URLhaus Database

You are currently viewing the URLhaus database entry for http://zebaorganics.com/wp-admin/en-US/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:936573
URL: http://zebaorganics.com/wp-admin/en-US/
URL Status:Offline
Host: zebaorganics.com
Date added:2020-12-21 23:25:06 UTC
Last online:2020-12-22 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-21 23:26:04 UTC to report-abuse{at}coloaz[dot]com)
Takedown time:5 hours, 23 minutes Good (down since 2020-12-22 04:49:22 UTC)
Tags:dll emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-222ja2Bv9tyxjxtq3Up82.dlldll aa56f22197570b9e19e40d336403b3d3dd1768c5e534523a70d44ba6cca61bceVirustotal results 34.29% Heodo
2020-12-229PTmsMpo5oR.dlldll 9656bbc2e82c73bdfe2e1f930b305ab94fd011148c40544a59c434c5c6f2a1c5n/a Heodo
2020-12-22ThWkmnwaFn1le0X1sTt.dlldll 81af628ef10e5a4b8945eea0fc1efa802d79d0f27a95a1471a6662258880149cn/a Heodo
2020-12-2264RgEc4fB3qt7.dlldll 5d544a3cb0d7435388be26c38d8f2a21bb49019e08ffeb050c992edb6f0eee00n/a Heodo
2020-12-228BZUZzgls250wpkn7y.dlldll 5769bee34642c473a283fdf7cb6f014bf1b95029a921bc6e28b6d6fd17112aa4n/a Heodo
2020-12-22pgJUo3.dlldll db2614f5b99f3d79e7030de16fa7b5356979d493ae86a7cd193027a2e5f8590dn/a Heodo
2020-12-22LiX.dlldll ee32e326912bc15f7671cc0fbde8b001ec0df58a8e0408f7ba2959b29eebed68n/a Heodo
2020-12-22KtPcT.dlldll d7a0a30ed8053dca098c2496f468b4c154bcb2b13a679bcd8c047c36984e1804n/a Heodo
2020-12-226WWPODSvPAHl1.dlldll a6a709f7d6a5caa276fb70de2fc7011b95ccf070ecc1451941de5fb2f6a445d4n/a Heodo
2020-12-22AdKH2ygPBQ.dlldll e44908282bce8842bc4af8abd4ced81bb9655b233e5b2073fc35020f2e03a234n/a Heodo
2020-12-22RBZiUQ.dlldll d14467857340f7c1c7fc56da56672d8c848a506c9274bd208f50546448eca4d5n/a Heodo
2020-12-22Kwc4hKP.dlldll 6ad2a681daef6cb3561d434afa8ee6d96dffa1af2fd5d4e1b9d6f0474d346a48n/aHeodo
2020-12-21BdCt6NFHPkQgraS6D2.dlldll ad47cc5bb2191793ab9a78fd897655fcdf8682c90c016504c41ae0ef7ad4803cn/a Heodo
2020-12-21ltdv.dlldll b732cab1158a740c9df02ee36c7d545cf034ad74d167f91a2eda27eef3a18d6an/a Heodo