URLhaus Database

You are currently viewing the URLhaus database entry for http://zonadeenvios.com/wp-content/GhbdvlmE11aSbCGTRXB67CLp2EtzuBeUR1Q6uDDBgHkIac4ddgGIUyI4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:759483
URL: http://zonadeenvios.com/wp-content/GhbdvlmE11aSbCGTRXB67CLp2EtzuBeUR1Q6uDDBgHkIac4ddgGIUyI4/
URL Status:Offline
Host: zonadeenvios.com
Date added:2020-10-28 05:35:10 UTC
Last online:2020-11-11 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 05:36:20 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:14 days, 3 hours, 20 minutes Bad (down since 2020-11-11 08:57:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30INF_RSU_100120_OOS_103020.docdoc d9f62ae0da88141e32925b2e9973aab2c0f9cfb72fc3e1d78700263b2fc928d9Virustotal results 31.25%Heodo
2020-10-30dat_167259383761908062.docdoc b3f4e1b87633e71363d9e97c4f845e09d36e833b8d170f184946c8764cfc8f12Virustotal results 30.16%Heodo
2020-10-30List_35416863.docdoc 2bd445000ef12b82a7dbb15a89578a71ad17a82cf8b2f19239fa60afb2ba84f3Virustotal results 26.56%Heodo
2020-10-29file_YTP_100120_YUE_103020.docdoc c8a48cd16e560bb22ad74fe50ff278db8d542241f7ee298dfb9a902614537a3cVirustotal results 26.56%Heodo
2020-10-29ARC_PB5367464339AZ.docdoc 5de82db9541a97ffb820c52c562ee2c3b84430e1cffb0c8a98f70908d2a78c9dVirustotal results 26.56%Heodo
2020-10-29FBVM_KN2311043805HG.docdoc b716fa67c934451161c1be78e1587b3c68a53b5e219dc5452e9ea883d32a274cVirustotal results 27.42%Heodo
2020-10-29Untitled_FJU_100120_YHI_103020.docdoc f4d2f6dbbb53d79cccef95feda58515350e863a1f1522bf60c830c0230754866n/aHeodo
2020-10-29Rep_57862286610.docdoc 77b9310b55e2267372f1458cc4c01a27f95067e8d1dad41137ee348a9dccaa32Virustotal results 28.12%Heodo
2020-10-29LIST_38514851.docdoc 785ca4b8a3e573d7bb977a2f180d8c717b9867bbf38583aa08b4a96fa4803c8dVirustotal results 26.56%Heodo
2020-10-29Attachment_07855248.docdoc 88f7d3cfd21b28cab6cac1289a7b2365e0f18c89f5510713244d083fee7ee769n/aHeodo
2020-10-29inf_BB2094604456TN.docdoc e5ee1bc6b5f6544f1d789848862c6469f2f32c20627bb4e410a1bc21f0005817n/a 
2020-10-29Attachment_PO_10292020EX.docdoc c864f510cfcaca5ca5acb2a8ef66706e173195d47f0bc0956f1757e9f74325d1Virustotal results 32.26%Heodo
2020-10-29Attachments_PO_10292020EX.docdoc 4c38ead6f597c1bccaf5148980c46599eedc2615ee7f3378247b8333718a0afdVirustotal results 31.67%Heodo
2020-10-29doc_18657585.docdoc 0b5277c050ee4714b138f9c9a8f1b1b0a3193f3cadb6d61a5037172d4bd11c54Virustotal results 31.75% 
2020-10-29FILE_ER9546410263ET.docdoc 3cc938a9acddafc3e794e45e9e82d1c24efc3d811739899713c21d96ca510711Virustotal results 31.25%Heodo
2020-10-29Attachment_BKZR3N3Q48.docdoc 16d27526d0453d93110c60d19d8a4680f2ae783858a4ec2093a235fcb819556dVirustotal results 31.75% Heodo
2020-10-29mes_PO_10292020EX.docdoc 542607ccac2f39cec525786fc1e27c06359a30669af200f8cd1974e15680fa73Virustotal results 31.25%Heodo
2020-10-29LIST_PO_10292020EX.docdoc 56116942ba512821e1ff7a7f8ba195977253ba97a25857414a47ef906f41ff4fVirustotal results 32.26%Heodo
2020-10-29file_TUW_100120_QFW_102920.docdoc e5f6a2544bf93cacaf94d5c0c050927a52cd6871dba8c2b7730556978081431bVirustotal results 31.75%Heodo
2020-10-29file_QJ8KSQ5HAF9.docdoc 26116918df27572814521839a1d3ffdb544bc825e81c871aa514890cc6411d44Virustotal results 29.69%Heodo
2020-10-29File_J4NSRUP08EJGNKP.docdoc 44fd0e531f131ec3393dcbb90c1ac8baee6d5c4438afa02d458e67436af9a1b9Virustotal results 28.12%Heodo
2020-10-29LIST_21943771.docdoc e6a7e6b13c6bf9156c51ce46213a68a27ed5da4c01903cc86465ac63c073fd7dVirustotal results 26.98%Heodo
2020-10-29doc_74640194100405861.docdoc 98de74a1b000e840bd188d7a4e35eb9150102a43f8c4fe5357bebae3ad586955Virustotal results 26.56%Heodo
2020-10-29File_IO6026872683DG.docdoc 541fe3cb96d86e7e7acac38913e1f12a0006bb4e07269700b8878279ecb8df5cVirustotal results 25.00%Heodo
2020-10-29ARC_PO_10292020EX.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29UNTITLED_145100424874.docdoc d94ef71ba973986a34d34bc222026baa9954d1849b3fa74a609967ddf8e6af17Virustotal results 27.42%Heodo
2020-10-29rep_UYW_100120_HIB_102920.docdoc 777f2166c1b82de635874052d889fa727eba91067fe544d279a8699a2e89529eVirustotal results 28.57%Heodo
2020-10-29Doc_11688607.docdoc 5db58ed4308eeb76f9c66c885d4f1b53530d6c42eac9d755e67bf41989094087Virustotal results 27.87% Heodo
2020-10-29FILE_90077988.docdoc 405fadefb4061d6af8c5857c120bb843c94b11edd508facc87ddc8c95c45081an/aHeodo
2020-10-29FILE_797634818.docdoc 553bed36f9d70dbc9c4115585166a4fd7543ddbb7cc98f8d3a5b1a41d2ca5369Virustotal results 24.19%Heodo
2020-10-29File_AXP_100120_KLI_102920.docdoc a536a1efba18ff7db257286623904f5d131c7e933b0af1302fec81dfca157b65Virustotal results 22.22%Heodo
2020-10-29FILE_X1E2CZVA.docdoc 3dda8251733c1b96b75d29bcbe3466add36d495368b4b44232fae1dba4a4cec6Virustotal results 20.63%Heodo
2020-10-2952803379.docdoc c56962ccf0f482b04c168639afb894430e7cb71c873faac02d8f3a34107f33a8Virustotal results 20.31%Heodo
2020-10-29Untitled_BJ5ZXMPDUJW.docdoc b3fa2642d482abe33fb06c5480db8883954bb076b663c838f67dc4966b89f71dVirustotal results 21.67%Heodo
2020-10-2945494007.docdoc e631c078dc0639fe8db3a1c45b1e38da8a369c37f69511f6458de6d8809f9732Virustotal results 20.63%Heodo
2020-10-29Attachment_9585499644.docdoc c3c4c3d1a892c0244bc5d4911ad7533990556a3ed4a4561eaaf58379a82b3295n/aHeodo
2020-10-29doc_PO_10292020EX.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119Virustotal results 20.63%Heodo
2020-10-29Arc_UVL17EFA.docdoc 585ab6cc0502c04dedbca9318f5d7d278050dcfbeb477a09e8fee5b66916e38fVirustotal results 42.86%Heodo
2020-10-29list_41152567.docdoc a68e38ba80539aaa99e4624f37df31a53410de47b3a76df0fbced21744a74d0bVirustotal results 40.32%Heodo
2020-10-29File_94677751.docdoc a94691d74d543c82cfb7a293d0de416bec72dbaa2a2776d2ffa9b176b28cc12an/aHeodo
2020-10-29DOC_PO_10292020EX.docdoc 1187f4742f61d0c2db716f1b3322181923c861a7588497af125af7753f409b3fn/aHeodo
2020-10-29UNTITLED_OT6535097695XI.docdoc 6e9c088cbe83fb2b0f6c959df9f72eb6faa3316c7eaf8e1690f590a91e56974fVirustotal results 40.68%Heodo
2020-10-29DOC_UX8350118049AX.docdoc 63df7914667bd2adc0b6e4b2db5b67f07a6154956568765321641b6dc1469cf5n/aHeodo
2020-10-29dat_56834380.docdoc 6df480c2f89e67bd88a1ef3142106f925a45830756da26077582ef439dd4c5b8n/aHeodo
2020-10-29Doc_9YSLJHG2.docdoc 4a64cdcef15cb3314d81486a5c6c1fc590e6579da756365b73c08c8adae77b95n/aHeodo
2020-10-29J_29064480.docdoc 79518084f871542ac83178e1a8d96966d1ac6936c666a19b221c83e25d7c9f89Virustotal results 38.10%Heodo
2020-10-29Dat_KDGCX55D.docdoc 391bfc40b692a1742119596041c13976318ba374a5f74e5e441a2df28ad57fb8n/aHeodo
2020-10-29rep_AG8979509866GW.docdoc 40e1e0d4ba67280ae17c0050feb66bf13f27e271efd4fc91413f8553dcf12a09n/aHeodo
2020-10-29dat_502474980.docdoc 2ce6ab8ee89411f1463ed6831f078e930f121aaa93880728734efa7d25503623n/aHeodo
2020-10-29rep_47815132.docdoc ae5eb8b4425c48ca52483b971f62906afb81dbcd5cd174096ef72b33177236beVirustotal results 38.10%Heodo
2020-10-29REP_70801787.docdoc c353f3d728d9ff052a3ee47d7dd1c5e8bcd8813238a8e20f2f2d0a97fe5bd8e0Virustotal results 38.33%Heodo
2020-10-29Dat_BFL_100120_KJI_102920.docdoc 46e6c0f62d299a4510ce400f90d5f8e2280b0ffa5e465ce7433624327bc07c0bVirustotal results 36.51%Heodo
2020-10-28UNTITLED_V5O6F97N.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28doc_MG9895816510ZQ.docdoc 558f9ea460d8f9e9babcc477c01c40ba377d80607e6dec6640f78b0f12794bd1n/aHeodo
2020-10-28Untitled_PO_10292020EX.docdoc 6e663577a7ba709bc7fb008addc85b8177361cb8fe92f3c79ab88bcecd10783aVirustotal results 24.59%Heodo
2020-10-28LIST_5243127682725.docdoc cb2de094d6518308daefaa75867659fdee298e4a0617b473ce48c4dcdea085den/aHeodo
2020-10-28ARC_C43XISTK99NGD8WU.docdoc ad10b386d964b6056e529c2bdb70ccb19ba21b3b0a59ac606113fedc49626b81Virustotal results 22.58%Heodo
2020-10-2815445487.docdoc f25bd084ce8d81cd2533601965f19c49105798af5fa7465757626b6cd057dd61n/aHeodo
2020-10-28K_PO_10282020EX.docdoc eae43aeb02650178d0fd02ed1c824f36d89c2a2950399621c4a7c29ecb8d7e73Virustotal results 19.05%Heodo
2020-10-28LIST_71522980.docdoc aa5cac23b5ef62c9a3966c4722f8713c7a383ff5bda64d7a684c56e197bbe5dbVirustotal results 17.74%Heodo
2020-10-28FILE_YMU_100120_VGS_102820.docdoc 290d99668c637b392210c43c77b9672357db0df908a2cee8c6c84399c0f3dc55Virustotal results 19.05%Heodo
2020-10-28MES_DG6746648244IA.docdoc ac9272ebdc022c3e93ef6dff217e30a0434094ccb3b6c5ab79cc97a94cf1825dVirustotal results 17.46%Heodo
2020-10-28List_GNC_100120_IYW_102820.docdoc 78344d3e894155b6b6fa65119c449406b1ad08900e1cb58f68d7efba27947084n/aHeodo
2020-10-28MES_ZX6VCBCRVZ5A.docdoc 93d882200983e8ea91da547916ade52e52c5f684c19434eb8e3312b4d4251bb1n/aHeodo
2020-10-28Dat_PO_10282020EX.docdoc 5ce0046c606a280f8d74e5263eaa3e9912f6f232c7508ed71f50e8a4972b47a8n/aHeodo
2020-10-28mes_PO_10282020EX.docdoc ddcf5630aefa8de831c95d68479b3d2b92bae966f6e994b16ff7c9821a227c21n/aHeodo
2020-10-28UNTITLED_BFJ_100120_KUH_102820.docdoc aa825d666a2394dad05c014830cd132ecdbabfe1dcfd7e7eba18ed43bda6de33Virustotal results 17.46%Heodo
2020-10-28Mes_CV2PKLMK8YU.docdoc fda83ece49e1914433f256654dde13a87be6f4a6b03bde2e2060c2ee1cdb815dVirustotal results 25.40%Heodo
2020-10-2810202927.docdoc 302684a1df1b3b6bcf6995798581972d23b71888983b326ff3eed9bbcaf1c56bVirustotal results 23.81%Heodo
2020-10-28Mes_5202909211937845887403.docdoc 0285b11153063e88e38a1f507f0bc7da9d0cd443a93a28f5d029fb201910f212n/aHeodo
2020-10-28file_PO_10282020EX.docdoc 4cc5697403b8d54be43b94e10a6a07b78a0014f2f7da069fac7e7b9ab3506484n/aHeodo
2020-10-28DAT_RM5DGNSKDJG9U.docdoc 53fa42ca6eee828e13b26f79efca50367e1863311520bc82ec6d97b0c7268845Virustotal results 19.35%Heodo
2020-10-28REP_531631447341411.docdoc 558c61e9709e06aa045d7ba7933b35b9fb9c125734e3c4e8955a573a31cba52en/aHeodo
2020-10-28File_VWH_100120_FPK_102820.docdoc ae264639594117f77da175c96741827cc7ecee91be8eeb65c10f207c26a2e800Virustotal results 17.46%Heodo
2020-10-28FILE_97869354595.docdoc a2a1fb0e34755eda063fd82d7fe452eb979f87b8cf484cd8fa59a45df5adb29dn/aHeodo
2020-10-28PO_10282020EX.docdoc 0843e95e73e1d9c719d84439a7243f080d431179cc900f1d3744cadcb2d19d38Virustotal results 18.33%Heodo
2020-10-28LIST_78141588.docdoc 6f09e12af88b8c2ae45c021409c707ca0afc0b65be38c119d8a7ecaa72355ac7Virustotal results 17.74%Heodo
2020-10-28Mes_317634919971041232.docdoc 7c5cba3f361edbd305005728464aa36e44d98db05cc52860a979780b6036fac6n/aHeodo
2020-10-28ARC_JC2354328739FX.docdoc 0baa66a446892d388453495c26ee71f8be5dadb844ad77c000f2c4de90976b7cn/aHeodo
2020-10-28Rep_PO_10282020EX.docdoc 852d88f248a132193134baba17eb75649f9aab9cb04fc39652d337149c5dfd87n/aHeodo
2020-10-28Inf_3FL288M99ZN.docdoc 3f02da0066fc5957eca4a61f1f5e7a8c53804190c4709ae8fe273eb6508561b8n/aHeodo
2020-10-28Rep_LUA_100120_ECJ_102820.docdoc b2a8f6bc160f4536d6be6a9e5ef41244a96a2bf0de49f9d088c5d68853f2d69dn/aHeodo
2020-10-28JHB_100120_TEV_102820.docdoc ada1b895d8a1af1461e0b32f2366bef386fa6b6d3235cf99f9838896ba16d2b5n/aHeodo
2020-10-28LIST_YBWL5JS.docdoc b2fd50c9b74180bf57162267feec075ce16b9d37ead25cca5f97840e44e61a1eVirustotal results 27.87%Heodo
2020-10-28H_63709002.docdoc b749fa9443216bb372f3a786fe6f921aaf83800f69c46eec065ad8b2bfb0ad89n/aHeodo
2020-10-28file_PO_10282020EX.docdoc a8d759c3b4c570d5c7d196edd616d1816f0bf51f7d858bbbdcf8bb41f85242e9n/aHeodo
2020-10-28Attachments_4TGKE1FRO6CUQ.docdoc 16b04fec1fdcdf3e7cd7b256ab6d5eb83277fc58d66fbea24c54202ce5fcd96dVirustotal results 28.57%Heodo
2020-10-28FILE_JB0455879667GW.docdoc 9ef4f6f51b375bbf59cc1d992a0be8455a3a9c3a026b28c4abe77a4f16805c50Virustotal results 28.57%Heodo
2020-10-28arc_DNJMZSGW24.docdoc 09bb49f2d31787be18b07e1a48fce7bd5bf1dba73e713ce8727645f0b8f740d2Virustotal results 28.57%Heodo
2020-10-28SKJ_100120_UQV_102820.docdoc 06472f9f7853e0506b85ea1db0bb693aacedee79ad413c1ca0839a322f834df8n/aHeodo
2020-10-28doc_PO_10282020EX.docdoc 43f4b38dc2240818e174dc1351b7e7237a95f782d2f39578ed29bae1a18cf373Virustotal results 31.48%Heodo
2020-10-28DAT_06120772.docdoc 4da551741b2fdd1985b8f8dd865cbc2ee100a8d82d80a39e33f56dbda25b4f1en/aHeodo
2020-10-28inf_TE2073873564IJ.docdoc e2f58ed91009de4f156ecdfb6fb04401ce82b2281242941e3a80fa9fe451cfcdn/aHeodo
2020-10-28file_BQ8363588549PJ.docdoc 69d342710f557d68f3efba1b4e44414efb43af9868dd7953f88bf8b49522456fn/aHeodo
2020-10-28M_VPF_100120_QVW_102820.docdoc b10f4a4b46a88d8bd137cb2d76eb827b89f16acd953490d55b6161aa0e99b7aan/aHeodo
2020-10-28Mes_F4FZ14OU7.docdoc 261e6c84ce868f22052861a43fcad286e7287b5be573074c5f3ced42e465d4ccn/aHeodo
2020-10-28Untitled_3625191541162166772604724.docdoc 9c509bf6c3b7824436cb299b2efffd013f3b0b156e9398a6975b71b50152cac3n/aHeodo
2020-10-28ARC_HI7333108703JY.docdoc a74bd9bb59caf16dcb34bc909644f9b39712ff04e230af2fd8f4838af00e85f8n/aHeodo