URLhaus Database

You are currently viewing the URLhaus database entry for https://bullzeye.xyz/wnplu/open-36GyF2hU-lSPn48gd6sbWHWT/additional-v5o6f97nz5w9-a8fp7zq/RmxS3yY-LIhM2dwe/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431881
URL: https://bullzeye.xyz/wnplu/open-36GyF2hU-lSPn48gd6sbWHWT/additional-v5o6f97nz5w9-a8fp7zq/RmxS3yY-LIhM2dwe/
URL Status:Offline
Host: bullzeye.xyz
Date added:2020-08-13 12:34:39 UTC
Last online:2020-08-13 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-13 12:36:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 55 minutes Good (down since 2020-08-13 16:31:23 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13dat_937495.docdoc 6a429f70198a9efc77444f176afd5bf1cd97f794e2020e32ffc020c481e42b4aVirustotal results 30.00%Heodo
2020-08-13doc_20200813_DWY31319.docdoc 57270c211c92893639f45356ac942602a73f44cd8d9f13538b2afd2e300ea475Virustotal results 28.33%Heodo
2020-08-13REP 20200813.docdoc e3b735c7e48d5fd9dd8fbed7a6c5665a9000bb4d3022e2662ff985e567bf4441Virustotal results 28.33%Heodo
2020-08-13List-E87430.docdoc ed5cf96ce29d25d0ed178015e7bfff38df7088dfb18ff6b3443bfa7ab107286dn/aHeodo
2020-08-13MES-767.docdoc 4d9fb0fc21364011b0155c51ae24085a4371dfad9f32a0569e54d330fdf068ccn/aHeodo
2020-08-13List 758.docdoc a29171156f8613e2fb07ecaddce758a942371a5df390af684dd26d9eb8c58629n/aHeodo
2020-08-13LIST 2020_08_13 767794.docdoc a8a916f66d089d2a2c23ed7f30163860cc91269fb71b2415123cd57e3e424593n/aHeodo
2020-08-13Doc-JK4247.docdoc a9e97cd44d571b602a1a710895d7a187c895248302aa3f6d52eef243709d9b13Virustotal results 30.51%Heodo
2020-08-13dat 3353.docdoc 4cea566229c73afde8f711ab3753d32bc35a21d9667dd73c709977964aadf3d9Virustotal results 31.15%Heodo
2020-08-13LIST 2020_08_13 8867213.docdoc 59cf60d70be84cb50173a843815e0f1e700e02794af516037a781dec3a6d6be8Virustotal results 28.33%Heodo
2020-08-13file_20200813_4545897.docdoc 597c1e67220b23553876dd11db55a2daab298063d5ff4f3afe922db00c9cf514Virustotal results 28.33%Heodo