URLhaus Database

You are currently viewing the URLhaus database entry for http://zeeamfashion.com/evil_twin_vhost/Reporting/r8n/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:618898
URL: http://zeeamfashion.com/evil_twin_vhost/Reporting/r8n/
URL Status:Offline
Host: zeeamfashion.com
Date added:2020-09-28 20:46:05 UTC
Last online:2020-10-04 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 20:48:10 UTC to abuse{at}alchemy[dot]net,dnsadmin{at}alchemy[dot]net,support{at}vitalix[dot]net)
Takedown time:5 days, 10 hours, 45 minutes Bad (down since 2020-10-04 07:34:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30DOC_PO_09302020EX.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.22%Heodo
2020-09-30INV_CUC_090120_FXJ_093020.docdoc 950f9c4f6561a52ab6850b63b0551b2e75c7232b28c11aa0e470001d770dd194Virustotal results 21.31%Heodo
2020-09-30BAL_PO_09302020EX.docdoc c5d3f7beeec8a157185d5c01ac991e0357cb0d55f5b4335f3846792136692714Virustotal results 20.97%Heodo
2020-09-30BAL_PO_09302020EX.docdoc 8cc454cbd44284ac4a4b398e7fb7e8ef64466cb44537458d884f54fea7d6374dVirustotal results 21.31%Heodo
2020-09-30Z_PO_09302020EX.docdoc d6ef2c87a2f7382737b67e8a7af717228006adca415f24e3f7a0165808c144c1Virustotal results 21.31%Heodo
2020-09-30INV_34367032.docdoc 420c99cf0d5ca3e0ddb053ffa31741bebe9dd69fb61224c8c741b7ec01e85e96Virustotal results 20.97%Heodo
2020-09-30PWGM_SIE_090120_OQQ_093020.docdoc 119dab813d43139ec7ee0f953f68341391776f7f5cdbc1fc6eeabf95356a8a21Virustotal results 19.67%Heodo
2020-09-30HZ8R89JQIDXC9.docdoc 605f71e5062dc6452e0f427294e6d436a184d7cebd4d4600c98d0a5542c30addVirustotal results 21.31%Heodo
2020-09-30RWZ_PO_09302020EX.docdoc f8fb4db3104cc2c9f261f3b3b43acb4132f5759f8e485677651a52478610f5bcVirustotal results 20.97%Heodo
2020-09-30INV_HQWWIY3D1KUSYZ.docdoc e9a9d7c87ef767357d0019c6185d27bec8449b2abd340b93b54b6621c426fc14n/aHeodo
2020-09-30DOC_PO_09302020EX.docdoc bf10b7e9f1ff0345f426df6b7da95cdb75284d378f7ea29d192e24623e35f3a5Virustotal results 45.90%Heodo
2020-09-30T_LOJ_090120_PIY_093020.docdoc a9b4569007c2822d7d717a8ea3a4e3a496c52a3f2011519ca3c4dd5e42011465Virustotal results 46.67%Heodo
2020-09-30BAL_PO_09302020EX.docdoc 09920ec2c5029cdb6177cee45414e34e9307a6f40548df1ba80385c44cfcc613Virustotal results 43.55%Heodo
2020-09-30BAL_USTF7AFGIB.docdoc 3d322e72fd831b7624674c0a9ed650c75bf0cf2d05e5c2dcf7746ee4187260b3Virustotal results 45.16%Heodo
2020-09-30FILE_PO_09302020EX.docdoc 5b04551305572c828c0ac8143249ef7e94223b0fbf7d12b43f77c4e3da8bda45Virustotal results 40.32%Heodo
2020-09-3077442367.docdoc 0bffbb268223d255d4ebdcee53bd0d8e990843600bf96f811f47a550d1e366caVirustotal results 39.34%Heodo
2020-09-30PO_09302020EX.docdoc d8f8b40e6c0fff5344fce0199e4fd683f50bc846af26963d53ea1554aa202e61Virustotal results 35.48%Heodo
2020-09-30J_98716504.docdoc 8c21463a0b127e2db497f399810180572cf5e4027f3942919aeeccabf1d3753bVirustotal results 37.10%Heodo
2020-09-30BAL_BXF_090120_HRZ_093020.docdoc 020aeaa470dfa7a4e9fc3e8d88db9d7f89b1bd64df67a963467490068a6f3d6dVirustotal results 32.79%Heodo
2020-09-30EF76DK334.docdoc 8649c9f23563646d5b0033bb729307388ddb4396da639cbf0385c08ec0a01cffVirustotal results 32.26%Heodo
2020-09-30FILE_3XELF8I.docdoc d56585c6e4a0ede125061be754c5a0c9b45728232d4c61937ffbc047df3aae30Virustotal results 30.65%Heodo
2020-09-30FILE_WR6ZPD2ZHMIA5M.docdoc 48e23cb77f6629ddf1c1b70ff1af00789fe9ed39014db2e97b4be24c2e13a168Virustotal results 31.67%Heodo
2020-09-30UY8887423895IB.docdoc 96658effd966024181bb6c0128804f37e523120f12108dcc80230e636aa0e291Virustotal results 30.65%Heodo
2020-09-30REP_PO_09302020EX.docdoc 587adcb5768ec9aa8b3be79e9ea740bc5052b9d0f09d4b2854fac3ff667edd4cVirustotal results 32.26%Heodo
2020-09-29REP_H9OZX8KC.docdoc 6596f751d97b234516bc66104d96abd644a86657c7c981f245101bb9bba1c004n/aHeodo
2020-09-29FILE_10116575.docdoc ad21f91ac048eeb669e0a9cc8199225d755cf89a9f5d79d7fb39ef2659f04a9bn/aHeodo
2020-09-29SJ7D0F3QPXAOM.docdoc a0269d67f007490795637a732bf26ce5976a2b4039df3d784930ef9109697365Virustotal results 27.42%Heodo
2020-09-29PO_09302020EX.docdoc d59faf29c8fe5f632a3b7d91802b08434241b502d47b2bcdf2276dc68e4e7d48Virustotal results 29.03%Heodo
2020-09-29DD7882860991JA.docdoc 76d3bae4ebe683a5d3ff0d90971119c287a3acbab073e28b979ad7eaa60e37bfVirustotal results 27.87%Heodo
2020-09-29O_871968233659366.docdoc 14e6ea40cc1e124fe353ed7aeb27490dad58d6a116bfddc62aacaa02921c5d88Virustotal results 32.26%Heodo
2020-09-29IEM_090120_UZO_092920.docdoc 5f1ea173886baa8208a164cab30480d8362327401dc4782d01aa1caeb3314b9dVirustotal results 24.19%Heodo
2020-09-29WH0679123654XY.docdoc e14d5e952754ea4e70d6b4e7fa8492b977440f96102fd4b5962df2b34c5ec4a6n/aHeodo
2020-09-29FILE_Z92JEZG79Z0SI3.docdoc 57c668a0bbfa7e8683b5b1aa582e5bee9674151ae3b0a92c61f7fb594b2fc2a6n/aHeodo
2020-09-29PO_09292020EX.docdoc 68a9ee794307f9d9834945084a0412835b4b80754f558094acd6f3b5d6cafee2Virustotal results 24.59%Heodo
2020-09-29DOC_75196838.docdoc ac227d3a7a5726f8481ab18b06d8afab6c1d4f31572578a71f4375020fa715c1n/aHeodo
2020-09-29DOC_PO_09292020EX.docdoc 0da375987ca85423a9ba820c1000eeb64083a2efd303617b7a1e33de0a7d21d1n/aHeodo
2020-09-2916006986.docdoc a916028a8065134286abed17393e55e315c9ba012558b7a0875e09ac2ff95e50n/aHeodo
2020-09-29N_F00K660D45PJPN.docdoc 45e97570fd10c8eb0957ca5b1d503d457681e75e5cc9a885394b17425496d58bVirustotal results 46.67%Heodo
2020-09-299768066807355540652690.docdoc 5f8f8f8f2bd286d3f5f76e6ca535978a9eccba49c5fb61817ef1d967a44d0ca5n/aHeodo
2020-09-29XKI2C3HENG.docdoc 3d8a783425d8282e9559a75a4f06d8c18791c61dfc931c9f54e50a92b5a5f285Virustotal results 45.76%Heodo
2020-09-29BAL_68343044.docdoc 27442f20eb59b4d209325e6568821d54267357d72c350b9aac8bdbe721e0235cn/aHeodo
2020-09-29REP_659639503884.docdoc 79b121ca291143b84bc1cc6c6a2a5f5f734bd157440ade16df5fd0cf683356aaVirustotal results 48.33%Heodo
2020-09-2979802466.docdoc 72cce742afb1793666134468897deb5f7fca3bffec97714f0fa758c704e5d974n/aHeodo
2020-09-29PO_09292020EX.docdoc 5812d0ad109d6f40968469204b6745f68b91371d185978b1538b763789ec4098Virustotal results 45.90%Heodo
2020-09-293RECO4ZKF9YBKSL.docdoc 7e85837a8b4971b1014e74d107d5cf4f797470db1b9823a8bca7511a0d991c96Virustotal results 45.90%Heodo
2020-09-2947156915.docdoc f9cdc77ed726ea74349609ebcbdf46678cd15a3f47f9a5780c6edc275e2117b9Virustotal results 45.90%Heodo
2020-09-290587503775.docdoc f4ad95a20290c41dbfd7f5f6f7c7ba9b8112cf7de810f89d92476e31e6c42e9fn/aHeodo
2020-09-29FILE_5ODU1013BC.docdoc d9589a671bfd282af7368f128a3acecfc91b1128e0fc61e4ff98d967b1cb89d1Virustotal results 45.16%Heodo
2020-09-293164180979396718139761336.docdoc f017fb57e3d63cad2e865981e345ac9c31f64c1114aaa4e21c6aeff31cbb13d2n/aHeodo
2020-09-29207902160293696.docdoc 6fd207179f176e11c17024e62c6007fe91dc6dd1fb8643b66e2d39b36fdbec66Virustotal results 45.90%Heodo
2020-09-29DOC_4P79N9JB06XK4.docdoc 1f05ac51daee57a330e0b2e270a5455a23d6866da5392138b1403ac63e5b4793n/aHeodo
2020-09-29PO_09292020EX.docdoc 1b4294152cd807e23b698599e9be39ec531fc28ab159272ea894cc5633ab2cbfVirustotal results 45.16%Heodo
2020-09-29BAL_97028227.docdoc 1af9c4541fd3967f4d9820ee633cde8bee8d73612d046cba0456debdf28313aen/aHeodo
2020-09-2965374829.docdoc 4b7fd3aa52853241aaa5c8d95e005ace57390afc9406bdf9da287bd7c6ccd123n/aHeodo
2020-09-29PO_09292020EX.docdoc 70ea160fde803539083eb208609b17b5910f502f8bb0a3e36e053ece5b214df2n/aHeodo
2020-09-29BAL_787230395913954088874886.docdoc ccc18b91da784754f83482778c7bfc1de931b4416de9957b6e7b61b25d8d43caVirustotal results 40.32%Heodo
2020-09-29G_PO_09292020EX.docdoc e5d1b3e601628703582a921fef151b6f35ed2776cd4a18887cefac671899cee6n/aHeodo
2020-09-29PO_09292020EX.docdoc 194b30f855f3424668f49d26aaf22efa741ab0afe8f918f576bf7247355c144fn/aHeodo
2020-09-29Z_11322087.docdoc acbe625125210f292986e1a32b358fc608504c11aee463f05e4ea2b4ecac55acVirustotal results 37.10%Heodo
2020-09-29JOX_090120_XCB_092920.docdoc 354f42e3a360351ce3a12b152b9b619b2dda611a1bd404d2e54a8e0f2249f988Virustotal results 38.33%Heodo
2020-09-29FILE_YSL_090120_ZRO_092920.docdoc 098fb7d718037b90543175fc964c4fde918746825292005bdca3f6bf33a29360Virustotal results 37.70%Heodo
2020-09-29REP_93517309711836520733.docdoc 3282dfbfe42f2f929d4e24a4b8c1613f9da3bfcc2e228a3692a931afc3178189Virustotal results 37.10%Heodo
2020-09-29PO_09292020EX.docdoc 62d1a0ddc98b6e9f6f22539f196550672415057298dbe058673fd5fc8bab7bbaVirustotal results 37.10%Heodo
2020-09-29DOC_CMO_090120_BWI_092920.docdoc 13b98d2f0d07581934fcff17efd69c9924d5cc1d0bb874c28eaaeb497cba7bb4Virustotal results 33.93%Heodo
2020-09-29REP_5009583467979956043475.docdoc 6f7ac22d800aed7da1b89ca41cf9288d41ca2d701f2bc69f206bed6bf832fa7fVirustotal results 35.48%Heodo
2020-09-29INV_OQPZ0CWLZLBM3U.docdoc f32f8b9e20a672922119f98f132c9fa7f52718da751a756707a788cc8f64d4f3Virustotal results 35.48%Heodo
2020-09-28FFPWMAZHCZD.docdoc 1fdcd8e253588b618783075095bff83fed0abcfb359a355750122d417f337993Virustotal results 32.26%Heodo
2020-09-28REP_55754662.docdoc 1d512af61eb402a20c9e93a49c64de0a8b8e170071b6a5d51c9e27b81e464981Virustotal results 32.26%Heodo
2020-09-28O3G10AZDTE95.docdoc 59e1adb95a67e6b993d26c058b67b01c98b0a4489a085a79ec203cce04408410n/aHeodo
2020-09-28FILE_ME56MJ1F.docdoc b2228c113565358749244babdf08ab1a60ce07c476644361178fc7cebc8e9423Virustotal results 32.26%Heodo
2020-09-28NS_83058245.docdoc 6b15cfdc451b71e4c59ab00cfd3ced8fb77f6724e3a813a9c66854a0603cb088Virustotal results 30.65%Heodo
2020-09-28G_00498425.docdoc 17d5a70293fb25971975ca6e3db5b2c8ab64a4ce026604b60278b18d01c0224cVirustotal results 30.65%Heodo
2020-09-28MW2581844623SY.docdoc f1128b4b115af957d794812accfa22e05ddd588d3fd52e5c72ddc7429468142dVirustotal results 30.16%Heodo
2020-09-28INV_59370608.docdoc 76a0317474e7c397a7a1303c212e28945ebc2d5fcd1ea7c8b9b6af0f50c1b535Virustotal results 29.51%Heodo
2020-09-28U_20339433.docdoc b980296b82ab20c87dcd75ad3d23f6ac750b16e0babb5eee53147d93c83a335cVirustotal results 30.65%Heodo
2020-09-28FILE_PO_09292020EX.docdoc 582f57c091cdbeb80216ba0b447cb9e9524da65ca308a91662202ff6966d3703n/aHeodo
2020-09-28RIXC_PO_09282020EX.docdoc abb57e259de4bfc3cf5d76479ef8c2ca2f37dbeefed25a83d47feea92e4d4283Virustotal results 30.65%Heodo
2020-09-28DOC_QQ0376994772MT.docdoc bceb1b46f7099731622c35f1e66fe7519b41666875e98060735db9253302753bn/aHeodo