URLhaus Database

You are currently viewing the URLhaus database entry for https://andreizach.com/sitemaps/public/zI1JOoadql6heZyr5Rm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:618443
URL: https://andreizach.com/sitemaps/public/zI1JOoadql6heZyr5Rm/
URL Status:Offline
Host: andreizach.com
Date added:2020-09-28 18:51:38 UTC
Last online:2020-09-28 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 18:52:07 UTC to CloudFlare Anti-Abuse API)
Takedown time:54 minutes Wow (down since 2020-09-28 19:46:53 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-28INF-2020_09_28-C588.docdoc 84025f7343277daa58bc982cb0cbf1b86426c8ce05c63d0d0ffaed66a4b7f066Virustotal results 32.26%Heodo
2020-09-28arc_2020_09_28_CZ590162.docdoc dc762014c4c9457aa47040bfb2683d0fe766de1b24246a8b7a021497ffc9b7e7n/a Heodo
2020-09-28inf 2020_09_28 3724.docdoc 9229b8aa910b6a3a82477341ff66c9e89779d37ee24826a7b4c370fbd0bf4e62n/aHeodo
2020-09-28OLG7644-20200928-1516862.docdoc 8d949a82a15f90565e204f6710e5c0d0cd258fbfa73248403b9742d0058e0ea5Virustotal results 32.79%Heodo