URLhaus Database

You are currently viewing the URLhaus database entry for http://zerohourtransit.com/information-17/4gqekdttfmtg-44/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938308
URL: http://zerohourtransit.com/information-17/4gqekdttfmtg-44/
URL Status:Offline
Host: zerohourtransit.com
Date added:2020-12-22 13:09:05 UTC
Last online:2020-12-25 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU003189237 created on 2020-12-22 13:10:10 UTC)
Takedown time:2 days, 21 hours, 8 minutes Poor (down since 2020-12-25 10:19:06 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-22X4825238615LMP.docdoc a61add91d1ec99ec85463137cdefd5a4f56e2bc5885b00b4fdb840347ed6ab4eVirustotal results 44.44%Heodo
2020-12-22Inv. 6158204855.docdoc 92888947fd26e79a007b4813b402232e8c2d8759a09c4a09df45de70229b9087Virustotal results 46.67% Heodo
2020-12-22Form - Dec 22, 2020.docdoc a0aa13db6c8109cee5544abb9e28e2455ced6b65a3a34f0b1502989fb24a411fVirustotal results 45.16% Heodo
2020-12-227512079-122220.docdoc d54ba8a8a51f5b139f174c012bb6cb5d21135722e679bbb89e7eebc2c20c1988n/a Heodo
2020-12-229310215.docdoc b3f879c4cbb15fbe5903af5dd475917cda8522fa3cceff8bbc9e85a1a7597131Virustotal results 43.55% Heodo
2020-12-22Copy invoice #912452.docdoc 26cc3dc599e7c6668069ec3d25e56886ab7363ddf2d903fc85f62033063c6347Virustotal results 43.55% Heodo
2020-12-22Inv_7971.docdoc fcc999c249edb86e0084722fe062aac095e907ba25fad3a1c9065d23982eca31Virustotal results 44.26% Heodo
2020-12-22Invoice #4597894.docdoc fb888f92c6e162fbffb452a01ed94f8f9913fb0a5ca7c9aa32809b3fec2279d1n/a Heodo
2020-12-22Form.docdoc 489ae3e964dd00af56c633210ed38573d66a17c8e9aa637c2270c21043faaa37n/a Heodo
2020-12-22Electronic form.docdoc 19e8d382a8d268c0daa99c59d6e6a199006770f0a1d51ee76c78332ea48f8bc6n/a Heodo
2020-12-22Invoice.docdoc 0af8cd3d1815a4917fc85beed3d3103472d8044e614b5b7487fd864385a3dba0n/a Heodo
2020-12-22December Invoice.docdoc 0d16cfb714e27c47b5256fd37ac0a0850f012f2b9b2214b67e57dace37502070n/a Heodo
2020-12-22Invoice.docdoc c12da5cf42d129267d61867d8369e7af38212f680f03c3405633303a41e0af9dn/a Heodo
2020-12-22006792.docdoc 63cecc8ed5f6f3e7292c5fe4e4f35d73597715f4e26a01ad574f29238742d1eeVirustotal results 41.27% Heodo
2020-12-22INV #0649 FOR PO #04760786644.docdoc 1c4ed6bb74630c2de7b4c9987378a5fb97a463f1ef6ab2890f14bdbb02b86f2cn/a Heodo
2020-12-2200915113.docdoc 97646fcfc6d6f5312748fe2508b25f5f16fb7f2feaaff9e2cc5383473b6b53a8Virustotal results 36.51% Heodo
2020-12-22Invoice CYEHB5.docdoc a6aac908f0f5c39fe7636ecc8544aefd6990ecd36f8cae361dff6e9cc941d182n/a Heodo
2020-12-229508877-122220.docdoc ee400ceb5719ec55ff700a05ff717638fff1a0b99f8d46092fd7745068de1b04n/aHeodo
2020-12-22Form - Dec 22, 2020.docdoc 6f0424c93e6c63914b8e42fa4acc8d455142344b24c1d31a41deb1c488856fe1Virustotal results 40.00%Heodo
2020-12-226996937723clpU.docdoc fd5a51e050b237a83b90f298193456eceb34ec820cd6540eeb5b67a3ad39196en/a Heodo
2020-12-22INV #0517089 FOR PO #5418723.docdoc 7b4d819e0f671fceb40485a0444e7bfe40d62a505506b46845ca28a88d12e5d3Virustotal results 33.87% Heodo
2020-12-22Invoice #4319.docdoc 99b661d3c47623478333aa3c81af3cff4f16f8898746457711a8fdaba0e535e5Virustotal results 33.33% Heodo