URLhaus Database

You are currently viewing the URLhaus database entry for https://zirrimarra.eus/wp-content/Documentation/svz0w6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694767
URL: https://zirrimarra.eus/wp-content/Documentation/svz0w6/
URL Status:Offline
Host: zirrimarra.eus
Date added:2020-10-14 22:58:06 UTC
Last online:2020-10-19 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 23:00:15 UTC to abuse{at}choopa[dot]com)
Takedown time:4 days, 21 hours, 37 minutes Bad (down since 2020-10-19 20:37:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-16INV_24807529.docdoc e6896dad4ee0bc73a3114762b88c9d93732c631e64c537334ac38f7c7c421141Virustotal results 32.79%Heodo
2020-10-15LMS_100120_GPX_101520.docdoc 599c5a96c48cab303ee9a8fedda331cf66f2db8f076733cf715d00c5c4278e20Virustotal results 29.03%Heodo
2020-10-15BAL_PO_10152020EX.docdoc 09b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbn/aHeodo
2020-10-15BAL_LS2Y0S0TE6PQL3.docdoc 09ca73e0406c4d96a73cbaa68660617439ee99224d2603caf1610dd5cad5cb25Virustotal results 41.67%Heodo
2020-10-15BAL_618970199030.docdoc 4daef1037d2e8f34834dfda50a4bc9fd7b5e30aea3c2d6b666d85824bb90d79dVirustotal results 40.98%Heodo
2020-10-15FILE_AM1108817429CC.docdoc 826df3430c822b2aa33180efdc56c45a6a2e76c53620a4956652785a354fe744n/aHeodo
2020-10-15DOC_PO_10152020EX.docdoc 03afbf9b046ee6d340253662dfb45f59e4fb6e75b28dd8bf52bb8becb58145b0Virustotal results 33.87%Heodo
2020-10-156533264400579613133522.docdoc fc4e851464b275cb4206af8ce176350c7e12b7b1334a795cf27e48bb6cd9df06Virustotal results 32.79%Heodo
2020-10-1510514302.docdoc 0cf59450f4af8123dc62d34cb387c1f4bcc5a3c38cd4c966acbd7552574d9fc8Virustotal results 33.87%Heodo
2020-10-15REP_MDP_100120_SOP_101520.docdoc 100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533Virustotal results 34.43%Heodo
2020-10-15FY_42187627.docdoc 92a930cc35f0b758afa1eb48adbd009a241f19b3a1e5a10f2fda6b5495256eebVirustotal results 33.33%Heodo
2020-10-15AI_FA0690463930TW.docdoc a9e9fd09c8758fd9bc32c4f3cdc9b19afafdeb894a288778c2a4df42944be7c0Virustotal results 35.48%Heodo
2020-10-15DOC_0MN5RHL06ZB.docdoc cca3799a5d79aad049795ea6a869e22d90d248ef1c1193d5d5933237b20157c5Virustotal results 32.26%Heodo
2020-10-15DOC_PO_10152020EX.docdoc 275d247b675319a0e083b29b0e1c88b3bae28687e80b83a5b6db109ae72d954dVirustotal results 31.15%Heodo
2020-10-15REP_MOL_100120_RLC_101520.docdoc 0ce691ae2caab090785a0378e42e72fb8c1b6e129c8b3f50e32462295cf128e3n/aHeodo
2020-10-15PT_6BKQDYEG7K3.docdoc f2749bfcb47ccd5ca2d9a1a0707ed06064ceb9ad0549c3bbff8475d01668d9b5Virustotal results 29.51%Heodo
2020-10-14IQF_100120_ZNV_101520.docdoc b1380f1fdf3f7636d79043feef8f62d1f57ec8694f3abddce522899895cf4dddVirustotal results 29.03%Heodo
2020-10-14YH5976121908SH.docdoc 9c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811Virustotal results 30.65%Heodo
2020-10-1473531176668.docdoc 90e36d2990e1c86b71a77c96196d4fbe57e9e5d274d37bd085edf57d4058a55bVirustotal results 27.87%Heodo
2020-10-14INV_PO_10152020EX.docdoc e373aeaa39d4efff72593a5b0a30b797679037516c98a1f6fa3deb3f5fc6bd74Virustotal results 27.42%Heodo