutes Poor (down since 2020-09-05 15:37:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05BW_PO_09052020EX.docdoc 8b23e164f16ba0caed21611db9782895ac3a6a1f5b30a16e7cff6a2f8e3c3008Virustotal results 21.67%Heodo
2020-09-05OHC_FJJ_090120_HXY_090520.docdoc 908698080dcf9229ad6d3a5b3faa55ad9f3499129372a809d011b6d24ba9d445n/aHeodo
2020-09-05BAL_8806325396.docdoc 7888c29713425a14d1a374dfad7e3ba568408a4c756f476461f1357fe69699e6n/aHeodo
2020-09-05BAL_TK3034550276OS.docdoc 52646e971288c190bffe00616c46fdb3741f1be6a5f0fe2235ca71c24435bf65n/aHeodo
2020-09-05K_311048856129394426.docdoc 7c88f52c679aeb917f52a42b5424f5aeb90901cd44d00fe9aa0608e4f2940cb4n/aHeodo
2020-09-05OD94D429JL1BXLP.docdoc 2e997a833026463ee1ddc2b571d97d90c94ac88cdb614cc5e5803d48b640391cVirustotal results 43.33%Heodo
2020-09-05V_ZX1713556932PW.docdoc bb9c837b1bd4fe34cf3377a063261449907bae9ffec1af75dcfbe5fd01ec9a7fVirustotal results 41.38%Heodo
2020-09-05BAL_GS4751328488LI.docdoc 2b7b0ff44457a586cf0ca88f5b8f4bee199a18d6c52e494b2ecbbe083c3baf5fVirustotal results 40.68%Heodo
2020-09-05REP_32595338755135.docdoc e58920e12dd5ce571200cf0e7449728756bbb8a0b43d301ea7a625b5d7755c1en/aHeodo
2020-09-05REP_2911056502238.docdoc 5391bbb94eaab89d4864ca7408da299a029611928be8cb4e99c97eabc0b46e4cVirustotal results 33.90%Heodo
2020-09-05DOC_94714096.docdoc 7a30501200d16da77107068379331700e901268be067ce701617b4df11238b75Virustotal results 21.67%Heodo
2020-09-05REP_PO_09052020EX.docdoc c409cd7639c969f0ed59d092f2ae2232a491fda76e08a4abbf011a59a648258bVirustotal results 29.09%Heodo
2020-09-05WD8160186581TO.docdoc ebc24ae3a35b97e088396a839e1b94a2a71fc528915607e809c1d56780cdf030Virustotal results 31.67%Heodo
2020-09-0523719312.docdoc d687cfe8a3bb92d088de0d9d1a6a61c4254635189e0a677975a5fb453724576bVirustotal results 31.15%Heodo
2020-09-05DOC_70EN65G15.docdoc 916a9fdb4940cd7596a9604a95e7af177de4c28e90bfa8c2c98d836e82aab78cVirustotal results 31.15%Heodo
2020-09-05INV_BFU_090120_OCC_090520.docdoc 53ce3cc79fda9e0a7f82873c3b94b8dfc7d31d3eab577ee54707cb8c1ad10585n/aHeodo
2020-09-05P_14724130.docdoc 7332b5582ed72e5d0f8ddd61b24b1329f4a0e3b5083cbe586c00e49f88e04b46Virustotal results 22.03%Heodo
2020-09-05REP_27937280.docdoc 60b865bf47919000a88deabae15f03836f7a97fded9224d81a04722c88461f93n/aHeodo
2020-09-05JAS_090120_NFX_090520.docdoc 13ad6c45f7189df1c3e34c5d0f1b0688a5c6bed6688be2ab02294bd75dcc80efn/aHeodo
2020-09-05BAL_57403093.docdoc f6dbabd3bbe35e52a24bdc676ac827f6631ddbe77e52afd53bdf3204b02f97c6Virustotal results 22.41%Heodo
2020-09-05G_NYJ_090120_EJH_090520.docdoc 6289f2e9039d8290e8166b5e1251bcd8d8317a3c458b4d21b7e210f113245c7fVirustotal results 31.67%Heodo
2020-09-05F_YEU_090120_IOK_090520.docdoc a4902d6d558079a9a9b9e2c5145cac1d467bce94d757d62b3b56df8d865cb0cfVirustotal results 30.00%Heodo
2020-09-05DOC_LQZXY96E.docdoc 6e94c41aeb7553891486189934d9ce6825f6cd5654d06c01dbeb75bad2f298cdVirustotal results 30.51%Heodo
2020-09-05DOC_74028777.docdoc 3cc5c61f7f38e6a0d0826bfef88b5579f3f31e5577e95625977df303da6e7e7eVirustotal results 26.67%Heodo
2020-09-05BAL_FG8948165405OD.docdoc f9ef3bfe7d720474ddaeb7e816e38478952790b9b70acac27a93a3ff3603ff24n/aHeodo
2020-09-05BAL_BPH_090120_TKF_090520.docdoc ebfcd70ebff55e62fec45d3a0788f6e8c9c17580d337ada36af00299b4fc89f6Virustotal results 24.59%Heodo
2020-09-05FILE_PO_09052020EX.docdoc aeafbb83665901f2f26e8d1dc47db812193cb13aadb1bb4f9c57e20d11979c74Virustotal results 25.00%Heodo
2020-09-05PO_09052020EX.docdoc de2503e4fb1d6a3ffc85f8c066f1573bdc8ae0aec1a0dedeae271c96d1b558ebVirustotal results 25.00%Heodo
2020-09-05INV_738924608145913152.docdoc 06bba3841bce09d816852e07db1632f9afdade1c5f7080d4da62953bc2c6b5b5Virustotal results 24.59%Heodo
2020-09-05BF4296633641YP.docdoc 8d5986085cd34ff48a11330bc6fdb74cfb01bc4f473cbdde5f7d4e8ca5cf637aVirustotal results 24.59%Heodo
2020-09-05BAL_8HDTDJKFC.docdoc c32724190cce2c08e0ff24aec9d392c06d60d948d66449850678496e1427640bn/aHeodo
2020-09-05IGV_090120_KEH_090520.docdoc 4a09b8410533e58450903480f4bda8f6857774c7c0a4e157418e8c3bb716202dVirustotal results 18.97%Heodo
2020-09-0526744086.docdoc d58fe516c9dbcf7fdc113d931629449423b9d072225d2e97a9d0bd082c6d107cn/aHeodo
2020-09-04VJ0767171461QB.docdoc 5d0a19a1fe7969a9950c8d711f2e80d7203cce5287c039937b593fd098938701Virustotal results 18.33%Heodo
2020-09-04B_M39I9I9IXYGY.docdoc 2f43042095548e57c08e93e9da55256337e669662c48bcae3ebc01a9b3113cbcn/aHeodo
2020-09-04FILE_SBY_090120_QPE_090520.docdoc f4ed99cccf3436ccf82ee81f454adc4b8f7a7d2aecc14226aa8675e95f42b0e5Virustotal results 25.00%Heodo
2020-09-04DOC_LK1018607913CM.docdoc 8b862cd5cece96f37514b0d188f8c210426e88f591e867c618df952152c7ff5bVirustotal results 22.95%Heodo
2020-09-04FILE_89723873.docdoc e3dc535e0f5a45859e8c323deeb9865a9d02594ce15fc062b0a65984ff34023aVirustotal results 25.00%Heodo
2020-09-04DOC_876508087468488.docdoc fab2e15b24926b36896f0aae619e19001af9577998f0e99344f1326faf43d174Virustotal results 23.73%Heodo
2020-09-0436222529478889.docdoc b5533222607313c1e5318c308f318224a53034815f0c64c398f7a47c3a022efdVirustotal results 37.29%Heodo
2020-09-04UZQ_090120_HKE_090520.docdoc 76169ff374a9346a75d77ab68b5e4d9565aae56d2b73736ddde1a02bd95dd5f2Virustotal results 37.29%Heodo
2020-09-04GXRJ017Y2Y9L4L6W.docdoc 8e37d86d7b733fafbb97894ee96d1ad387cbbe82900ff2e8e589d9184f91da7dVirustotal results 36.67%Heodo
2020-09-04REP_NF8541831407QZ.docdoc 59fdddd7d14174695b3060a24099fb534d15016cfee986d9a0ab15d779102b66n/aHeodo
2020-09-04UJYSEOC2LB.docdoc a7680798d59287fd95857a80ad4476ee4e1a98ed04c97a6afcfa5f523ab1ecccVirustotal results 37.29%Heodo
2020-09-04INV_PO_09042020EX.docdoc 58d07d4495dc0a6bfd46263f25301032d3562ca22a5cf2ea19e557d9e58b89e4Virustotal results 37.29%Heodo
2020-09-04FILE_10797146.docdoc 25dd5ad245a3a2eac82fb0ad2ec67b0baa6c67e01d69e776fafb50eb35f26831Virustotal results 36.67%Heodo
2020-09-04J8LJROH5FY42X.docdoc 0bf47bcf57e6b6b263747f0fdca169f668074843a9de60c73ebb09da12c05cf7n/aHeodo
2020-09-04SH2QCWQJ9G1EGKT.docdoc d23faf09d666b06ecc0248933f0050591863e4e0eca630cb4c1be7f58512fb3bVirustotal results 36.07%Heodo
2020-09-04FILE_98432404.docdoc f6176c22c0dedb27565ce220ac7b9815469179392bb92fbe785be55cd43400ceVirustotal results 36.67%Heodo
2020-09-04KO8727152444SP.docdoc da9a6385696d505459b043b8444346c7faa2614fd5f77a0e0df5110774036e08Virustotal results 37.93%Heodo
2020-09-04Z_44777407.docdoc 02dfcb241425a1573bdaa28cefb98b7ad06913ea17c20ab173ead3402c03e12fVirustotal results 37.29%Heodo
2020-09-04S_4531533467507589005743.docdoc be7359d5f34e145487cc45d11a463a8826b0aabbf7a8da0bcd9b4498bd6d3974Virustotal results 32.20%Heodo
2020-09-04BAL_S1I3DSNX.docdoc b704f4df9369996d3f77982e46cd1d4b080de1817ffbd8d68f5f4a82e16b1993Virustotal results 33.33%Heodo
2020-09-04PO_09042020EX.docdoc f2bcc6d8340a374e5ab78dc34f0ee3466bf303f6f77532bf94033595f3fff21bVirustotal results 33.33%Heodo
2020-09-04HC_FSQNLUXH.docdoc a2fdc9abbb2377b367097472c437e5a8ffedbf8e9b27eaa1e230d8cde71f89f7Virustotal results 33.33%Heodo
2020-09-04FILE_60444696.docdoc c791268b0a93500d2bf73e476d673bb2f139cbe63c7cdc5fe1f0da8bbfa86f17Virustotal results 32.79%Heodo
2020-09-04FILE_TUKQDBTR903PJXNF.docdoc fcfb787cfb5584dde4336dd9df370f1dbdce4446e047c22f8303455993f4c853Virustotal results 33.90%Heodo
2020-09-04REP_DJ3517262776KK.docdoc 3212bb6c80b78835f1e18093791987c2ad8b31e57c295a67264ca87c4edb0ad2n/aHeodo
2020-09-04BAL_72735660.docdoc e518aef76084cd1d89c2f34eb4960ee623c0f2f87dd31121f0f4f70c376753f3Virustotal results 33.33%Heodo
2020-09-04REP_137124775008.docdoc e627d5445b586181f22e9b1c5890b35c8ec027b86c72566fb2b9a685c10727ebn/aHeodo
2020-09-04ZDG_GUC_090120_RDW_090420.docdoc 2130681c6aad2c8f3371feaa59b9a21724fa49c49a4fca8fcd6773e0b27e2bbfn/aHeodo
2020-09-04REP_70919572851901636309684.docdoc 121bf03a4ab3c4b45e699994504ce2bc327aea720cbac22a23c8b3fbf220e5a2n/aHeodo
2020-09-04INV_XXQ_090120_KQW_090420.docdoc f19b7c3502d8e70e4a41fc4676cf0ba7a1de47cc19b1e961be4ceb8511119637Virustotal results 49.15%Heodo