URLhaus Database

You are currently viewing the URLhaus database entry for https://zodiac-casino.co.nz/wp-content/parts_service/yJbJbfysD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761657
URL: https://zodiac-casino.co.nz/wp-content/parts_service/yJbJbfysD/
URL Status:Offline
Host: zodiac-casino.co.nz
Date added:2020-10-28 16:42:04 UTC
Last online:2020-10-28 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 16:44:02 UTC to abuse{at}eukhost[dot]com)
Takedown time:3 hours, 58 minutes Good (down since 2020-10-28 20:42:33 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28Z6268704857YO.docdoc 3b31e20a19f924917aea1e08d62b46e74ecf47777ab81e3843195449c1ceb80dVirustotal results 20.97% Heodo
2020-10-28GC-100120 FPIK-102820.docdoc 0402eac76e97d2bc47ed688412a18594674b7e981d4307bbe0b8491d8ba0268cn/a Heodo
2020-10-28Payment status.docdoc 661694d6fc62c1af16ddbe2db10c54b471f5acb387cde760666a6a672635f16dVirustotal results 17.46% Heodo
2020-10-28invoice.docdoc d1f0145ea0d4e036edd208387b5c7c012b0eec91562b6f210853152462b2ff63Virustotal results 17.74% Heodo
2020-10-28Invoice.docdoc 3e784298291a432cc1c053b0a50d2245977718a7f16e344559d0952260c96049Virustotal results 17.46% Heodo
2020-10-280972199.docdoc c6d94cabee4abe9dc14f1ccdfcec3f631453b9e19046806554808e77ddda2cf1Virustotal results 17.46%Heodo
2020-10-28Y-100120 YHER-102820.docdoc 448eabf56cc654711f7a3a6005be397a5aeda5ba6f329742da01cf7d31712931n/a Heodo
2020-10-28Payment.docdoc 3732182a2ad2854b3f9ae9a1eeaaec7d53eb43bbc485318ae0a2f573a0159b0cVirustotal results 16.39% Heodo
2020-10-28Copy invoice #9484.docdoc abc441e8e79d4bbbc2cad82c9c8640e5556dfa439a39b965716dd1cbef7e2ac6n/a Heodo
2020-10-28invoices 7059 & 1762.docdoc b251dae8df2d623a2a0e9d710e34ed18d85891d8120725c2c7cd794c094950ccVirustotal results 17.74% Heodo
2020-10-28INV_471101.docdoc 2d02f7d64430a41c50eaaed46dce33dcc544dc0d4904fd4561e8ebd851447952n/a Heodo