URLhaus Database

You are currently viewing the URLhaus database entry for http://138.197.106.206/Models/urldefense_proofpoint/billpay_bankofamerica_com/PaymentCenter_Index/09_18 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:58822
URL: http://138.197.106.206/Models/urldefense_proofpoint/billpay_bankofamerica_com/PaymentCenter_Index/09_18
URL Status:Offline
Host: 138.197.106.206
Date added:2018-09-21 16:19:48 UTC
Last online:2018-09-24 23:XX:XX UTC
Threat:Malware download Malware download
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-09-21 16:20:20 UTC to abuse{at}digitalocean[dot]com)
Takedown time:3 days, 7 hours, 11 minutes Bad (down since 2018-09-24 23:32:18 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-22eBill-810507547626998789974.docdoc fa20fa00858d9ebc9f9e1703177b7a6da5bc8fd5a307c838ecb8d68f37dec7e9Virustotal results 40.98% Heodo
2018-09-22eBill-810273076760220975903.docdoc 6c17454e06fa7db6022035e80268129753e1d253cc486dd5d2476bbb4213c827n/a Heodo
2018-09-22eBill-810039600857181475959.docdoc 19ab3d8c57f0657da2bb64c16a55c3d2fa2fa1ed39cbd74a1aa31a706ba63085n/a Heodo
2018-09-22eBill-810467579744214731990.docdoc ad6f42b6028ca842530be300565087ed0868f8cdaa07a1b7a6b71d6d05c5c38fn/a Heodo
2018-09-22eBill-810702310811361257299.docdoc cc2290d218c14a31c1fba6387834c6844950de12dae7ad8523f35b908e2cfd72n/a Heodo
2018-09-22eBill-810285855609874469122.docdoc a80b6b42ebdfe7251ce683a7dd14a4c62f52277511220ee3e1fb5eda8fb83bc3n/a Heodo
2018-09-22eBill-810014126167622179318.docdoc 2bfd9fea34fbcc9de267b0209373c51a51769708b0efe5c1d5ca75a7666f0c1bVirustotal results 30.00% Heodo
2018-09-21eBill-810116821711202926356.docdoc 2bee1ad63f892a7c4690cd0774ab39acfefaae2c2b31af3cb5117f2c5df9916en/a Heodo
2018-09-21eBill-810779297992443917704.docdoc 22e92dad710541583f68334d8163a6470588635d8efdb40b6ed7204738cc8bd5Virustotal results 28.33% Heodo
2018-09-21eBill-810491000907809878362.docdoc 2cc336d79a6c2d7bf78349079148ae312b96a32b89bb1e03be698af6cddefc46Virustotal results 27.87% Heodo
2018-09-21eBill-810814473676586047603.docdoc 97d8f0d05f89571d41032355dc2f4d938df17385ab81400e57d24189a87e8786n/a Heodo