URLhaus Database

You are currently viewing the URLhaus database entry for http://zoelowney.com/BANKOFAMERICA/Aug-13-2018 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:41807
URL: http://zoelowney.com/BANKOFAMERICA/Aug-13-2018
URL Status:Offline
Host: zoelowney.com
Date added:2018-08-13 19:32:29 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-08-13 19:56:32 UTC to abuse{at}godaddy[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-15ACH #1ZZ-Aug-15-2018.docdoc 15d06f3a25b77c5893d642f7ab10fd15e7200785b59fb9962980234dc0b83633Virustotal results 25.00% Heodo
2018-08-15WIRE #6MD.docdoc 8c4ce35dda3d110f5e6e6bac50cfbb34751f5db03188170d1680144fcca1267cVirustotal results 31.67% Heodo
2018-08-15PAYMENT #041382XKNTFCG.docdoc e93367edd903d593c0ed475e31e8b433a5c5eaf3ec2472a0a31c758b4a85082fVirustotal results 31.03% Heodo
2018-08-15ACH #5XY-Aug-15-2018.docdoc 61f8679f1af61e12535ddedacd965dbb1f745d85d67e597f97df64c2947e35f9Virustotal results 30.00% Heodo
2018-08-15PAY #60TKWUP.docdoc 1bc8843b448337bb7b472a5419b0581278435d2de3d7899b6584314350fb689en/a Heodo
2018-08-15PAY #7794HZXPAFNO-Aug-15-2018.docdoc b3780348a997bf9644df511fc09819640396ae7b5934775a7dae92d1453b9f74n/a Heodo
2018-08-15ACH #08HJPUB.docdoc 175b3629c776f00ce86f5d635be7e8a8f96e0e8abe184b49ee11020f3f363626Virustotal results 33.33% Heodo
2018-08-15ACH #274HFVDBAUV.docdoc c12e3138da25045d878e6c577cba65ed3b25e0100035fc9fcb2992da77ab8531Virustotal results 33.33% Heodo
2018-08-15PAY #550546O.docdoc db0486e7fe13763954972e8b29e104d2b9b6f7070f4638d828b707a63c1ecf2bVirustotal results 35.00% Heodo
2018-08-15PAY #19912HL.docdoc c9f4fdf390dfac51bd78635013c2129bf6edc1e81624a763dee822fb6ce92352Virustotal results 33.33% Heodo
2018-08-15PAYMENT #4273586AIJQJCHD-Aug-15-2018.docdoc 1a4ca08fb00aedb3b45ec4418539472eea22761aabe719e0e8021947305c4e6eVirustotal results 33.33% Heodo
2018-08-14PAYMENT #2105WVCYHRYI-Aug-15-2018.docdoc 56da85225d571569da00e536b11453df3932984b2181103626ac3e238a79b31fn/a Heodo
2018-08-14ACH #2QRQ-Aug-15-2018.docdoc 5c6d9f00e6fcf35631b4b45573b5ef3523be605ddb1d3e34213838821686ff2dVirustotal results 26.67% Heodo
2018-08-14PAY #0654991VUELKFNA.docdoc bc4381b76ef10982d2f32f07816b5d3e87ed6b4ead245d8c830424422e7bc06fVirustotal results 26.67% Heodo
2018-08-14WIRE #15IRVEZ.docdoc 75c75abfb68fa9ad3ba70008aa74974e0125be70764678d86e51f1ca37d0d918Virustotal results 28.33% Heodo
2018-08-14PAY #8315121QQYGESCS.docdoc 98d4c036aa8edc94b6e508adcbec57c4c507a5ecdf481cc30aee66f3a9057b11Virustotal results 29.31% Heodo
2018-08-14PAYMENT #0274QGDYCU.docdoc a4b0568b2294ef9d027c5e126914544224e7621b54ad2c61ec925a1c424f8e90Virustotal results 29.31% Heodo
2018-08-14PAYMENT #15318QHRXGLPV.docdoc 56bbc15741d9dd380655a3c68f355e081ad4efb4a4f0979d3e9696ecfd745e7bVirustotal results 29.31% Heodo
2018-08-14WIRE #67VSYXGSK.docdoc eeff30302c60ee1360d9bc061a346778b05c42377236052cabe4855439987911n/a Heodo
2018-08-14PAYMENT #5WOPM-Aug-14-2018.docdoc 52c2d15e600bf4ad4c7254e7e7b06537ef44894fc07a3691491ebd4aba97c450n/a Heodo
2018-08-14PAYMENT #640QH.docdoc 624cd190286fdbf40b32768f2fd330f7ba4ec4824a38fef7894d24708c52411fVirustotal results 32.20% Heodo
2018-08-14ACH #6WYJUJWM.docdoc e2f057f461e6f34dfc0e8123bf35e6b2bcc1981698811f127b48700e43310c94Virustotal results 30.00% Heodo
2018-08-14ACH #91073ZVJ-Aug-14-2018.docdoc 20f4771fc95bb5e7d9a371334784a1f92b9b7f124f03daa095b429b370e0ae5bVirustotal results 31.67% Heodo
2018-08-14ACH #8030MC.docdoc aa010815ceb9eef32db89f57240949c1e13244b15f4607220d62ec77302232a2n/a Heodo
2018-08-14PAY #659594JDKCW.docdoc 39e7dd2506b539b18a3552bff726eaf7a1206e4b29fc85c5ca189fdb4344a4dbn/a Heodo
2018-08-14PAY #7727288PMPJPEIG.docdoc 131dc89104afa262b7b2476df2a04ffb6085442115e61dda3ff669b6b3168af4n/a Heodo
2018-08-13PAYMENT #314B.docdoc 04f8b430ef0e919c513430b47b33a44f41f77ca56d8fe99fa7ff5b026125121eVirustotal results 25.42% Heodo
2018-08-13PAYMENT #404641CJZPXJK.docdoc e1aad4875acddd1edd99ed628a9c1eae09b4f5a0fc74c4dc6fcfb903e65ef806Virustotal results 27.59% Heodo
2018-08-13PAY #0784492IUHL-Aug-13-2018.docdoc 262f362e36276789609ffff90c496997372888b0048edb3cd16f14e161fc55a8Virustotal results 26.67% Heodo