URLhaus Database

You are currently viewing the URLhaus database entry for https://zion-polch.de/wp-content/FNFCAWCWA/uEQlVWJFN3On6LjTFs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762088
URL: https://zion-polch.de/wp-content/FNFCAWCWA/uEQlVWJFN3On6LjTFs/
URL Status:Offline
Host: zion-polch.de
Date added:2020-10-28 18:54:04 UTC
Last online:2020-10-29 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 18:56:15 UTC to abuse{at}hetzner[dot]com)
Takedown time:12 hours, 50 minutes Good (down since 2020-10-29 07:46:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Attachments_BX804101.docdoc 804d8a73caefdbeb69c3939a8a01531db4e813e85b3db18efd2e87cd58c132f0n/aHeodo
2020-10-29BEZ20775-2020_10_29-6619686.docdoc 8b60926cf9d5804b5b4c7900d12d19836729d506ea04601e39c1d72ef37eb703Virustotal results 15.87%Heodo
2020-10-29605 20201029 ZB00704.docdoc 2459f003d4b784c960c6fbf68be74cdd02277d11ded9f0a6be0f969c3061d54dVirustotal results 39.34%Heodo
2020-10-29Untitled_2020_10_29_19772.docdoc 5b3616526c1b12e0827b2566e2d6db0df97c7629c9e1dc92efc5b66e348c1b77n/aHeodo
2020-10-29DAT_2020_10_29_66293.docdoc 71bc58101436a711833b7d8478b9481b6353079f89c0ff4b11760a64e6456afcVirustotal results 38.10%Heodo
2020-10-29List 20201029 U0620.docdoc 579fc26628f7ca7ec4e9eba537765755680cd5efd646becf39e12c1533b60fb6Virustotal results 35.48%Heodo
2020-10-29DAT_C14670.docdoc 6838da271d0d1b3e87290168d3717f5b627a6021ececd73b0408522c0f5f3aaan/aHeodo
2020-10-29Dat_20201029_GJ7457.docdoc 29069c8ef4147aa42ee5cc01d2dcc4f0a5dd6d8116c4122852845a08f2e5fea2Virustotal results 35.48%Heodo
2020-10-29doc-20201029-47780.docdoc b9275b6099be967ff38eaab7ab232ce6ec1f903fc98fda4de1f2c057d3f85f70n/aHeodo
2020-10-29File_P987.docdoc b213e87540cb4152478d07f8211e8c5210925f974e403ec713ce5e5f9f4eadf1n/a Heodo
2020-10-29443403 2020_10_29 M15287.docdoc 192e7f20388641538ab4e7e243d6c81dfd520107bc8854005b2096b31981a624n/aHeodo
2020-10-29LIST-20201029-80039.docdoc 772b14f20e166cb1f21d538a8d1dd0c81dc22a2907ca07f299a1c90053c25d5eVirustotal results 34.92%Heodo
2020-10-29Arc_20201029.docdoc f93b2244f0e3fc1dd8ad428bea4ce02820a32d5a444eb2d4848f150252dc7daan/aHeodo
2020-10-29Untitled 20201029 JW58526.docdoc 99db7a0e3b100982f31ffee540f8fd2418200a74e24ae05dcbbd1974be87525en/aHeodo
2020-10-29ARC_20201029_591814.docdoc 01832091bf1c1ecee3623274c0a9d173d305fb1b0f1059cafa86eab41961f498n/aHeodo
2020-10-29UNTITLED-20201029-05404.docdoc 131c6bd5dfe6fa22b22ee9a089ef38bcbf255dfd62f14fd565acc4c2c65f5b85n/aHeodo
2020-10-29REP 20201029 5506.docdoc 754b3e1caf1ff6a8d35d59b3ba921a8ac224f6118520865d02140c0277724a73Virustotal results 28.81%Heodo
2020-10-29Attachment-2020_10_29-1257257.docdoc 947359baeda91df2475d551cd36248ccbc371bfab378fba634176d4fe1bc46c6n/aHeodo
2020-10-29LIST 20201029 153.docdoc 1057624fd741f170fc4a05bb538ab9a3d863abf1ca31d713b1d13cd57a03e8c4n/aHeodo
2020-10-29file_2020_10_29_DIU878.docdoc 697d945ff47046f421017a4ececab19494f8ec8b9d59abc54fd159fdaf1bfcafVirustotal results 25.40%Heodo
2020-10-29Doc O827.docdoc f8b55420ef4b3052e8b71f5a228e16219e3f6372d19e8c3e175e8fac7482824en/aHeodo
2020-10-29list_DK128735.docdoc f49637e7159ed3b8f29519c003193985c2d5de0638a9386d637a2e62a8910160n/aHeodo
2020-10-28Arc_R85040.docdoc d465b5e81ff8cc58d781ba58f2359e6668797d044d4f6144ebd5f738331e402eVirustotal results 24.19%Heodo
2020-10-28FILE-2020_10_29.docdoc 1d63cfd4eadc52c7da496f80f53327a27c43bd1eb9c1cb5143231d6b287ec934Virustotal results 25.81%Heodo
2020-10-28Rep_20201029_5376.docdoc 48a76d85d2eb93ee3fa58f3b1ef6a80e17e824cef265353c9cb804874809063aVirustotal results 25.40%Heodo
2020-10-28mes_20201029_02583.docdoc c47e2824a0c7956c6d3e86bc3b599b19f2eb9c2136949bda71de8e4a5009b49dn/aHeodo
2020-10-28MES-20201029.docdoc 0141fc68f8d61f3c6ab01420927eb224eb83af6d701944e66d37f19898cf1b4eVirustotal results 24.19%Heodo
2020-10-28113B 84892.docdoc ad77961c7d3cd0062a947a3bab02b1d85b657b86966dfda37d57926a3a004cf6n/aHeodo
2020-10-28list_K897257.docdoc 76029e7fcd2020aae7857b746d85ce4b9e91d196221d3b731060c7908f45bdd5n/aHeodo
2020-10-28Doc.docdoc 63e7ee325c79ea137e6cf1af5f7b56ef6767d20edf1d67283a46f0ec1dac902dn/aHeodo
2020-10-28doc 695881.docdoc e9b125831f9c4c65be0d9f2f69841b1e6f31ce194faa59bd32c929e775f0bdcdn/aHeodo
2020-10-2833929-2020_10_28-1716606.docdoc bd17ceae08c87f45c042d5893ecd4547b333d49f07e732df28e2000b4b52c46bn/aHeodo
2020-10-28Untitled-2020_10_28-N095.docdoc 8f43c8b43810e2ccbb80a555c115fbc81e758e2b687ab205b92ea93bb0544a51n/aHeodo
2020-10-28doc 2020_10_28 33593.docdoc 390ed8e89795b54ef9057527e8d1c53b76155fb2299146e1d42364ee2de62aadn/aHeodo
2020-10-28ARC-2020_10_28.docdoc a7334e4015384352c5f89b54b06a5599ddd4c8cb3e5ebb2ba08dd15a5f68c5b4n/aHeodo
2020-10-28Inf-20201028-FAM791.docdoc 0b4686326341aa6170756e22822c138bc6d813412182af4238dd97fc39ea37acn/aHeodo