URLhaus Database

You are currently viewing the URLhaus database entry for https://blog.zunapro.com/wp-admin/js/widgets/EH4agl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:521991
URL: https://blog.zunapro.com/wp-admin/js/widgets/EH4agl/
URL Status:Offline
Host: blog.zunapro.com
Date added:2020-09-15 23:43:04 UTC
Last online:2020-09-16 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-15 23:44:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 57 minutes Good (down since 2020-09-16 02:41:59 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-160t.exeexe 6d4c59e26d18ea80f09a3002bf847ae693a9763334d01a8e8bf2527450b655f1n/a Heodo
2020-09-16yGSAFIaAsJK.exeexe 4168b8d0a820c65855cf0ea0de17828ca991cf6193a3f89c66e7e2bfc0005e5an/a Heodo
2020-09-16wA2oIC4nBnxp.exeexe 1ab902095b99b41c64ec680dc8047e0b603ab1511d00d0be6701ff969f5cf30bn/a Heodo
2020-09-16ooal51pCctDv.exeexe 870fa55e7798413eeaf034788f4d25ae92d7fcb1fbac4f10cbe60693ff9ad59an/a Heodo
2020-09-16XWTmNxZw7qU.exeexe 644fe530bde19badfc0e7d851137120895733f314f980e3849e1ccd16040f3ban/a Heodo
2020-09-162ju.exeexe 9ae29e92114605a2f4c3187ffee98179a7933dbeff6c54028299ee8c4c666e8bn/a Heodo
2020-09-16nE.exeexe 55831e1aead8f03996cfee088460de4cace77294858625dd2adcb54ff7a5efe7n/a Heodo
2020-09-16HklLEF5lnzPo.exeexe 45ad3bb7a51edf9f833d652b1cdb16e271f6370437c23380c7459ecd46546dfcn/a Heodo
2020-09-15QrToHeoUmRhAN1LE.exeexe 3933f1cda6d9bd8be4686229c5ff7bae6837b658fe768a358a5fab98321ed351n/a Heodo
2020-09-15jFoBw2Jq3pu087zXuz.exeexe 99277fbb22d002cb3818eb86050d647bc87e93cbdb0d8923cbec6fb939763e0dn/a Heodo