URLhaus Database

You are currently viewing the URLhaus database entry for http://iclub8.hk/forum/archiver/5GxdL8eaaX0m1a/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:10444
URL: http://iclub8.hk/forum/archiver/5GxdL8eaaX0m1a/
URL Status:Offline
Host: iclub8.hk
Date added:2018-05-16 14:00:10 UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: c_APT_ure
Abuse complaint sent (?):No
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-05-18INV3743354692930.docdoc bbc89df919a5ee942cdf94a95b76f04a35d013a846777f1c12e18363a5900d38Virustotal results 16.95% 
2018-05-18INV525760845510406.docdoc 14d87d2f4cc7da3e45c1ce71fac8910fca1f87589307cdcdfb685700b12009c0Virustotal results 18.97% 
2018-05-18INV388329386290258.docdoc 50745686633d60c13056ec6423ca12f2c42a96ceb10807ff7f2070ad8ec3e284Virustotal results 20.00% 
2018-05-17INV54437938.docdoc 3812ca2c1791be4069dc09b8ce4cc3781810b8836e74952b70d88205fdd557dfVirustotal results 24.14% Heodo
2018-05-17INV41442653733299640235.docdoc f8cec2103456d4eed4bc6f144bef714e74b0183b706e19729e6b37aa2c84ee90n/a 
2018-05-17INV16312920776529.docdoc d4582df0dc9b7242534bd79135d4c85480adb2b59549279a7dedf2fd9a7bdcefVirustotal results 29.31% 
2018-05-16INV8541731826721069.docdoc e9725d1ae08361b7393e7e78d635650c8e73c069e2df729b0b10a8f9e5583729Virustotal results 17.24% 
2018-05-16INV529786042356341.docdoc c891b41e3e331f8982c116766d6bf9bcfd40a8333d4599e6b9515316d947652eVirustotal results 22.81%