URLhaus Database

You are currently viewing the URLhaus database entry for https://zenbiotech.net/wp-admin/Documentation/mSFbwKsl3MOVuEyM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752843
URL: https://zenbiotech.net/wp-admin/Documentation/mSFbwKsl3MOVuEyM/
URL Status:Offline
Host: zenbiotech.net
Date added:2020-10-26 18:21:09 UTC
Last online:2020-10-27 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 18:22:03 UTC to admin{at}thvps[dot]com)
Takedown time:20 hours, 27 minutes Good (down since 2020-10-27 14:49:04 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27List-6221.docdoc 098c2a710a248234e55b49c7fbe94ca4009414120e753e96a1c72647d868ec2cVirustotal results 27.42%Heodo
2020-10-27FILE.docdoc 3e1984dc01f9c26b7add06557c0eb2120f5c61863f8d892d4371b5d54a55b9d1n/aHeodo
2020-10-27rep_2020_10_27.docdoc 315422f610c5a03facbb1b149b5e0e8db64e6d406ae95a6e2143dacbcb29889bn/aHeodo
2020-10-27Mes_BAP7819.docdoc d37e36ccf1d1d6305c792cf1fa6646b2ea51b0caab3d7c9c5b26e852d14c0b89Virustotal results 34.43%Heodo
2020-10-279263084_1528.docdoc 43e4ed5ce8446adf27c4dabef1525678fd5b94b1a0e8893eef1eaba99b3f2411n/aHeodo
2020-10-27FILE-2020_10_27-68778.docdoc cddae4cd8b8c7abc1819ded260b8860c7c1eb39c1cdb57421b29f1b28d190104n/aHeodo
2020-10-27Arc_20201027_086.docdoc c9b48a2eaa1fe1cac12fe4ff2fe7ae9be3436749ce7bc05129e96953bb7b3494Virustotal results 33.33%Heodo
2020-10-27mes-2020_10_27-XE5905.docdoc c0508d0e377a5c387a3dada0c34296054a04be855453eb24e691a79e460acdc8n/a Heodo
2020-10-27Rep-20201027-UWU54855.docdoc 484388d782fd4a5477ed0fc44b40d2d5fd73d0ea7d3088d7c015d2b4ccc5ea93Virustotal results 33.33%Heodo
2020-10-27MES_7552.docdoc 99f180b5f078397a7dc5f8ceaeb590a3f0a3c0563f33ab32e3a552bfcddac010Virustotal results 37.04%Heodo
2020-10-27M75496 2020_10_27 I678618.docdoc 0c343362640a070b75799042abec8925e073822099454ab5dc72b3fb34fad7fcn/a Heodo
2020-10-27list 2020_10_27 XE857.docdoc 21c700f55e87b231a4359fc2b8ac3b24936f38116300921d19643d55ac6066c3n/aHeodo
2020-10-27list_20201027_NTA1921.docdoc 9288feabb7ee47cae3c66d6ed449c22b462d1a3fae77a10b1651c000235fc2a9Virustotal results 31.75%Heodo
2020-10-27mes 2020_10_27 0214016.docdoc 9442de3f723ce250a9d5c7794dd85993c2159b9db4440c3fed759a74ae8ff494n/aHeodo
2020-10-27Arc-2020_10_27-0826.docdoc 15f7895baa80a79efe44219dfc071420b29b2eba96154bc049187e64560e4ee7n/aHeodo
2020-10-27INF-MOY86741.docdoc 6624e99caef62a4448f00037c9fb126ea4442107153d3f09b90996abfea9d753Virustotal results 31.75%Heodo
2020-10-27Arc.docdoc 472f1c85d6885a6a700172ea0bef6ce352480576bd2f1ec3080d27ca534a323en/aHeodo
2020-10-27LIST.docdoc 84677e7ea6e64057f15f0aa4ac719b15747db42d902d4f70e6a350f6f47dbde8Virustotal results 33.33%Heodo
2020-10-27Untitled 973305.docdoc e5dd7fed0fbcf976ea76c910eee78339656cc5393df448efb5996f77ade132a1n/aHeodo
2020-10-27REP 20201027 R4308.docdoc 017ee1b49a436cfb928232681056da0f0270b7931014d28a00cdd4d6638496c8n/aHeodo
2020-10-278138KU 5868246.docdoc 3e69343775695c3fee43ce5bf87ce9273523180185be0d039fd4a837b69eb770n/aHeodo
2020-10-27843.docdoc 820e38a91b3fd262506a0a1e5e644638078c9450f6d825620bd7d3487631efaan/aHeodo
2020-10-27Arc-335.docdoc 64010a9cd4548d4f1dbb52c6e83920053cf5e062fa5ce8b8f69989480acfbf3dn/aHeodo
2020-10-27MES EG387786.docdoc 25e2948ee6dea97044697955af64bb89205f75802bb417e426d6d3ab8dc908dcn/aHeodo
2020-10-27FILE-2020_10_27-711419.docdoc df607299d246c6414a4c92d9bd2fdfc9b0c06496140755eb13d0dc2b1f038f18n/aHeodo
2020-10-2715734428 VOM61927.docdoc 3f213f6d1ba9f50390a64b0165ddfdf5679aa0dca997d9ab358b93e86befde29n/aHeodo
2020-10-27DAT_20201027_X795046.docdoc 1218dae61d7d72bd4387dbe5dba12a8ca87f4fe817fd909dcd856d0384717a72n/aHeodo
2020-10-27LIST_2020_10_27.docdoc ba8769c88b663f9b0c6c929dd205c97e2309d714936a6f17d5e2eb479e8a48c1n/aHeodo
2020-10-27ARC 2020_10_27 K952.docdoc f715e2571cf2bfd37aa823b2ddbe5462575a40ed082e3b039329ce574a2be700n/aHeodo
2020-10-27inf 853.docdoc 9c8e29cf162bd43604573c0a82cc8375a4f728d790c0c5e9c090b23672e5e529n/aHeodo
2020-10-27Arc 20201027 UG582.docdoc b476a22032820fe10208a586bc4a6d4e0cbf3c24aa884da7fa6563758151493dn/aHeodo
2020-10-27Arc-20201027-Z46337.docdoc a1ee5ec6554f80d750ae663858d2f8d930f7b45e562126707d7b6757c69560a5n/aHeodo
2020-10-27UNTITLED_2020_10_27_302193.docdoc 7912010acd05d53592d8cc6439010e92826dfdd3444e7931ef7950d92eb42250Virustotal results 52.83%Heodo
2020-10-27ARC 20201027 UA232937.docdoc c5b2b6d6d926cbb08bb1a896e3b97451b28ece77c39c0896948b761a5f58ee63n/aHeodo
2020-10-27dat-KV075.docdoc 6562c1ec0d60cdfb002adb4ed15dbbf2f2f3f717002fbe8151e35d3755eb4358n/aHeodo
2020-10-27INF.docdoc ba144b2c722855e58aea0bc21aafb2692d8b535dc920fa40677eee2de5baa662Virustotal results 52.63%Heodo
2020-10-27inf_2020_10_27.docdoc a8af91bef70904171bef405f02b5defa05d6b30f158c7ad6360a7436e6b7be3fn/aHeodo
2020-10-27LIST_2020_10_27.docdoc c34b033be6ccec716ff4925ce6e96a65872b23103b659fa24f079d99711963bcVirustotal results 48.15%Heodo
2020-10-27Arc_2020_10_27_212.docdoc 52d4dcd449517b101bb99988f9b270b9785a8987cc4edf558f18fa0bbd5bb438n/aHeodo
2020-10-27file 2020_10_27 TZS3438.docdoc 627c23b11e6048db0ff6e2a44fc9bcd0555c4aedfd31ee768b764b084ecfa5c7Virustotal results 51.85%Heodo
2020-10-27237980-20201027.docdoc 7f3ad8f66409867f25e71e87520c6c5bef13981bf27cab43e285638a3681292bn/aHeodo
2020-10-26ARC_0845244.docdoc 5af94d5b1e905c40d01805e011b493589549f37de4d6eb3e1b68044d47d8988cVirustotal results 41.27%Heodo
2020-10-26696E 2020_10_27 912.docdoc 3ab0e38ba83a5c38bf360f80849f9d1ef5ae83e0be4fdef0a2b71ad76efe4e89Virustotal results 41.27%Heodo
2020-10-26Inf_2020_10_27.docdoc a5f3e8db8097e0528055b569e19bdda01a51fe0e1f03614930c5c428aa0e8b3en/aHeodo
2020-10-26Inf_2020_10_27_IA64671.docdoc bc23d2f73145ee8b7cb2c6599d33dfba5d95c4a49b2f8deab7fd2fe9f2530b9eVirustotal results 40.32% Heodo
2020-10-26UNTITLED-492046.docdoc 9624eca338cef03d8004d874cd0c774bf67ece67290d5a0022da8117345b11c6n/a Heodo
2020-10-26ARC 31913.docdoc 300fe8a8206fc96bf8007311c265ecd86c75124818fc9b9f3424286f106da398Virustotal results 39.68% Heodo
2020-10-26UNTITLED-2020_10_27-Y96208.docdoc e3ad9aea158e55c0fb1ef6c4aaea82873511e899f979de288f615b319eca4b57Virustotal results 40.00%Heodo
2020-10-26DAT-2020_10_27.docdoc 80617da3c346c07e04f87ed19bcc561ea222ebb487366acf0200cb581aea89dbVirustotal results 41.51%Heodo
2020-10-26Rep 2020_10_27.docdoc de04a20487db8ec538e7b52ee91ffc4046e92748e3b3ba2684cf3a807f502d66n/aHeodo
2020-10-26list.docdoc 9cf56a7784e96327856d334a095beb3b92568462ede5fe91ba11b2d2fd4e2443n/a Heodo
2020-10-26File_2020_10_26_ATH629.docdoc 03c21b6bcbe5fa49917ab3be83b2d132ca4fed5fabfe944b25790964442b63e9n/aHeodo
2020-10-26Arc-20201026-X955.docdoc aa98072a6252e4d67b430893acb0b04164844cae9cdff39a527a8b69a8702317Virustotal results 32.76%Heodo
2020-10-26Dat-20201026-0787756.docdoc 58d9b03edf2664b1f5b319b5357772b522b22af59eabc3c9447ca692c617627bVirustotal results 33.96% Heodo
2020-10-26rep 0415.docdoc 60c57e1a1434449e75b4eab42e16151e4cb54879f29e670bf03b01977cbd24a7n/a Heodo
2020-10-26Mes 20201026 RPI98543.docdoc d6d100bf0b55c917208c8e87a038cd89ccc183671077a2e14dc7a377c4831b19n/aHeodo
2020-10-26Dat 20201026 A145.docdoc 6296dd0e0121c62547203df6e7077dc12848b12398fecc65c7fe2e2e6d6ada9fVirustotal results 35.19% Heodo
2020-10-26Arc-20201026.docdoc 494b69d41cfb03a099041f1f8a9b94df29cc109ed9706f41afbdf31b5176a3a4Virustotal results 33.33%Heodo