URLhaus Database

You are currently viewing the URLhaus database entry for https://zonadeenvios.com/wp-content/invoice/923619/hbLUcp/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729133
URL: https://zonadeenvios.com/wp-content/invoice/923619/hbLUcp/
URL Status:Offline
Host: zonadeenvios.com
Date added:2020-10-21 12:17:07 UTC
Last online:2020-11-11 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 12:18:20 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:20 days, 21 hours, 1 minutes Bad (down since 2020-11-11 09:19:50 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22invoices 0188 & 2138.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22Form - Oct 23, 2020.docdoc 69af96e96aafc755df2b99ba9d1925a163cac2579277136ed1a6bc9b24d0bfe0Virustotal results 40.38% Heodo
2020-10-22Invoice.docdoc c62002794ed88e1776376cf0144fdaa74155895bd71f5a69b781acf83818f56cVirustotal results 40.48% Heodo
2020-10-22Payment status.docdoc 980307d89e587b452b4070afed9ad8494e035481816544a310dec6a81a7aa8c2Virustotal results 39.62% Heodo
2020-10-22invoice #3418.docdoc a1ef2e0555f7e14dc268a65a1b25f0961ee37a55170b424ba29ad8ebdd90db69Virustotal results 39.34% Heodo
2020-10-22Copy invoice #72457.docdoc d9e9ce342586063f33aaaaf408ee47cc54b990cacbaab0383bbacc0852320faaVirustotal results 39.62% Heodo
2020-10-22INV_053823.docdoc 621c80400686860afb16c417aa76f5068c7bcd642104a225644b805539b9e5c6Virustotal results 37.10% Heodo
2020-10-22form.docdoc 05c27cabbde0441208b26f77df5a0f5346f2c057b25ab1515c61805324c18ae9Virustotal results 37.93% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 6d023a0790cfa813258bb0b0457a718d4d55c93a65b0988444b19c6279f5c42eVirustotal results 37.70% Heodo
2020-10-22invoice #46124.docdoc 12a9d00947e3f08cb67e3d1a197fd116e29836a17845009e590d283eb80e960eVirustotal results 39.62% Heodo
2020-10-22PO# 10222020.docdoc 789b91aa9915333fc8a86c33524bd2e469d7cefca47127b96ea032ee5182bc9bVirustotal results 37.29% Heodo
2020-10-22October Invoice.docdoc 5b1761a1537a8c8673316453dd74af7fd6185e1ac5daae77606ea4734d305825Virustotal results 36.54% Heodo
2020-10-22October invoice.docdoc d60a5b32d8f9d47bc60a8227a98cce49b50d11ff3464da426f073e91dcfe7a16Virustotal results 36.54% Heodo
2020-10-22Invoice #223.docdoc 54e4fc3613affad5354fc1058f7879031c1191f2e8e79b72df4673bae4603695Virustotal results 50.00% Heodo
2020-10-22CHJ-100120 ZKSD-102220.docdoc e1c18ef2692a84d679e77f98cb2d79c78ce841f999715235aa5aac42607ad26aVirustotal results 48.08% Heodo
2020-10-22ET4918214766GA.docdoc 711fafda2f160ff5d89246ee698c4ba0738663a2a0a61469c401fc03f59b4550Virustotal results 49.09% Heodo
2020-10-22form.docdoc fe69570cfe43c056f36d0a40929d53d4532cd181924613bda7436913979c33cbVirustotal results 50.00% Heodo
2020-10-22Payment status.docdoc 64ee7027b8c1fc6f5a53589c1b063a42cf59f5a99924588ae219a9950fbe7130Virustotal results 46.67% Heodo
2020-10-2200282941595.docdoc 48c4356a3629c972a22b83fe612ed12ed47467fd7085e18ac16786cbd9c2bc4aVirustotal results 53.70% Heodo
2020-10-22Form.docdoc 73dbec89c21200a9e7dd1ec67b06b9efad9718584b71af252f4926418abf32f6Virustotal results 48.15% Heodo
2020-10-22Payment.docdoc 5fb5309b154278b57d6a94d784dd5de602c441608e00557aa6c53c200ccbb3b1Virustotal results 45.90% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 2bc5c1591569f6e8a480a530bf343df21867da564b7503824cb0e5193d3f8937Virustotal results 41.38% Heodo
2020-10-22MAU-100120 IFLI-102220.docdoc 9e13f2a6023aa5aee27ad5d18154d66135feae3909574687817e602e90390b5bVirustotal results 47.17% Heodo
2020-10-225376053621TF.docdoc ab4a558e5f07f221ed6052698d5a9d1b3654ab56380486df8f091e1176d3af1en/a Heodo
2020-10-22INV #260540 FOR PO #00111578412122.docdoc 4d7e619f0381816bed7d0ffb6ea0a43ebd6050cbfb10f691c1bf8d8466c11345Virustotal results 45.16% Heodo
2020-10-22V-100120 KNTT-102220.docdoc 72da9c13652853256f7cab8762f533e63f52328ba4b06d4bf44d3dc0cd5fe2c5Virustotal results 46.30% Heodo
2020-10-21INV_266158.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 33.96%Heodo
2020-10-21Form - Oct 21, 2020.docdoc 846e5913124d7032c01dffc200b7250ef349a517df8653d0e92ba024b61de295n/aHeodo