URLhaus Database

You are currently viewing the URLhaus database entry for https://zastreamtv.co.za/cgi-bin/3HVEgR6G4j5E1ULJsAwPKLoTwi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:769270
URL: https://zastreamtv.co.za/cgi-bin/3HVEgR6G4j5E1ULJsAwPKLoTwi/
URL Status:Offline
Host: zastreamtv.co.za
Date added:2020-10-30 12:18:07 UTC
Last online:2020-11-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 12:20:17 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:4 days, 5 hours, 54 minutes Bad (down since 2020-11-03 18:14:38 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-31DAT_JGS1QUV1FEOUTUX.docdoc 858159295a83a85ce85a8e18a4398873eb02dfa32012325f963ab2de57c8c0aaVirustotal results 56.25%Heodo
2020-10-31DOC_WT8P88OERV022R.docdoc 4bab596233b6ee4131996d95b9d863e6833d285d6f87dd2bd841f2682b6146a3n/aHeodo
2020-10-31INF_75144995.docdoc 396b664fbdde301d1ebedd54f4beacf4726ef9fe1d0807a86fe0b00e0a71772dn/aHeodo
2020-10-31FILE_3109694941.docdoc c0e896c6e7521d6431ca692ef69c30c605ab7e599336d9c027721e573d1b2161Virustotal results 58.73%Heodo
2020-10-31mes_PO_10312020EX.docdoc 2cb36ff671181007c49a60cbbafe936340f4465bc46d3451c5ad6cb8086a4ebaVirustotal results 51.56%Heodo
2020-10-31UNTITLED_02147496.docdoc ad6530753d959ec1d3305730db8985d3f0fdf9e9ce893c2f8bd8873ab51f8fdcVirustotal results 52.46%Heodo
2020-10-31INF_UU9125757838TR.docdoc 289f8b4babc8f697bcbc3125ded9cfddefa96b986243538034beda8361d69a26Virustotal results 26.23%Heodo
2020-10-31mes_329215255161636740.docdoc 5f41c6d26db569d644da86fdc71dd2448e2850998f476944b09e1338411210f8Virustotal results 53.12%Heodo
2020-10-31file_PO_10312020EX.docdoc d7c0fc3658da4a6040cab7aff29764849e26c699642492446759314c94586b6dVirustotal results 26.98%Heodo
2020-10-31X_EQT2S8I5A5.docdoc 0406910d3c48dbd18d57086dcab9b4f73a8081dae9fac3010f0ae90b73c7c34fVirustotal results 54.69%Heodo
2020-10-31DAT_IV1475878894FP.docdoc 41c1aacf38f4e4b127131377357db324852107ff972122bb57ec3ba8f894a7bdVirustotal results 53.12%Heodo
2020-10-31INF_PO_10312020EX.docdoc 665ca5b6b8e24008d94bd73e8fc3862a558d2074f35ab952eb016e2ecfb2c125Virustotal results 26.56%Heodo
2020-10-31DAT_PO_10312020EX.docdoc 4eabd4dcb81c28e86bbfd9ac62090d51aea5a733c96a8f3a7ad130a9841bce71Virustotal results 54.69%Heodo
2020-10-31List_76340336.docdoc 26b30e58ed2342d042367ba0487873439d5c9c28920ddd000bb94b3eac79d94dVirustotal results 54.69%Heodo
2020-10-30file_FVQAHDEHA9QKHVJH.docdoc 66f30f7d40ef0e230f042cd6abe51971e49af52617515c3d0d99f3f365a59e90Virustotal results 25.00%Heodo
2020-10-30UNTITLED_MDZ_100120_SPT_103120.docdoc 14a8572928770f8d61fa05890c3e0a5cd4396bfde2ce2763d533e89d05120d34Virustotal results 25.00%Heodo
2020-10-30O_PO_10312020EX.docdoc 22a4eae8735782a3f12e3f7ee5b6d0839cd7c4a8b91dce6ce27e2414b2e5f817Virustotal results 51.56%Heodo
2020-10-30Untitled_PO_10312020EX.docdoc 49931e499615a1dc36cda98151d3c406413f1c47504b38f2bb658631313c273fVirustotal results 54.69%Heodo
2020-10-30EEX_PO_10312020EX.docdoc 5041a2eae4b04f23df9804031b3a30e815e0c2310bf42d82176cb89618617933Virustotal results 55.56%Heodo
2020-10-30DAT_KG14RRGHN.docdoc cc0614f4e21c1d63a80e1ddecfd591353e15aa849f754be9d8b709cc6e9841c9Virustotal results 53.12%Heodo
2020-10-30doc_22379787.docdoc e37545649e9e7c9250af64a93a2fa3e37fd90ab7f9c16e96b4469290f309b52bVirustotal results 23.81%Heodo
2020-10-30Attachment_IP4095785739MY.docdoc f7cd964fb73ef51565181df0b0bdc561fe166542fc297684546797abcbc24000Virustotal results 23.44%Heodo
2020-10-30Attachment_HUR_100120_CYR_103020.docdoc 75ca20340c21dbd94ba3ec4c8eeb14f3a78e68a955701cbdc754c29163674a3aVirustotal results 33.87%Heodo
2020-10-30File_39559321488862097444.docdoc 894961b5cd902ae1bd280ad4d906f510e47f2d02fba5fc278823a37eabedcc7fVirustotal results 33.33%Heodo
2020-10-30UNTITLED_77321315.docdoc 5fc665986d6e0e5763554e4d9f9db9ccc61b2c20fc408e955d286a458f622f48Virustotal results 47.62%Heodo
2020-10-30UNTITLED_PO_10302020EX.docdoc 1b230d33228fd383eaf4cc6faa376c0173fb8ff8d70c42dc9ab1ee5eacb411den/aHeodo
2020-10-30Doc_Q7EJBUM7T3GL.docdoc 023fdae311195c64889d2c87831a470d7c4826a755cd385729dc6bb02281c4e5n/aHeodo
2020-10-30file_NY3466742632JA.docdoc f49b970c0f5c5e742a76964f8ac3473e2b6a8558589d75cb54c5f7978178af16Virustotal results 42.19%Heodo
2020-10-30Inf_342959413877336111267.docdoc 99058ee5998a7ba4c31c25cfb2a68cafa37ae8deb724a8c4939e84f9d7d574cbVirustotal results 42.19%Heodo
2020-10-30Attachment_PO_10302020EX.docdoc c3a3c4b5fe05e1cabea15022173fa5a6f9fb05c83f0cb2d70441f0d415fb9405n/aHeodo
2020-10-30DAT_FWC_100120_EEG_103020.docdoc 13d14b40f01d08656e74e969635a6cc3da85d7e7561d122d76d2e7f6a7b8960en/aHeodo
2020-10-30File_MGXP8ABW.docdoc be0b7b1655cf76359f685b7367592ccbacace133e9a4b1180b5dd7c364d6be29Virustotal results 42.19%Heodo
2020-10-30Doc_XV4247150311AM.docdoc 2c35c7c2a35e6c0d057d6a29697d6caeab76363a0040219edbed385309cb15f6Virustotal results 42.19%Heodo
2020-10-30REP_RGD_100120_BLL_103020.docdoc 6df2d95c19b3ce313cebc624934a89b12d1825460eede986255006aa3ad36e17n/aHeodo
2020-10-30dat_YBPJ0654N.docdoc d6f5c2f6c473a5df7285cae32d8806ee2c6ee513400416463c34c7f6b3dcc703Virustotal results 42.19%Heodo
2020-10-30MES_EU3713022624HD.docdoc 17d5bfb8d831eb1b5f2defabb4f6b29c2c2f65bc90c0b310d7e0867ac11c125fn/aHeodo
2020-10-30Mes_JE7703665587QR.docdoc 21d510dc43e2e064f6d94e3b502c483eb6fc1171828a5349dd22c43ccba66638Virustotal results 43.33%Heodo
2020-10-30doc_03402190.docdoc 6270902fc810af901f9685bb0b3251f8cf96445514e9bd288b51d51156701665Virustotal results 25.40%Heodo
2020-10-30Inf_24209154914768117786335.docdoc 72cbfce2d1bb68f6583a651975d64056490779254d19bbf18636a754d88688c3n/aHeodo
2020-10-30REP_7158648216953278707197145.docdoc b104e5360f8f17268449e97ba36749b921cf7cdd797fdb8a28ffe20d8d9c59e4n/aHeodo