URLhaus Database

You are currently viewing the URLhaus database entry for http://kanaangroupsociety.com/BANKOFAMERICA/Aug-13-2018/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:41982
URL: http://kanaangroupsociety.com/BANKOFAMERICA/Aug-13-2018/
URL Status:Offline
Host: kanaangroupsociety.com
Date added:2018-08-13 22:15:49 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-08-13 22:33:28 UTC to abuse{at}liquidweb[dot]com)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-15WIRE #3069QXN-Aug-15-2018.docdoc 381f75bad85bd4d127dd3d1485d52db6a9b03c8dda68fc33c1adc56438f59723Virustotal results 29.31% Heodo
2018-08-15ACH #10011AJYE.docdoc 73868ae24df659f67651ef7a5ff653338ba622b42de4d3c215d336f9e1f45f09Virustotal results 28.33% Heodo
2018-08-15PAY #2299AVE.docdoc 76fdc1b5a547f51fd68ebd1c2c2a9706891d3960732dffabbdff13982c9ad282Virustotal results 31.67% Heodo
2018-08-15ACH #9040N.docdoc 9b0839baa0922196d1c9af88985487b24298e62fca519d58ff03d46cba49c7c4Virustotal results 32.20% Heodo
2018-08-15PAY #6007135HRMAKKDV-Aug-15-2018.docdoc 7f58976b59ff4dd80cc39c62c8850e4db6b83da1ea613cd9480321a0484c6153Virustotal results 37.29% Heodo
2018-08-15PAYMENT #72571MISIL-Aug-15-2018.docdoc b3780348a997bf9644df511fc09819640396ae7b5934775a7dae92d1453b9f74Virustotal results 36.67% Heodo
2018-08-15ACH #567NTUGTRF-Aug-15-2018.docdoc 25154fb7ac5bbaeea084f65e310f1a7b614f0d611e1b660107f898b312780ccfVirustotal results 37.29% Heodo
2018-08-15PAYMENT #261883LFYPTKV.docdoc 175b3629c776f00ce86f5d635be7e8a8f96e0e8abe184b49ee11020f3f363626n/a Heodo
2018-08-15PAYMENT #91SRRSI-Aug-15-2018.docdoc 750f735540883b2a173ef6de05ed720e37ff554457199c64728f5dbd9d411348Virustotal results 33.33% Heodo
2018-08-15PAYMENT #5282811BZMHZK.docdoc c12e3138da25045d878e6c577cba65ed3b25e0100035fc9fcb2992da77ab8531Virustotal results 33.90% Heodo
2018-08-15PAY #21470OC.docdoc 78c8459629d6d186b8e344e1361540ea66dca3285057643cbfb8fe77a3440fbdVirustotal results 33.33% Heodo
2018-08-15PAY #79KN.docdoc c9f4fdf390dfac51bd78635013c2129bf6edc1e81624a763dee822fb6ce92352Virustotal results 33.33% Heodo
2018-08-14PAYMENT #9AX.docdoc 14269533d139ff3652bf6cbfb71b961e9f27d058db2b625fa3493cbfe10a69ceVirustotal results 25.45% Heodo
2018-08-14WIRE #058GHT.docdoc 5c6d9f00e6fcf35631b4b45573b5ef3523be605ddb1d3e34213838821686ff2dVirustotal results 26.67% Heodo
2018-08-14PAY #78289QYDPCU-Aug-14-2018.docdoc 75c75abfb68fa9ad3ba70008aa74974e0125be70764678d86e51f1ca37d0d918Virustotal results 28.33% Heodo
2018-08-14WIRE #76087ZEDRLE.docdoc fbcae92bc747efb4a517bae6b26ddde6b7569e22f7ed3b9b875f892469765e36Virustotal results 28.81% Heodo
2018-08-14PAYMENT #591721BEKTZKMN-Aug-14-2018.docdoc 98d4c036aa8edc94b6e508adcbec57c4c507a5ecdf481cc30aee66f3a9057b11Virustotal results 29.31% Heodo
2018-08-14ACH #127527JESOCTGX.docdoc 200f9ce2b352f4cadc07b595bfd5687cd67a942892ea333eec4cf3fe2636874bVirustotal results 26.92% Heodo
2018-08-14WIRE #3498JOUED.docdoc 157dee01954573e9799483d766734d8bb3279f7fbfdd5f88ab3e9f118901e572Virustotal results 29.31% Heodo
2018-08-14ACH #085005VHVGAO.docdoc cdc86d9833b498b8b5b1675f86a064cefe95973b766e264cdb892275a2b2efb6Virustotal results 29.31% Heodo
2018-08-14WIRE #291LPQAVXF-Aug-14-2018.docdoc 624cd190286fdbf40b32768f2fd330f7ba4ec4824a38fef7894d24708c52411fVirustotal results 32.20% Heodo
2018-08-14PAYMENT #0VBYVH.docdoc e2f057f461e6f34dfc0e8123bf35e6b2bcc1981698811f127b48700e43310c94Virustotal results 30.00% Heodo
2018-08-14PAYMENT #427GMRWU.docdoc 22a04c30ef04aa94d29bc57ff29860d14e4dd33c2a432b552bb7aa801ef5dedcn/a Heodo
2018-08-14PAY #541FQ-Aug-14-2018.docdoc b3384dc3062d258c6c865a507ce9ff98005319b3ebe1fc7f6a28807b284b3cddn/a Heodo
2018-08-14ACH #64RN-Aug-14-2018.docdoc 131dc89104afa262b7b2476df2a04ffb6085442115e61dda3ff669b6b3168af4n/a Heodo
2018-08-13PAY #55C-Aug-14-2018.docdoc 243c1a5cd47b29f7d142aced33b3bef54d2ecffa4a3be4da009562f8517429e0Virustotal results 28.33% Heodo