URLhaus Database

You are currently viewing the URLhaus database entry for https://zaps.co.in/who-will/4zwiuo76pt-419040/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764097
URL: https://zaps.co.in/who-will/4zwiuo76pt-419040/
URL Status:Offline
Host: zaps.co.in
Date added:2020-10-29 07:23:05 UTC
Last online:2020-10-30 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003041563 created on 2020-10-29 07:24:05 UTC)
Takedown time:1 day, 14 hours, 20 minutes Poor (down since 2020-10-30 21:44:28 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29INV_075941.docdoc 2efeab91d822ab76173df70e491b2cd6881d1435186ad6659da73c4e5c5214bfVirustotal results 34.38% Heodo
2020-10-29PO# 10292020.docdoc ee34d9fc3f07a4d4e46927587419c036126144d692c38ded4a9e3ee8dc2d9a57Virustotal results 34.92% Heodo
2020-10-29Copy invoice #07534.docdoc 0cd92885567ce8bea98c6744504811e857d0a19a81b78f73d33623d3999efec1n/a Heodo
2020-10-29INV_5908.docdoc cbce0e0313a3db6fb0061fd2b0872e0735248ffc5e80ca6982ac2400e479e72eVirustotal results 34.38% Heodo
2020-10-29Inv. 516125362.docdoc b620242d81548da725331ab89065055cf2766d259d918733cc3a33c91e309adeVirustotal results 34.92% Heodo
2020-10-29PO# 10292020.docdoc 12a1ded61ef91e5e79c4009234b54a7f4c391d254585bd931987c8289841abb8Virustotal results 34.38% Heodo
2020-10-29Inv_83797.docdoc 739b604f19e74fa2a4c12ca8e77df879b1ea0fbde304cf63d53247285e5f976dVirustotal results 34.38% Heodo
2020-10-29Electronic form.docdoc 0d30a2f25c077dbaa89fd166e0c2e24a2d75900432ab850d5c00dbd826ff759fVirustotal results 34.38% Heodo
2020-10-29Electronic form.docdoc 092adc3e63864e36764ee209d07e652c3b37b55e0f433d9ae5c69a1619a482a5Virustotal results 34.92% Heodo
2020-10-29Form.docdoc 6510c1088251e05cfe18fc22279a7312308f08614ba3dee7852e6b1342e21dd6Virustotal results 32.81% Heodo
2020-10-29Invoice.docdoc 03831f7e2f99729e161730c4980e1c8ebf2276ca7365f7aca5a8d60c9cbf60d1n/a Heodo
2020-10-29Inv. 039727.docdoc b21cdfd6c2639dcbf952b105db8bcc4566643560d411abd27354cdafbb65f8a0Virustotal results 32.81% Heodo
2020-10-29October Invoice.docdoc 1b2de3332921f5fe9e1286ec898140d7d640381face30ec213ea09fbce78b03dn/a Heodo
2020-10-29Electronic form.docdoc 62da1d16914ee7b918b84c1bfd2714584b9f6a979558c8e3c09c779b4b30deeaVirustotal results 31.75% Heodo
2020-10-29form.docdoc 36b7baafc340571b45db974f84dd88f22d49c77fbb2ac2f46ef48b4bb4b4b2f4Virustotal results 28.12% Heodo
2020-10-29Invoice #58087.docdoc 9143453f9dd04d35a094a0332fdc37a1d517cc582db210673a79310a26505e65Virustotal results 28.12% Heodo
2020-10-29DLI-100120 VCLE-102920.docdoc 86dfffd30d29d077cb1a2b881f0cae3c137ba70268ab9726d48444e595f3947bn/a Heodo
2020-10-29Invoice 46323.docdoc 2df17cda9f5ded819514b9060733138dd171d92eba13d68bfa61efa6d39a85bdVirustotal results 29.03% Heodo
2020-10-29Invoice 078475.docdoc f3068382cc295bad25bc7c5ee96d09893b73ed065dd521170ec6c4cc731d6145n/a Heodo
2020-10-29J8367173589TB.docdoc 9c69f6cf8966a5e6349506b4664919c990dcf411ccd38d0748ea6c60dbf3fd8cn/a Heodo
2020-10-29invoice #946837.docdoc 0ff96480062e84aa44e93eb008a5937b1f317e5a0e222198658fb2a71dc4b952Virustotal results 28.12% Heodo
2020-10-29Inv_5967.docdoc e749d0cc03322ca6b682f2bbe8623788c2fb183386a0b43baafe5525fb8d2f13n/a Heodo
2020-10-2902907506.docdoc 02fafe24fe1eab419305d450f7fe2753711cf6b5b8c5013c75c814cfdddb8348Virustotal results 25.00% Heodo
2020-10-29Copy invoice #29779.docdoc 0128b674249cf22f59bed1a918f9c828770abd2dcd93505856fb7596440a2a5fn/a Heodo
2020-10-29Invoice 74193.docdoc d5d190f1fac46b962b459226f25c1e630715a1c7fb4bc14451c56817b4cce25dn/a Heodo
2020-10-29Form.docdoc 7d41847fb131218d629e6bb8132dc6b2b1ce714b4090c01c3f531fa66ad7274aVirustotal results 21.88% Heodo
2020-10-29Electronic form.docdoc 9da8a687183313d2dec4f41ff6c4b5b6fda388b7d8d295b3071df72518fb318eVirustotal results 21.88% Heodo
2020-10-29U005 invoicing.docdoc 56fee4b612e880d994e5c2581806181f3d258b7b6a64094075e2612856d9de8dVirustotal results 22.22% Heodo
2020-10-29October invoice.docdoc 95b4f0a791e9ffefe35972f8c4e1a90c115fe1c8976f779e44b5190d859b3eb0n/a Heodo
2020-10-29INV_06767.docdoc 176d883eced9c465d7391f935cbdb75d425c31d1d0d51771b6c730dee296a8d6Virustotal results 22.22% Heodo
2020-10-29Payment.docdoc 3e84e096f2f889c271504b8dcfb1e9fb78a347087b984a219d7749a8a0839c31Virustotal results 19.35% Heodo
2020-10-29867573240.docdoc df634084d9cb08a06d2e82f00cc3fef1f64efc21da9ebd08ba86b684ee237863Virustotal results 19.05% Heodo
2020-10-29invoices 6995 & 5255.docdoc 36bc0b0a45b7b904804ec1e2efc5349ac69bbdd883633311f3c89eea32884799Virustotal results 19.35% Heodo
2020-10-29October Invoice.docdoc 4cb127ce18e45be83cf16dc026bebd934df33370b60438047d1d63ca5b7ed039n/a Heodo
2020-10-29INV #01472487 FOR PO #277624251.docdoc bf01de28c8cf6dc5958da2bedc45b045e3978c687cc80c399c8fb63407e8562fVirustotal results 19.05% Heodo
2020-10-29PO# 10292020.docdoc 8744e383bf013444ed1f687f385d558ee1c4e2a153cdfe224250a02fd1eada2eVirustotal results 19.05% Heodo