URLhaus Database

You are currently viewing the URLhaus database entry for http://www.tz004.com/ad_files/Overview/hante3496439239015vj791pmsu6tns97j/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:607828
URL: http://www.tz004.com/ad_files/Overview/hante3496439239015vj791pmsu6tns97j/
URL Status:Offline
Host: www.tz004.com
Date added:2020-09-23 23:56:11 UTC
Last online:2020-11-14 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-23 23:58:13 UTC to abuse{at}hopone[dot]net)
Takedown time:1 month, 21 days, 9 hours, 26 minutes Bad (down since 2020-11-14 09:24:52 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25X_BFD_090120_QTR_092520.docdoc 8a73bdca97395b9f659104c200734008fe685faff6734fc31ce0cd575090f1b2Virustotal results 35.48%Heodo
2020-09-25OAF_090120_MUX_092520.docdoc 32e608f5734fcb68970d54ede47ece4cf463eced4316ce2fd04fb7869d2072d3Virustotal results 29.51%Heodo
2020-09-25DOC_48947256.docdoc 8737044355a98a9ffd49ece5bcd55b760fdd2e63b8b6b02d15028deb9d28ed36Virustotal results 24.59% Heodo
2020-09-25JXD_090120_MLU_092520.docdoc fe3018c09ebbc1ba8e04839eafcb353384ffb23b0be6729808a820abc068b280n/aHeodo
2020-09-2422968738760485338.docdoc 89825271f1b18375f523320908826b553e9da21bce402e9844bd3d55446fb509Virustotal results 31.03%Heodo
2020-09-24INV_PO_09252020EX.docdoc 30a0c59711e06c411f4e1a20c649f507a1ef69742192df4ede24d92289aee591n/aHeodo
2020-09-24INV_102186083834590121.docdoc 7732eb513243e6e3a764a526f3e87061885357e7adc6901e3ff647b039b4bda0Virustotal results 30.65%Heodo
2020-09-24REP_FZB_090120_BBI_092520.docdoc 733d8b10af3308cfd8ebc53724d8bcc6b47a2a8652e46f3dd15d87ab5ef7f123n/aHeodo
2020-09-24BAL_PO_09252020EX.docdoc c8e1fe8c16784222fdc737735ed29812a5f1721e61b75f3386fa6ea802c9b525Virustotal results 21.31%Heodo
2020-09-24FILE_EL5074658366HC.docdoc 46996b6a7e3fb5f718730ed86bbfa6e57792d961db1bd60352e17703af38134eVirustotal results 29.03%Heodo
2020-09-24ZWTNKMPML8DN.docdoc 7e1935fab86166df5d6770468bf12c57a50720c0b7ba90e21accf2ca8493ce15n/aHeodo
2020-09-2432528141413142148160215.docdoc c4fc9ec7954c1bc71dc415464f2813e6151dd7c106526dfe3aa8d97ec3b8f9deVirustotal results 20.97%Heodo
2020-09-24215492464222.docdoc b9211d9fdc8cf882f69237754fd387b887bd80a07f2abe12c2f687dd04ec3ad4Virustotal results 29.03%Heodo
2020-09-24DOC_AQE_090120_LUM_092520.docdoc a57fc009ab0a20443a4b85deb2d976357ec107017cceda370de28f76897500a7Virustotal results 31.15%Heodo
2020-09-24PO_09242020EX.docdoc 02ef96f4a3c715053acf327bd61196658034d30887f0bb1a9769e4bfedfe0a41Virustotal results 29.03%Heodo
2020-09-24KDR_090120_PNN_092420.docdoc e8920178a654a05f4d58c417ab5df624d778f70deb69ef450e79c6511c72e55bVirustotal results 21.31%Heodo
2020-09-24BAL_FV4016738355JQ.docdoc 68d56a79c843b1b6a5d9937b5f98c3ecd25a60ebbffb348a9e08cde6dd1a98fdVirustotal results 30.65%Heodo
2020-09-24PO_09242020EX.docdoc 85c3fbc17a0daacdb938f7ea4b8dfa14ae9a099d59de1e9fef807b569c999acbVirustotal results 19.35%Heodo
2020-09-24REP_OJ5067773803QQ.docdoc 85264b8b2a7f29ff8c64c3de97d3e17a58c4aa09c6a67460d5be96117461224bn/aHeodo
2020-09-24REP_138829656.docdoc 00fbe37855be5d55bc265f0e5e3f284ede6342549349e4b33cf2511347b3fc13n/aHeodo
2020-09-24PO_09242020EX.docdoc 8ffd33471d8e180b9ff498aaa84ef11bf50e846252c62e42e416fe68c1698d06Virustotal results 25.81%Heodo
2020-09-24O_PO_09242020EX.docdoc 6d3d32f94e8c49634c93ac96bf0b6ef4bb3dc49696aef545f990d19752a027e5Virustotal results 20.97%Heodo
2020-09-24BG8201715307UX.docdoc 32bbcef052b442f62a2fbb0c5dad498dcb779148f31f2e51d4f7a38245024f8en/aHeodo
2020-09-24DOC_VBMT0PNT3T1LV1AX.docdoc 60b9c51a988490875a152231c3217de228b7406a1378ab07263aea7f02ecd3ccn/aHeodo
2020-09-24DOC_PO_09242020EX.docdoc 460d4f1fa3c90d50ae0a56c6c4c26bfcd3d3d22829baef98b7ea3e9b451974feVirustotal results 33.87%Heodo
2020-09-24SO7914636065CT.docdoc 3321abc9c460868cfafe80f968ccea4254b02ede808bcabe4dd58055ffddb358n/aHeodo
2020-09-24INV_QZ3424997549YD.docdoc d038ad9d31d6764ec9e5ad2246c2f2a99e0c06ca8798bd54e73deecb05dab14dn/aHeodo
2020-09-24BAL_42088822979853.docdoc 2e3f0cba76c76de6beb1d7782576c1913d7a5ec9e471a36bac04827d26b0185dVirustotal results 31.67%Heodo
2020-09-24BAL_HY7204995729HG.docdoc 62b4929ff251b1ad4f361fa4d8f8980b722d4219e9e7a8c9aea193558deb8c2bVirustotal results 27.42%Heodo
2020-09-24REP_VT2804753781CR.docdoc 322437c9e679266325e5e5e4e5192b3480e02f680d56fbede6b807db9def583an/aHeodo
2020-09-24INV_NRP_090120_ZZY_092420.docdoc 7e5a42a73c29e93f48c97d924845eef4cce7d6a931dadaa19068f78f4bb83015Virustotal results 30.00%Heodo
2020-09-24R_QS2837656603WB.docdoc 3b6754841cd0be21c785048d546fed0ac9485c8d67dd12c0a9d69a31184786b3n/aHeodo
2020-09-24GFKN6S0VKJ4.docdoc 27dc3b44a37b8d1d2c9fb8be66fc68db20eddfd82efd9aec4a13681328129242Virustotal results 27.42%Heodo
2020-09-24FILE_CZC_090120_YQN_092420.docdoc b56489389c1e6ac6a72a02bee6d40a243d9b77778e255686c8adaa77247a7cd8n/aHeodo
2020-09-24BAL_93D5568KD77S.docdoc 1c66ec5827934e0744220674a8ae91d47bfa027376d756dd4722ecc165f09878Virustotal results 22.95%Heodo
2020-09-24BAL_458478561698676.docdoc 0124d3e8aff15d102fb833f22f02e06f09205ee29cc4bb8c1bd2568234eeb319Virustotal results 20.97%Heodo
2020-09-24Z_YNG2WR6G.docdoc c8de91c5a698b19b834995d8d06dcfdbbd8147015a34eaf4fa99ccd6cdf012f9n/aHeodo
2020-09-24FILE_FGQ_090120_JYD_092420.docdoc 6e5bcd9db826f2b855f63e8a591e02ebb0bbd141387d2922e3e251fc8ddbcbb8Virustotal results 19.67%Heodo
2020-09-24V_S39EEG1.docdoc 10ee811abda6b02efcafbd3d0632861a478e57acafde239f71e7231b6ca2e7c8n/aHeodo
2020-09-24Y_43044583992055.docdoc 54d6881837b3fcb6a0b3e639c58f6e159abb745d0862e1f5cabe6c7df3a3da12Virustotal results 20.97%Heodo
2020-09-240C5DRZWOS0.docdoc e2dffd7e2a3663a738dac21fd590dec2cce14df9ccf7aebcc5944258a827bc04Virustotal results 20.00%Heodo
2020-09-24ECOCAQXB8FG8.docdoc e03588b5c327278e634c775b1f13c311c8aa3494cddd7aff114eab54dcae3c5en/aHeodo
2020-09-24RI8930197144FH.docdoc 4d6a492ccf58a9712b96c0ce4443b1881fa7405bbda94ce7cc0a92ef06a2daafVirustotal results 40.98%Heodo
2020-09-24ML_F4CWFCMP.docdoc 19cb69cbc19879e5cae4e56b1d702cfcd04c72ebf8a9c795592d509a91e5a2ean/aHeodo
2020-09-24FILE_KU4126061888CP.docdoc 3b2da1783943899a3e23e20477670990adbde1f6edb9bb2e2ec1aa640c601f3dVirustotal results 35.48%Heodo
2020-09-24S6SRPEFC9NZQXB.docdoc 813c3689cf9fecd602a950034dcd90f060f360f68193e239a02e13ed8587c220n/aHeodo
2020-09-24FILE_22130047.docdoc a48a197539aed2368c68f377ee4e1a8886412cabd39050e98b3fab282c089d39Virustotal results 37.10%Heodo
2020-09-24PO_09242020EX.docdoc 8f054924ac0e3a72b2725a18206bf1e2faaa327460d2e7199b1152126241d054Virustotal results 35.48%Heodo
2020-09-24PO_09242020EX.docdoc 79a7d433152a96d54a0687fd65dae6aab97a6af26dd206692bf88636977729a1n/aHeodo
2020-09-24FILE_WS3008469926YI.docdoc dd05de775c3c07e1c25cf767154016406cb4c3fc2b20a4824593c30830e79583Virustotal results 35.48%Heodo
2020-09-24INV_DR0587789111EM.docdoc eb45dca6aca88223d8145576132a86f7f21770508a20b6335021ea03cc040d8cn/aHeodo
2020-09-249950405413818557.docdoc 0185c23ef468c062bc446ffc87e7af495c49e991d0a24c67634d8f0cd3d8bf8bVirustotal results 32.08%Heodo
2020-09-24I_76159583906781.docdoc 9ca8f66ca174af2d6d9944b2cfda4685bd8710217610c24b6332ae5436c52405Virustotal results 30.00%Heodo
2020-09-24BAL_W6XF7Y4IL.docdoc 0b089eaf3134af01322c9b778303dd6bebd992f97ce0f6f5b81a06f6e6d85d78Virustotal results 30.65%Heodo
2020-09-24FILE_4Q0J3M2FHTLMBM.docdoc b1bc22abca15845684f53bec0ca8fe04943d104d77b2028d65bd63855077731bVirustotal results 30.65%Heodo
2020-09-23PO_09242020EX.docdoc 324337642923507f95f8882431a523b118e670bec80dc82ea989321c6abd2e37Virustotal results 27.42%Heodo