URLhaus Database

You are currently viewing the URLhaus database entry for http://portal.zastextiles.com/processing/HhNxCNkpaJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:754134
URL: http://portal.zastextiles.com/processing/HhNxCNkpaJ/
URL Status:Offline
Host: portal.zastextiles.com
Date added:2020-10-27 01:51:04 UTC
Last online:2020-10-28 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003036421 created on 2020-10-27 01:52:05 UTC)
Takedown time:1 day, 10 hours, 18 minutes Poor (down since 2020-10-28 12:10:39 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27INF_TW7E3MIF5ZU84G.docdoc bb8010402e5f009f29886cf28e720b447bbc5d467a89ca4817d6492f70e2439cVirustotal results 33.87%Heodo
2020-10-27JC8605802837DI.docdoc dfba0c0279ce312703161fc36a706210611ed837313ae97396607890e243f668Virustotal results 32.26%Heodo
2020-10-27Arc_70649576106717.docdoc c2f163720f0e6e06b3b33b5477481a4789df1991bf3ef3c5e8eb3c3580176e65Virustotal results 37.04%Heodo
2020-10-27File_6Z5U8E0H5W.docdoc 56c2cef0eede6803ac93b690989ddfe5728039f73ee3f2667128ff8812054a6an/aHeodo
2020-10-27DAT_LQ9716857170JP.docdoc ec989ed848ce15ff9c215928fb9f5687e944c2cc6ff3aed355a40aed4da88099Virustotal results 33.87%Heodo
2020-10-27UNTITLED_YI9911409364AM.docdoc f08dcbd662346509dda32a750aef30760483bb319be71138d1973e4b3e98c98en/aHeodo
2020-10-27Untitled_Z0H1JKXP1.docdoc df6ec075b661ca498939b6b15933fe4822e9e1540863133b43a606b14f2f1f76Virustotal results 32.26%Heodo
2020-10-27INF_PO_10272020EX.docdoc 568a352a99c7d13f8738d6cda1e312b1d7788cf46a1b392755bf34ddcdea64dbVirustotal results 31.15%Heodo
2020-10-27Rep_IN4823785907CA.docdoc e4527d560cd4686420f59af761956425e12c91652dd75544c29db4c730095ce2n/aHeodo
2020-10-27FILE_EC7922148256EB.docdoc 26e945530a8377fbe94678c56d4d2cc60c824c2ace12663ae21976d3780acdfcVirustotal results 36.51%Heodo
2020-10-27Mes_M2Z4GT094X.docdoc e76793fb9b8a242cfa95dc549c57e5d3887843aa25b6c235e4fcf59ebf1fac2cn/a Heodo
2020-10-27UNTITLED_3469H9HUJRR5TN.docdoc a5e4a9fcc63018129ac55cce97da596cf2679d24ba2d6e953a11c1d9d7473ca5n/aHeodo
2020-10-27L_44182462.docdoc 2c1771765e8e21c4067b414eff7986d87694fe6fcddb8f1d708213de0ae9f827Virustotal results 32.26%Heodo
2020-10-27ARC_707381548795236080201.docdoc b817324c74ae71603ddf1c22270df083b0a64f7215824373c59e30fd6cddd0f1n/aHeodo
2020-10-27List_MVV_100120_FKJ_102720.docdoc 67bd10eec5edc05a357c8b7feaf5f56446cf27fd1ff17d30da3afb170199adcdn/aHeodo
2020-10-27DAT_LQY_100120_ZGS_102720.docdoc 4d55ddffa3d513e115000683cfa2fb1e2b738298d58e3b6dfaa8f66feb1351dcn/aHeodo
2020-10-27REP_YCP_100120_BLS_102720.docdoc 99dcbef73f8e02416896cdc9204b4ee7249131cea8de9baae8bd7f40985c7d5bVirustotal results 31.75%Heodo
2020-10-27FILE_K2CGFHRJ.docdoc 3d3018783ee56f8fe4b38d613ee7b96aa6424bdf12d3bd7c3dc618c6bb38dcdan/aHeodo
2020-10-2755678582.docdoc 115c98911b958fcf8e3c9300eca7763548205c8fade900f66be4d241ed54c99fVirustotal results 31.75%Heodo
2020-10-27file_AKK1FUIQ.docdoc 24766703c0713e30ba3b3667a3e220f3d909b86f5566ca06a66f97a7f181715cVirustotal results 35.19%Heodo
2020-10-27NZ0890346675QV.docdoc cd0b23d03029fe913a9d2f52d14b0703f4a6f6a4cbda6744a455fca3373d3ca2Virustotal results 35.19%Heodo
2020-10-27C_02004124.docdoc 0bce545acd6f37453246cb2ce9c6ef9e85b7c6c02676fed1a2bfd42934be9c03Virustotal results 40.74%Heodo
2020-10-276165886875254292245562719.docdoc 58dd20d9c3e38a8115434572a1975f207290cb2340b203ffaa6d3b08fa95da9fVirustotal results 38.71%Heodo
2020-10-27REP_8744190375.docdoc 73d86e2272fd2354897cf0ffea6273f56a56597f4a57587b435ac22f672208d0Virustotal results 40.00%Heodo
2020-10-27REP_BA8093604411GV.docdoc 5427634467eebd0455fc0de71aff6b4e3e2e35e5e8e1633d567fd18654a1c532Virustotal results 40.32%Heodo
2020-10-27LNIUQ7IPM1GOY.docdoc cca9d247d6b6a9a8ddf13e33a1bb5b362ec0a59dc1ce159ef274af49a40d5b9fVirustotal results 41.27%Heodo
2020-10-27J_80411819.docdoc 6f039a653dd4edef8c16347acc26f36a9b283bdeb9c8fb6ce48faabd9f67f5e2Virustotal results 43.14%Heodo
2020-10-27T_PO_10272020EX.docdoc 6f8789d6d5e2019e7ace4e5a165ab487c2bb1b99164c1b8a7c6f4d49187c4a05Virustotal results 39.62%Heodo
2020-10-27DOC_9IB5J6P0A37ATHD.docdoc bf04be287615bd3af69a5f056b49c8022660833f42e354c39c808061f1b2b7fcVirustotal results 38.89%Heodo
2020-10-27SL7003720079EU.docdoc 56672b95281d04830b996e84df9edadf1be30650c9e410f25dd4596927d71d7bVirustotal results 39.62%Heodo
2020-10-2787057A9TY4BSP78.docdoc f83783eda067f6e1b71d589e230f6aa844b2410c42ce2f20a60f9b32960852a6Virustotal results 38.10%Heodo
2020-10-27FILE_RW2964720938TH.docdoc e8caccd0e30b68aa3a338537f9164503821ec1089daf287db3acf97ec74e59f3Virustotal results 38.10%Heodo
2020-10-27REP_PO_10272020EX.docdoc 9984eddfbc2dd95122946859d15907841ecc6834d8a87869837cd309180f03d4Virustotal results 38.33%Heodo
2020-10-27Z_1208504365.docdoc ebfca25ac5a8d600e73ba0523100c430e2b6072247e42a91c12ba2e1d718c4f4Virustotal results 39.62%Heodo
2020-10-27LCDF6KEF10AX.docdoc bef2cf86acbba45a17385614351f915491d344ba1d20e5936379853d0eb2b0a7n/aHeodo