URLhaus Database

You are currently viewing the URLhaus database entry for https://zdaben.com/wp-admin/INC/CW1ng7WMEZixUZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:588526
URL: https://zdaben.com/wp-admin/INC/CW1ng7WMEZixUZ/
URL Status:Offline
Host: zdaben.com
Date added:2020-09-21 18:53:34 UTC
Last online:2020-09-22 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 18:54:27 UTC to abuse{at}sioru[dot]com)
Takedown time:17 hours, 22 minutes Good (down since 2020-09-22 12:16:31 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22dat_20200922_OAS138.docdoc 53ba841833e4a9acfb16fa855e6f616913dfd599db840ad5f7aba6635ebda0aeVirustotal results 27.42%Heodo
2020-09-22doc_2020_09_22_0480.docdoc 62a247c06790b9986416ffa1044dc5d8bff40b6b706081e25f4db985f613afc6Virustotal results 22.95%Heodo
2020-09-22List_2020_09_22_6104.docdoc ef28e3219caccf8576b7f4eb7146b9fc62fa24e5e962b80f11c01df5a146e758Virustotal results 23.33%Heodo
2020-09-22FILE-20200922-KB948643.docdoc edb38f20a57df9726e7a8a2f78f122e7a968a390fa006a996d93e06a040df87bVirustotal results 24.59%Heodo
2020-09-22Rep 73854.docdoc 4f8e5670cb71d357da7b7eb48753d60aee76b24e8ad9bf8c7908c6410b488b64Virustotal results 23.33%Heodo
2020-09-22dat-2020_09_22-Q9409.docdoc 37c4ad414be30dc65ee64153c1bafdfc4c89085c285dee64d6516423f718960bVirustotal results 23.33%Heodo
2020-09-22FILE_582.docdoc 76c0630543f301f3fe63e8ca4ddef6171019fe2bc21d3c891bceb80774bb4cafVirustotal results 25.42%Heodo
2020-09-223053 20200922 T245717.docdoc 4cfc968cd768f17951b0927ce37e5713686b0a8f2b112c3883ae23f8d190d781Virustotal results 23.73%Heodo
2020-09-22File_2020_09_22_0139.docdoc 7e348cbf0bb85b15e9f742193f2073ad5cd0cda176a4f0da91a947f9bcb54b6bn/aHeodo
2020-09-22DAT_20200922_2221633.docdoc f482643e9c789b0358eca0cec6dd9523355bffb2da53b01de9027ace5430b3d0n/aHeodo
2020-09-22arc S515431.docdoc f0dbc484997e20fe5db380cddafa06e0d939fe71ce91d0fe4ed65ebabcd06b3an/aHeodo
2020-09-22TP994_DWH806.docdoc ec37b136624422e29c88210cbd3ef2b25ca9ec1099ed0db90314595f7421b388n/aHeodo
2020-09-22INF.docdoc f46d933cc794ec8f95dd03ddc687ee164ba570053e0d0813e8d79c4d09ab368dVirustotal results 50.82%Heodo
2020-09-22FILE-GZY9910.docdoc 3a55d135adcf77677eb1ba21e4b5425ff19a8198264e313df904dc6982bf1a80n/aHeodo
2020-09-22doc_H650541.docdoc 5744548adb59f24037bb5500e559b80bc6917502f107b28a16b38ab4e6abfb71n/aHeodo
2020-09-22List_2020_09_22_45012.docdoc 8934785f5b6877f8dd468cbee3d8eb5b07b3ed41ccfbaa1fd2724287c6b58fc5Virustotal results 45.00%Heodo
2020-09-22REP 20200922 J063.docdoc 7d7c3ac7f91ddd427921fa257d0e556486d9819ee2e21115247c2b5d763007b4n/aHeodo
2020-09-22Attachment-PHP363.docdoc e5feef66c305d39b964ea0daecb60211c37c70d35ae53a638ac6a43c344abd4dn/aHeodo
2020-09-22mes_2020_09_22_M35012.docdoc cf1ab745ab6a4dc857eb8232bcbcfe7675540dbc45e29114985c290ff415b8den/aHeodo
2020-09-22mes-XXV0317.docdoc b3bc13c79571b2cf77ab2ad7a593e512bbaf1bf61f0ac3eacb10e78e840cb9fcVirustotal results 40.98%Heodo
2020-09-22Attachment_27872.docdoc b3838280203a43fd02a295edbba1ec0ebe08ac22efe3e8e5baed626f3ebe698fn/aHeodo
2020-09-22file_2020_09_22_ZA619225.docdoc 943f5e58cd9c9060ea37bd3ca7dba199921932c07110941346389657a4ef1a6bVirustotal results 37.70%Heodo
2020-09-22PCR70087-2020_09_22-2478.docdoc d05527f19cbcca0953e287b0b76194570b3c3e64eaff273f6428446e1a4379dcn/aHeodo
2020-09-22SJP818-DVM163652.docdoc 90f5fcbadecf831b2ea1ad31be2ad24a539c2886611a270e23975355d3ba2692Virustotal results 33.33%Heodo
2020-09-22doc 2020_09_22 IJ503.docdoc 3cb78e2ab36c72f8292da6808ae005ee3aa17c694c35a65fea4a89d0f972d121Virustotal results 32.20%Heodo
2020-09-22File_20200922.docdoc ce99d6a97e21495a2133ae942cc02e674461cbcbd4065b65eabdb8bbcfa5743dn/aHeodo
2020-09-22List-20200922.docdoc cbc24d09773cf56460c3a9cda7b497317ec61632c48aaf8615d94fe4a58ac642n/aHeodo
2020-09-22Inf_20200922_08084.docdoc ddabac18016628a7b4e14df72caa0012c52af6a318df5c236615b4869b257546n/aHeodo
2020-09-22Attachments_MD665.docdoc f9c1f50a35c2941949d6ee8e91935c1fcebd4b1f46849f8870ff3267bc5a88e6n/aHeodo
2020-09-22dat.docdoc ceeeb96a381895e4e8e1b6d7a37870865d0d21d8202c86996ceea054fdc6ad4fn/aHeodo
2020-09-22doc-23374.docdoc 7a69f4936890bbd4971317e9a2abf4042add105e51a3da5fe2be1251a9a68ae7n/aHeodo
2020-09-21inf_20200922_75502.docdoc e555220f1fea5978ed71dd48c9b80f989ba259d12fed9b96cb8692e21a706971Virustotal results 31.15% Heodo
2020-09-21Arc 2020_09_22 SV835.docdoc 457b6a08f7e1b6cf8d09929198bf73710085c58f346b256d31d99645df480e67Virustotal results 31.15%Heodo
2020-09-21UNTITLED-2020_09_22-AF7594.docdoc afeb53f8204c23e2ff8f5733e97220ecfb71466eb4f3f9ad1aef0807fd216973Virustotal results 30.00%Heodo
2020-09-21rep-2020_09_22-7491.docdoc 408b12e331000ac29de83635501b2c1ad800d8465e28a0a8054f10c4fdcb091cVirustotal results 30.51%Heodo
2020-09-21Rep 2020_09_22 9747820.docdoc a71eb1fecb04c956e351274028426fcbb1a65045ab70ec3f73350e15fa439bcan/aHeodo
2020-09-21arc 20200922 VFH6993.docdoc f0e77efe2ed5bb775bfcefae4448ed8dfc00f824d1e9a9b5f6ea63624ee6a360n/aHeodo
2020-09-21doc_20200922_VSU046734.docdoc b6a912df69f9643eb650746c7b191bc2b44d760e2a51bfaf8eca19a74241e06cn/aHeodo
2020-09-21Dat 2020_09_22 B350448.docdoc c1fbade9d5f7c2b5705288400f77ce167e2f71ae4bda087c52e2983d2dffbdf2n/aHeodo
2020-09-21INF 20200922 067.docdoc bf472ca39b5a4407fe40c2130b3bb1495772cfe47feb4c79046e811be37e8d95n/aHeodo
2020-09-2150111537-GZN560490.docdoc b2fdf39787d7404bc206d1a5ed3b41053eaa0c375641af699e74f70281097f29n/aHeodo
2020-09-212736-20200921-49309.docdoc cc422106d6dd2c41a70e946a117c310587b1beb090c9366c0122801bdbf0ab0an/aHeodo
2020-09-21dat-20200921.docdoc 49b275e5af380c6534fa127d28e602929157b7eb19352e9a03fefd4271f678edn/a Heodo
2020-09-21List 20200921 5018.docdoc 77c88c85cace420b9b8fe01b1306ee27674e3ec8a457d99302c980ef2e271a3dVirustotal results 26.67%Heodo
2020-09-21rep_20200921_T572449.docdoc 35cde8868a2076e10e0dfddb3ec487a74ca52b6643cef4d514deb69d11e9edd5n/aHeodo
2020-09-21Doc_2020_09_21_807089.docdoc afd45922c3589ecc0dd6a70924ddb82a913798343dd9d425a83b655e94517da7n/aHeodo
2020-09-21DAT 7608.docdoc f843c6d86e65d7abf6658590e9c681aa01ccbf1e9938afccbf4e911e98dec3acn/a Heodo