URLhaus Database

You are currently viewing the URLhaus database entry for http://bzoca.com/PAYMENT/VG81545DAUPDK/Aug-07-2018-84600743/HJ-XOXN which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:39985
URL: http://bzoca.com/PAYMENT/VG81545DAUPDK/Aug-07-2018-84600743/HJ-XOXN
URL Status:Offline
Host: bzoca.com
Date added:2018-08-08 07:31:09 UTC
Last online:2018-09-08 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-08-08 07:37:01 UTC to netops{at}singlehop[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-09WIRE 536305RLWUXN.docdoc 3f4eb4f21805d0609afe58ab3950f08ba2f134b088230b196c169c767fd06a53Virustotal results 31.67% Heodo
2018-08-09WIRE 887666BAAFJ Aug-09-2018.docdoc 5b3165e554a96d03bd5f5c743b1b73ea35447bcd7ad01656b36cbb1c298f8499Virustotal results 30.00% Heodo
2018-08-09ACH 804VEL.docdoc 4e1b752854a3087ac35addcde982f4f9b4b254a3601642fb0142ebb3803dfa34Virustotal results 29.51% Heodo
2018-08-09WIRE 402165LWHQIIBN Aug-09-2018.docdoc c4417fc19a3e7eda5f143672d412b112c5a2f7c5a5ded0ba0c8f9c1604391756Virustotal results 40.00% Heodo
2018-08-09PAYMENT 1624LNRVPSGY Aug-09-2018.docdoc 310a2eee356a3bd699e2ece7fb399d0c05182b762eaeebe326ddfdfabab9b0dcVirustotal results 39.34% Heodo
2018-08-09WIRE 931FNCVHJ.docdoc 16c52af73c5ae5f2b52196cc111f1b3c924b0dc4514765728826d8c20331e36dVirustotal results 40.00% Heodo
2018-08-09PAY 88IJ.docdoc 450643ad882f8d3389d9d8a744f14843cdb7fbcc0b1509229f411ac91acdbc94Virustotal results 40.00% Heodo
2018-08-09WIRE 4455304KRLNSNQ Aug-09-2018.docdoc 878d58170dc994cafb826f76d5c7f3fdf3b85b8e9e5173db79b714b7dedb10feVirustotal results 38.98% Heodo
2018-08-09ACH 2172745CON.docdoc 482ac73572390a865001ca971dc199ebc7031c5fee9666a689cffcf208233013Virustotal results 37.70% Heodo
2018-08-08PAY 607AOIV.docdoc bb15ee38d69336289ba4cb76d4b0126eb50de8fc5fe6e055280fa88444337970Virustotal results 34.43% Heodo