URLhaus Database

You are currently viewing the URLhaus database entry for https://zabor-pro.store/wp-admin/OCT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:590216
URL: https://zabor-pro.store/wp-admin/OCT/
URL Status:Offline
Host: zabor-pro.store
Date added:2020-09-21 21:31:06 UTC
Last online:2020-09-21 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 21:32:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 17 minutes Good (down since 2020-09-21 22:49:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-21DOC_UH6675903799QJ.docdoc 75aacb9b9e0f3b4113358caf49078bb79286fb9637c523807a8f533d0df7c834Virustotal results 30.00%Heodo
2020-09-21PO_09222020EX.docdoc 539412deaa4405005d8f402fe43a5cffb4c1163e751e9cea52651a6a0f924086Virustotal results 31.15%Heodo
2020-09-21REP_HLG_090120_QEX_092220.docdoc 2d560e72a8bbfa60a7f05d58048f8174de084d6ff4a53531d9582e251fc067c5Virustotal results 30.00%Heodo
2020-09-2197067036.docdoc a8f76389eb48147fbdfcf5e3037911b1d933d7e0a1da38d58125ee2b9084b561n/aHeodo