URLhaus Database

You are currently viewing the URLhaus database entry for http://steveleverson.com/Dzre-ziim4C25INDL2Y_JqqCxPUDZ-lu/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:95410
URL: http://steveleverson.com/Dzre-ziim4C25INDL2Y_JqqCxPUDZ-lu/
URL Status:Offline
Host: steveleverson.com
Date added:2018-12-14 22:48:48 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Status unknown
AdGuard :Not blocked
Reporter:@Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-14 22:50:25 UTC to abuse{at}godaddy[dot]com)
Takedown time:11 months, 20 days, 13 hours, 30 minutes Bad (down since 2019-11-30 12:21:16 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2019-11-30n/ahtml 6e380a1b7e998564dc2a66d6f1670ed2cbfa89a9bccc3314f53045afce1cd0d0n/a
2018-12-15BIZ_027HFJAERV_12_15_18.docdoc 0dded430c1958ae0ec60c2d50ab99f562269ad1ee09db17606661bd55cd29c66n/aHeodo
2018-12-15SWIFT_9MHZNNZD_12_14_18.docdoc d0b670c53d9dd3846aba8d5883154ac6f13bcec166df3b87cfd44ca4fc8d8625n/aHeodo
2018-12-15BIZ_5384QQFSDAO.docdoc 41d9e3bb2d0e6a22f6ae4fd7860244c0bcb8dc1ef67542d7f274fa60e252f37cn/aHeodo
2018-12-15BIZ_0UUFQFJZ.docdoc 2ff34ee487aa8eab2df5be9b69e263a5a24c90c938f72d5df7232a6fb2fb350an/aHeodo
2018-12-15PAY_8XBMJYP.docdoc fbff12abf849f5e8cdd69ad3138ae675bcca493682552f16f45b34daed6c991fVirustotal results 36.67%Heodo
2018-12-15BIZ_600019VHSQJZ_12_14_18.docdoc 28aeb0d752d3483afabaaa6db205bef92ae89904583fffc1a6334ab27d9dd491Virustotal results 33.90%Heodo
2018-12-15PAY_27JTENQCHD_12_14_18.docdoc 4ee3e7905a8bdd8f6b53844f1a758b41e8db40009e04f1cd53418558ad9806f4Virustotal results 36.67%Heodo
2018-12-15ACH_39776MHYNPCC_12_14_18.docdoc 592ce7de71bfe682b196a02bd1a8cd0880053e15a13ae5bfa7a7c2ee01be4474n/aHeodo
2018-12-15SWIFT_8734ZYLEJAYV.docdoc 592247ff870494ffe2132d96dc4adb5a0e927d5acf9a8ca55dbd260395b70d58Virustotal results 32.79%Heodo
2018-12-15BIZ_65MQOXIMT.docdoc 24e15f79c89f7faba99ddeaad817ef9b3deeff1782d43d1d2403d22d4f57d6den/aHeodo
2018-12-15BIZ_3205ECVQJHZI.docdoc 83cb7bba95779dd6443ae9c7b928b9d45c9cc56e1a7dc6d6846fd1379094d893n/aHeodo
2018-12-15PAY_1078875ZETPID_12_14_18.docdoc 59351b32d196cb654b9bc18c62b82b1f2cf1ca50cf9b2e984756d39c130b0fdaVirustotal results 33.33%Heodo
2018-12-15ACH_4329WCKLXI.docdoc c2a0c517cc9be4d2979f5f7a2f49d4f163f6c3d468bd5eb3c4c686fe71338797Virustotal results 33.90%Heodo
2018-12-15BIZ_927GEQFBF_12_14_18.docdoc 0977160bd8b66fa2bd8433e7973308ae322c03705fda13606cacfb6701eb4eaaVirustotal results 33.33%Heodo
2018-12-15PAYROLL_500OEUOOE_12_14_18.docdoc 4c574446cf3632f6e1f17d8fd3799abaec72d6675b88e40d4ea8a208fd0c6bd8Virustotal results 33.33%Heodo
2018-12-15ACH_8091CJBHDFF.docdoc d48567a84097656cc25b0b3d512a73e219262fe394b305512b24c8b489840d1eVirustotal results 31.03%Heodo
2018-12-14SWIFT_4KXTDVL_12_14_18.docdoc be849032d67a24eda952c62593d2c6d991500c0a8e628fd189fa9ca51a221cdbVirustotal results 31.67%Heodo
2018-12-14PAYMENT_5589OWIOIWDE_12_14_18.docdoc 866e87bd9d1fd9e7b89e86fffc3838c98b0765246aa63f6a912a5bc213c82f10Virustotal results 32.76%Heodo
2018-12-14PAY_1055LWAYQMV_12_14_18.docdoc 2fd64d6d32147411b247ed7f83fe69d4555b581786cc331ade0b524990da4d7aVirustotal results 31.67%Heodo
2018-12-14PAYMENT_108592KXDEYVNG.docdoc d9df70d18ace618d9ed5f4be2e0c39c572e284e3dbdb8d5a663474904d89c98fVirustotal results 32.20%Heodo