URLhaus Database

You are currently viewing the URLhaus database entry for http://shopezoy.com/wp-includes/976144727019/zl6q3lkuimx-09/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:719992
URL: http://shopezoy.com/wp-includes/976144727019/zl6q3lkuimx-09/
URL Status:Offline
Host: shopezoy.com
Date added:2020-10-19 21:28:05 UTC
Last online:2020-10-24 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 21:30:08 UTC to abuse{at}liquidweb[dot]com)
Takedown time:4 days, 19 hours, 23 minutes Bad (down since 2020-10-24 16:53:12 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2000003990.docdoc 544ff4b94e4f7afb43e2c47a07cffc8162ca9d60b804e0d7203ec85fc2ef81c5Virustotal results 53.33% Heodo
2020-10-20Invoice #47239.docdoc 45327af6d3d75a274f4c5d122adc41d42ddff44e520c7c02efb3df87adc64be0Virustotal results 46.67% Heodo
2020-10-200028038265.docdoc 2e687ca36b3132b0704c1da58bfd462aa6bf5272d6ecbc84616059abc2fab4f2Virustotal results 49.06% Heodo
2020-10-20October Invoice.docdoc 19aad5040fee8a81772e4326aa715f5fdfa438971518f212a8a8a8f96bf9ae1fVirustotal results 51.02% Heodo
2020-10-20Inv. 627218101.docdoc be3645a6416b42048d934a1330244b34134f64f504a20c92af99c1ecd301deecVirustotal results 51.61% Heodo
2020-10-20Form.docdoc 351fcc4213634fcc050b1b9fa1b83edb1aa5b64736aaf801c2928e5deb5c35b4Virustotal results 50.00% Heodo
2020-10-20Z-100120 DQEC-102020.docdoc 0fc8e8b6e2bd46027ae6472ec944995b2976399582013b8a7ede625f362572f7n/a Heodo
2020-10-20invoices 0669 & 59893.docdoc abb1fa28c17964d8d4366e43c3fa606bb40eb59a69d128368a37c9ae5ba84544Virustotal results 50.00% Heodo
2020-10-20Invoice.docdoc b53ae43743c6308bc894bdee9df0745d8c360217f26cf37ceda3a979b519969bVirustotal results 48.39% Heodo
2020-10-19INV #79513 FOR PO #040324855005.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 40.98%Heodo
2020-10-19invoice #365720.docdoc cec6705193596102df72c60bd2d7fd7b8ab7d34cb2faf1beb4f83ea5dced6bb6Virustotal results 37.10% Heodo
2020-10-190178323944RQ.docdoc 88dd95edc7f24c985b398873d6279279760db09de42abf2d8a2e5b24197fb41aVirustotal results 37.10% Heodo
2020-10-19Form.docdoc 2ed83e0131c900f328a50a70183b38ac50328aae993c99efd75f27ff2855c2a7Virustotal results 38.71% Heodo