URLhaus Database

You are currently viewing the URLhaus database entry for http://mail.zeefinetech.com/acatalectic/browse/Y8hH9yYm5tSZN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698212
URL: http://mail.zeefinetech.com/acatalectic/browse/Y8hH9yYm5tSZN/
URL Status:Offline
Host: mail.zeefinetech.com
Date added:2020-10-15 17:42:04 UTC
Last online:2020-10-26 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 17:44:06 UTC to domain-contact_ww_grp{at}oracle[dot]com,network-contact_ww_grp{at}oracle[dot]com)
Takedown time:10 days, 21 hours, 56 minutes Bad (down since 2020-10-26 15:40:50 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17FILE-2020_10_17-S6261.docdoc 294c6f87d8514072c30988bd55dd643c5c018b9f9ae05b9db1a97d034b31e092Virustotal results 55.00%Heodo
2020-10-17Rep 2020_10_17 16498.docdoc fd4a45974318a540bf249d7aa768f6d4ec1bb268bb05e5028935db34aff711f4n/aHeodo
2020-10-177017EMJ-K77299.docdoc cbabf68dbf69bbc9e13cf1c4decc549416db53379348b45da4b5fedff65152afn/aHeodo
2020-10-17Doc_2020_10_17_YHO267415.docdoc 8763a9868e952dfb5be76162ed10b0d62fa00e1ba5baebe53f7cca486cb89542Virustotal results 53.23%Heodo
2020-10-17list-2020_10_17-6192939.docdoc adbad3c068d4497ae8a6a18056cfc39fb152c2085f694dcace8e772cc1867f22n/aHeodo
2020-10-17ARC 2020_10_17 391478.docdoc c8647133e45a641a9cefb6726994df00dcfc9fa481d38e667eab8f74f75c54b0n/aHeodo
2020-10-17INF 20201017 213407.docdoc 90e7a0a9f215c30d103034801a89e4b61554c48bff10a98df0d09257cfc716cen/aHeodo
2020-10-17rep-2020_10_17.docdoc 971e189c279099a876618c3226ef35e5afc62b91daf3b8bde466a424fdfaa063n/aHeodo
2020-10-17UNTITLED_2020_10_17_TX1079.docdoc 3b4872190aebbf74f2d47fcc2d043a4715838ec3148f56fdc7034c991b73949aVirustotal results 51.61%Heodo
2020-10-17MES-2020_10_17-760444.docdoc a2694945dbd5fc7e3bc4801eea70491938e4e9426b60bd80625312d3f3a7962eVirustotal results 53.23%Heodo
2020-10-17Attachments 2020_10_17 0008.docdoc 115b344de8011d635adae59417a4dab2f992101ce81619ffe1b1b0423d9df79an/aHeodo
2020-10-17Rep 20201017.docdoc ac172c6a7fb2f8004f019c9dd8d7400f660d58187ed3adcf2502c5effc15271bVirustotal results 51.61%Heodo
2020-10-1779369DJ_2020_10_17_UTB038937.docdoc c64264c7336d7e9f516999fa287be55be63b634b63f5ebbf1bab24e38ada5e8eVirustotal results 51.61%Heodo
2020-10-17Rep_20201017.docdoc 65fe5c36c465cfa1cc58f54aca29a2da9e56f3fa0b499ff8ae0b654338db114bn/aHeodo
2020-10-16list_2020_10_17_PA396178.docdoc 113ad60c6cf207f078325f4bd37200b9fdb820ddc2bfeac79a49a347aae1308aVirustotal results 51.61%Heodo
2020-10-16FILE-20201017-114661.docdoc 39319e4e0e23653363b81024b93090dbf717424cc2dcc3c0291e6e56e3328ed2Virustotal results 51.61%Heodo
2020-10-16Arc_2020_10_16_J628.docdoc 0d613e3b8dd87abdca992787394ba93c986820dd46d13b63128699ff814aa6e7Virustotal results 52.46%Heodo
2020-10-16arc 2020_10_16 AYQ12018.docdoc 14fb23d425064edf96ba4acb656479002d69054eccbae3688760eda138dbb67cVirustotal results 51.61%Heodo
2020-10-16dat-2020_10_16-97369.docdoc 0f3f04ac85e78d80efbda9617f67a8790049ba50df890fc992c9b0ea0688cb96Virustotal results 52.46%Heodo
2020-10-16Attachments_20201016_524.docdoc de085b2aa71406dd284396b50a4931dc24c0648c58b6b5f8dc22b9d7b2d491d7n/aHeodo
2020-10-16rep-2020_10_16-388.docdoc a1d573517ffbaeff20370dbfc3a3c7ae1abfcbde0154abf7010feae3d2911f3bVirustotal results 50.00%Heodo
2020-10-16Attachment 569.docdoc 862ce05b2f4d570225ef0b53b414638426a854c01a5ea7405554ae43e7206950Virustotal results 49.18%Heodo
2020-10-16dat_7006928.docdoc cd64bc23d4d04318406357db3c760bd5cc9b8eb88659b2df36be6d823fb0bfddVirustotal results 48.39%Heodo
2020-10-16list-2020_10_16-U446.docdoc d6a39bdb97baab89afc48245f344e08873c19e0e92da5841f6f3afdf899d735bVirustotal results 48.39%Heodo
2020-10-16doc_5200.docdoc d256ae49121d11c0494770e833b518932a302d465f80430b058c8d0584438c4eVirustotal results 48.39%Heodo
2020-10-16LIST_20201016_48071.docdoc 3eaa0b65ba2011470369ab443b530cc881c190b9504553bd9944dde2e377e698Virustotal results 48.39%Heodo
2020-10-167490-20201016-18383.docdoc 1cc8ccaf21f72d5aee417cfcf2102f4b5bd1213bfd52198ea91e30db4995e85bVirustotal results 48.39%Heodo
2020-10-16Attachments_2020_10_16_V0036.docdoc b8fb1c34806bb5e82591e936edc95a15e5fd910fbe6d4c97b2a9ea1627b1b0b0n/aHeodo
2020-10-16LT1288 20201016 PE2046.docdoc 0b77465d88f1cdf6745bfe68c62d8aad3f9adaf70da78396cdc99cd36235e0e7n/aHeodo
2020-10-166464-KU228.docdoc 56521a08dcd3eb2911de6c97551da434a6983d232f6d33ee36578865f7f55adcVirustotal results 44.07%Heodo
2020-10-16file_20201016_164913.docdoc 18f9f98dab8623a8b0c06b6d25747d727601b4551df382ffb88ff536f6df2762n/aHeodo
2020-10-16DAT_20201016_X755.docdoc 58650f87223839221d663ceddbae556c28b9353be73c88903e9a69abbac437b6n/aHeodo
2020-10-16rep 2020_10_16 2371.docdoc 94f9d064a654c11dfd64a500db871e2fa948243c8fa44e8a324ae7a541d45246n/aHeodo
2020-10-16inf.docdoc 9029f51418d74f465e016e0b2791ec9cc8a128ad3c7bc2cbaf5d07a5e9ae84d1n/aHeodo
2020-10-16Inf-2020_10_16-G2966.docdoc 0d8a6d854e14a57fed7fb1f39c731fcc825c411e22410ba84b0f771f327df08fn/aHeodo
2020-10-16Mes.docdoc 4559cab22420423717b0288449da9a3917e33784e3e778e0f3b0818e72c0b346n/aHeodo
2020-10-16Attachment 20201016 457116.docdoc 844fa7e2e8ddb967031bb8b2907076c09e64e5a9119bfa53df5303338b159265Virustotal results 37.10%Heodo
2020-10-15MES-2020_10_15-9257653.docdoc f3c842ffba1a274c8760d22c355b836f2fb7e28a43ae083a3e7a6c63d2be86b2Virustotal results 35.48%Heodo
2020-10-15455 2020_10_15 655406.docdoc 3513f9896a827f210e45287cf03b3f9b22b065e285d2a9028b16e1aa243264beVirustotal results 36.07%Heodo
2020-10-15Mes_6002253.docdoc 9ae69cd7d338a1bc63c6e039b029e3b25ba9d0ac381297144930b823f187a772n/aHeodo