URLhaus Database

You are currently viewing the URLhaus database entry for https://helpdesk.zkbrasil.com/wp-admin/FILE/rzeh7yi/yoibrhb5284731760346too301n4f0kxv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:555416
URL: https://helpdesk.zkbrasil.com/wp-admin/FILE/rzeh7yi/yoibrhb5284731760346too301n4f0kxv/
URL Status:Offline
Host: helpdesk.zkbrasil.com
Date added:2020-09-18 13:32:19 UTC
Last online:2020-09-22 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002943398 created on 2020-09-18 13:34:10 UTC)
Takedown time:3 days, 21 hours, 43 minutes Bad (down since 2020-09-22 11:17:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18R605P3ORARB95.docdoc 33099cd71cd92838445b2b6beaab0d5f29220c7866510e1a83dd32c0779c91a8Virustotal results 44.07%Heodo
2020-09-18Y_0XL0MKALFXLC2.docdoc 4e500dc20300e081376f4f6951330ba0b37700ae0b23ac5662a2e96e2cd9a755Virustotal results 42.37%Heodo
2020-09-1870501928.docdoc e6c59aa272b0319132af611954aba4331117e24c05ed652fdbf58c0ff36e991dVirustotal results 44.83%Heodo
2020-09-18AMED_PO_09182020EX.docdoc 4000d1ab30db6a5d94686c02f9a7e6e687231ff9bfd42bf56e3f9f1e8750ede2Virustotal results 28.81%Heodo
2020-09-18PO_09182020EX.docdoc 3794f324eaaa25b46f1e7f2d4c169c9839efa90483f52fd6816bd621f0984562n/aHeodo
2020-09-18JNV_090120_TMT_091820.docdoc 844364fc7fd27d3f478237624a434b3255b9f564ed64e272e1935914ab559d9aVirustotal results 41.38%Heodo
2020-09-18PO_09182020EX.docdoc 2be116761f944e13024bcdd5438723cefa835893e4fff5b6469836a25303c683Virustotal results 29.09%Heodo
2020-09-18C_GGL_090120_YML_091820.docdoc 529620cd21b208f373dc72c4efcc0cf9f3ce6bfbb8bd0e44bf371084cc1bb9afVirustotal results 39.66%Heodo
2020-09-18REP_KF9741498251QN.docdoc f6dee1b273f9ff061e9c1bcd320d7f98484283f3f6ce1973877bf93231a08562Virustotal results 41.38%Heodo
2020-09-18KX5817523351IJ.docdoc ff8c2c2c02846c0ee09da057b979f945cdc28c04c1c8041ff669861a5c327372n/aHeodo
2020-09-18REP_71167599.docdoc 3becf7d3aed1e6a3483bdeb9eb4c6887e9eb13ed6f194315109eeb2f19ae9a07Virustotal results 40.68%Heodo
2020-09-18252182599317228786875071.docdoc 579285f801aa56caaaa76f453da00a891c2d2bbe85a4d34c9c5ca47c5db15981Virustotal results 42.11%Heodo
2020-09-18REP_CBS_090120_HTF_091820.docdoc b525847655a58e746a7e416a39cab7b90b6a71a6228f915657e78f00799dddffVirustotal results 40.68%Heodo
2020-09-18VXW_090120_JZF_091820.docdoc 37a0d9d6ec68559ded11b432a58dba6536644a809e72c3375dc0b656f78a4964Virustotal results 31.03%Heodo
2020-09-1857608094458052.docdoc 4b4a38291be76ce02d9bd99092102eb3a5e0c9ee814e9fb7d6c3df32d24f6186Virustotal results 37.29%Heodo
2020-09-18PO_09182020EX.docdoc a83c9759321f48ee74ffd64e1ea879f1a4e77a5c212c3a604173d38e65291c51Virustotal results 23.73%Heodo
2020-09-18BAL_56401750.docdoc 44d0c90d842430656bb499c996d721b16d4ef131f92e3443c478d37beb0d43f2Virustotal results 23.73%Heodo
2020-09-18INV_93113664917164363570397.docdoc 39aaa2dda57fc4b9a918325a7de9d04f3064adfe0adf8ec9665c1068e9036497n/aHeodo
2020-09-18REP_LDO_090120_XYZ_091820.docdoc 15c49ec4dc917425fbbe700b8f340f1d1629be55957693427600488b42eb5156Virustotal results 22.41%Heodo
2020-09-18BD_DX4059571015BD.docdoc 310f3cc3eb2a31efc38b035aa50115810f1834d1928daf6f6269ab92f389b35eVirustotal results 23.73%Heodo
2020-09-18FILE_10507489114.docdoc 7c81019f932c35ff188d4260fe0b23ba6cb27363922cbb8265a8f3121e26c32fVirustotal results 24.56%Heodo