URLhaus Database

You are currently viewing the URLhaus database entry for https://ziil.eu/cgi-bin/JNzI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720286
URL: https://ziil.eu/cgi-bin/JNzI/
URL Status:Offline
Host: ziil.eu
Date added:2020-10-19 23:08:14 UTC
Last online:2020-10-20 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 23:10:10 UTC to abuse{at}elkdata[dot]ee)
Takedown time:6 hours, 56 minutes Good (down since 2020-10-20 06:06:25 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20a3BhKchTJnVmSpv.exeexe c764c20bf4d3b8e6e05387acd0eaaff5bb924bd2714d626fc191bc1e14b861bcn/a Heodo
2020-10-204OXDeXjwPaaqfpajMg.exeexe b24346db5608b3198ee3d8ba666140bc0615784044f9e00b1b11fddd777d8bben/aHeodo
2020-10-203M4ss.exeexe 403e9f84c958f1afc7b524bececf98a48ae008839960f2eb3eea9442813aaae2n/aHeodo
2020-10-20i.exeexe b0e450426d854b7dc6163e47faee5720e52a5f9f977c08967f041ec0c8c089a2n/aHeodo
2020-10-20dqWNu.exeexe 75b077c2a5e84de38b37ae07b1bd7177ddbb073d634036491eb20b66d47ed5eeVirustotal results 20.00%Heodo
2020-10-20K5z0mhbWi2SfZeDM.exeexe 9e47a4236aa7c3f69838f6ab2b7a35f5da24c7f82b99a5b66536033ab5c0043dVirustotal results 18.18%Heodo
2020-10-20OhYsFr0oM3.exeexe 908d6ffd317a5c61841dc79c7a1f8e07735d5049053f1a47ba17668339cda3c1Virustotal results 17.39%Heodo
2020-10-20EvtDHwoYyN4axzodcNVI.exeexe 928d6a1b3413a08dcda179bd2ac25369b94c7902902be12823bae818ffa0e281Virustotal results 17.39%Heodo
2020-10-201rpZCwNIO0tTlLPsiAl.exeexe 233a140fc1dc5ae470665efb6f455266eb2d7b6e83f81b700e7546cf5fa2cbc5Virustotal results 16.18%Heodo
2020-10-20OsJUqpDqQ.exeexe 037a3c1ddbf4d5f7e30f0a2c8a2a461aaa7762ae0f808b521a549f6bde223231n/aHeodo
2020-10-20VlbegQ2R6IAoKc.exeexe fe4062d6eddbcdc381522057bc0b1b8ee275e771332aae0ab52d7526845e3aafVirustotal results 17.14%Heodo
2020-10-20eI7E.exeexe e978fb717acf0f1688e422da402b1d5a2e2176d5ebfea374b7cde400e710680dVirustotal results 17.14%Heodo
2020-10-20c7QjjbJ90pAu.exeexe 8683fc98c058aef7705eeb8530ac0c66f1f93e1c017c628e1568001e5b9a0f1cVirustotal results 16.90%Heodo
2020-10-20IuPU6jWqLptHDmg2g.exeexe b1e5d95ef3e93931c6945de9c4595dd9b35731a6602fd1d7f8915e4861c32fb5n/a Heodo
2020-10-20Cw8F5zbW.exeexe 60c0d30357d2c90b4c3c75b59d1cb70b44d1071992c2ff0173701a2aa923a469n/aHeodo
2020-10-19lqhrW.exeexe bae4cf6f313ca6f4b7969196ea0746884a35a464e5500b1c95233b3cd33d597bn/aHeodo
2020-10-19wLj.exeexe 66b1b6546244ca1fff1d4114bd9699f3de343e68a58f90b850f994be7b7768daVirustotal results 16.90% Heodo
2020-10-19WlOL.exeexe 2e6b0a197ffd5d4e204dcc08c8de85a5708c7f21edb0fc0ade8c18eea2a4b451n/a Heodo