URLhaus Database

You are currently viewing the URLhaus database entry for http://mzeeholidays.com/En/xerox/FtNOp-Ob_hCjDXgekw-CFL/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:115541
URL: http://mzeeholidays.com/En/xerox/FtNOp-Ob_hCjDXgekw-CFL/
URL Status:Offline
Host: mzeeholidays.com
Date added:2019-02-01 20:03:24 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Status unknown
AdGuard :Not blocked
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2019-02-01 20:04:07 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:9 hours, 50 minutes Good (down since 2019-02-02 05:54:28 UTC)
Tags:emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-02-02SYE8248438479041.docdoc 4fd2ddba5d78c3be4e71585d2b8c36fc3c01932ddcbfc3095503d97d0433e66dVirustotal results 27.59%
2019-02-029750110619115595.docdoc 3aefb08f8a793edb6bade9308f84c6a2802fcdbca6e59030262b9af0564d6a9dVirustotal results 25.86%Heodo
2019-02-0247211072191971918.docdoc c893d80dd6ff0fefc7fde2336b40e3937c99d00ece19727a084303fe048622e3Virustotal results 30.00%Heodo
2019-02-02PAY04248305307067.docdoc e9b2f6895133860fc929b822c7cb78d5ee9c97ec937f16a22390fd357481a5b1Virustotal results 30.00%Heodo
2019-02-02758573796.docdoc f38bc2d9e57a7c95fd7bada2f9a0b9ac8af6af2ebc6f2288304127a71f2f04e6Virustotal results 32.76%Heodo
2019-02-02GUVIR65551025747694464188.docdoc f66925570a0a62bd3a90719237058656eadf0c0f891e24799854a7d93e63da1dVirustotal results 28.33%Heodo
2019-02-02PAY93870196772163.docdoc 9968bb0d612ba3abbba152d8d84cd8da508f98ae7517fef52969b91915ced184Virustotal results 23.73%
2019-02-02PAY19224778659953.docdoc d0f58e35c717d13f00258af37ad7ba354ed7cfe8360785f30e8d932dafbf4168Virustotal results 23.33%
2019-02-02137425572283135255.docdoc fa78dac7714dbf1f2ff6177f22e3aa25a098d3eed8979266defb1e1cd6a22d81Virustotal results 22.03%Heodo
2019-02-02PT004539311464021.docdoc 127270f3f077e0a994c0238b10f04005c3491b152b1bbe4f7e356ecb39ccaaebVirustotal results 20.34%Heodo
2019-02-02PAY977517323243852.docdoc f4b9d93c0a524b3ca39e24d9d507795a9e16cf77b9de94e0327557c3a7c8d2d0Virustotal results 20.34%
2019-02-0255560927668660278948.docdoc 61a9dfbcdae93648c0a5776d0eed0118c2004adc388bf552b1a644ea95f24313Virustotal results 20.34%
2019-02-02US4776389068530070.docdoc d2ac5e2df15e79e76c861f06a3b0e09e50f227723f1bee85dc85f21e4b95e6c5Virustotal results 20.34%
2019-02-01US408946521018.docdoc 3278d448c595516afef84073eac81a8497a2d6edad2dd299fdf135c36689e486Virustotal results 20.34%Heodo
2019-02-01US854595240.docdoc 3e6f9ce542036e8f9167f1c19ccb8d80f26f934b96d21e56a8f225e861b96825Virustotal results 18.64%
2019-02-01US86409442714428297.docdoc d5e97889c5b3bb6f202040edbf7a35398e92a8fd5a473c9db75b7da5a1a5085cVirustotal results 20.00%Heodo
2019-02-01US37094233009967883533.docdoc eb78c827cf587f2c174ff15ef8e6863b88210b88c90f525fa938d776020c6ab3Virustotal results 20.34%Heodo
2019-02-01US0748507364.docdoc 0ad82020d842a8ecab482d1671cffa0ce55f221da9f3c1cb380b3e88db50cc5eVirustotal results 20.34%Heodo
2019-02-01QQL033885256188408766.docdoc 5b9ac39780859b84a4bd9c4c3d775ce042387cf1c50f1738c5e9121967bbb9aaVirustotal results 23.21%Heodo
2019-02-01683993979142520.docdoc a1ac9fca21482d5b00845c14ab1615963d8c713e8d36bd7824644df3b162fa3bVirustotal results 20.00%Heodo
2019-02-0157859611525884827211.docdoc c7ce84d12ab302cda097013744a7503454431eb687b1262b9a005fcd67577901Virustotal results 20.34%
2019-02-01PAY532664523520376023.docdoc f15350c7baa03b9ce96c0ed468f0fbcd9cedf943c5c0a0198435be0859054c34Virustotal results 21.67%Heodo