URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xtime.hk/wp-admin/vWCTz-5dhRC_xVlY-DfG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:167339
URL: http://www.xtime.hk/wp-admin/vWCTz-5dhRC_xVlY-DfG/
URL Status:Offline
Host: www.xtime.hk
Date added:2019-03-27 19:35:04 UTC
Last online:2019-04-17 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-27 19:36:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:21 days, 2 hours, 46 minutes Bad (down since 2019-04-17 22:22:54 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-292019_03_DI803384794349243___42619380871437.docdoc 5e7bac49a57402d55155219a40378d2844f752d61287a19550bacaab853ba9d3Virustotal results 20.34% Heodo
2019-03-292019_03_INSTR44169077505442145___20381122492685131.docdoc 7fdd6d3f01b22f9877710c4a8d2af9396b12b1e7164cfca4027e0c4a9e309f71Virustotal results 21.05% Heodo
2019-03-292019_03_PAY77386651695075925___57425255458.docdoc 5c33e4cc4e661f50fe389db26b0e743170b70e09d788a18f5a4cdb1f7612e458Virustotal results 21.05% Heodo
2019-03-292019_03_JSK28589582152245044750___5058770215.docdoc 99abaec7f114aa7fad256b4264ba93b30392a5dae4a52af6b6e3b711721667d3n/a Heodo
2019-03-292019_03_93146466601135956868___96644392127123906400.docdoc 56993346a0e38ca5795eb761e74b3a3ae5611b68b63d62347cc16f7556ae34e3Virustotal results 19.30% Heodo
2019-03-292019_03_57655152407___853457929007034640.docdoc 59481a8827fc31c267669c6e0c12e4031797b696122d9c41f35fdda03df8b7bdVirustotal results 20.69% Heodo
2019-03-292019_03_U47604994819___88237210337876480.docdoc e90b47c43f4a2fddbd0252051c34fccb92a00d56cb210cc60ad0e4046a15f7fdVirustotal results 21.05% Heodo
2019-03-292019_03_MUNI32183681241___4719068617.docdoc a69a5aac05af96b852fa8818ea1b58cd2520b4b14c320923ded253ee82c3b932Virustotal results 21.67% Heodo
2019-03-292019_03_NMYG36109971159___04253219413509971.docdoc d8d62aec60829579e04cc6b6cadb344e1900964ef9101ad7cd46037aeef66b46Virustotal results 20.34% Heodo
2019-03-292019_03_60219864275___6967347214.docdoc 007ad9a413a85f6cfd21bbb42d7f91f49e8caae9c19eb46b454b8834546a83b8Virustotal results 22.81% Heodo
2019-03-292019_03_ACC2894161603___0392779352489.docdoc e185dae3edeeafc543826c544d0bbac8448198da0001882344f266697619b081Virustotal results 18.64% Heodo
2019-03-292019_03___US___PG4064552584___061127832727738936.zipzip d61ddb9c1fbbacb36809cb178ebaaf5929f6dabd5e206a5735196598b827f583n/a 
2019-03-292019_03___US___FFV4317143290___945993208.zipzip bfa6b8f4cbce4659b6a934b012342a4173446a87804f85aa369bae8f048f6bfbn/a 
2019-03-292019_03___US___558174971072874___30617072877252698.zipzip 1a02d51309a2700340388bc3785701e9a594aa57249b9d16b083b1abea7f3ed6n/a 
2019-03-292019_03___US___PAY6275042918666251731___71745047884886503557.zipzip cd1beb7c827b6fa7498cff6de1eccdc5c2e54c1e55cbc1822659a31194fcd334n/a 
2019-03-292019_03___US___PAY600351215819928___3680500174668256362.zipzip e13c5975a1d14b020e821c6c6c0f7b3460ebb1b5db89bb1e37026a3568b92de1n/a 
2019-03-292019_03___US___INSTR5209246198___3626277623161661326.zipzip 26752fda7098a128e69c5fc10db6d73a5e733c123dc7c1e4dfd03096d7a8af9cn/a 
2019-03-292019_03___US___BMLV7404003960891___58085674244840213450.zipzip f068ab61c5e48b9fe4e3211cb247bb526fb10c0f95707f73757b673067954696n/a 
2019-03-292019_03___US___ACC611689659652945272___3594337179951892541.zipzip dceb417eb8b15b7a44e88b8a13a42565abbb71a0362f3cc826c79c2745359d7an/a 
2019-03-292019_03___US___PAY44726306771___403977247872461.zipzip e8c70dfcd016c283cb87bcb7a0915acde2dc527abccae1ba6ad2404fb9cd0347n/a 
2019-03-292019_03___US___JR711179467___37461604184465100.zipzip 8a6c82e899fb95fda16b15909a1ab844b5ffa030d6bc753683ce401603293395n/a 
2019-03-292019_03___US___US612721938976196858___44741935979637451.zipzip d9eb2d446497f5b9f611b6823a643762ae1dd4fa8138ee10bf03123fc819c435n/a 
2019-03-292019_03___US___PAY96328052474423628___35463832835.zipzip ce094148aea2ad188e2b3dc56cce1d74e9a0f022ee75bcccbc044d24fe4fd1c4n/a 
2019-03-292019_03___US___27260590928___697153355005979.zipzip 6860759e5897368ffa97b7c62c254f159899557862b42bdb0a8adea761cb6968n/a 
2019-03-292019_03___US___ACC897520306751___9722166934639.zipzip 53056f5a77104a0167a6ac1a7e876141789e1c41b964ab45ac06de20273d05ffn/a 
2019-03-292019_03___US___PAY29901763979354467996___931311872061175.zipzip b7795c01e902c08f2ac5e5f8b17e6c8636a969cdb96b0dedce06d63efc24d4e9n/a 
2019-03-292019_03___US___42076931931457___542058016.zipzip 951be1b74b81ee7fd99a5ad6e794079c878e49dd53f71c2093bb208eb0005ad7n/a 
2019-03-292019_03___US___389768116___053974664258137.zipzip 2cf20fd6f37dc5ec9a0711ce32079f2ae2c8d25b67103cdb0a95aece4726db97n/a 
2019-03-292019_03___US___US841125044231845100___52457854416450.zipzip 943b762704668e8772c24579ed77bb49e486891f70c7286c9d17aaea7648d136n/a 
2019-03-292019_03___US___PAY10179960689171___09618896451135.zipzip f5bfac6ac1c59b274c9f87adada3012e1785262b878090c481244a87ad733c01n/a 
2019-03-282019_03___US___PAY29306816569___48429340140862908082.zipzip d43510f5e3dd4d0f492fd10cf1d3c82d8d7072991c76c23d79db141f44bf050en/a 
2019-03-282019_03___US___WPL037627080153___535580784762.zipzip 5d0ca41d162b01642ff9fdc4110b6534ee14ad54394c689143b26f8fb58083a4n/a 
2019-03-282019_03___US___ACC541122431965381___943753733945.zipzip 81d8b856296e6e93ca6f32d4197efa8399ee06ee5086eb60707cc7d4316c63f7n/a 
2019-03-282019_03___US___PAY40385897722854241572___4740777951523195364.docdoc 87698079ef2b9a3ce0ff2c16e9039e847a81bae4e0793b005c72a443683d28f4Virustotal results 21.43% Heodo
2019-03-282019_03___US___ACC2644723646___3025073518522418.docdoc f3adf91c3cd1e972bff7f230f24729c6e69737862b88b491720f05a6fda282f4Virustotal results 19.30% Heodo
2019-03-282019_03___US___INSTR917305611___182265176.docdoc 235617c4c46b0eb57a53bab6974f0e81512bf2be9c487156640919032afcf477Virustotal results 24.14% Heodo
2019-03-282019_03___US___PAY3966153456404___183925224247482160.docdoc 55272816d957c8d610f15e20aff8e0f30f8ae00e9cdfc521a58e7340c260f589Virustotal results 18.64% Heodo
2019-03-282019_03___US___INSTR5578986094317___007418217866262978.docdoc 17139a0b1e99a41443a231820173404850d3ee4093bcb4011cc71f790d1f9f09Virustotal results 18.97% Heodo
2019-03-282019_03___US___8464363571___97453687684206019.docdoc 180da596041ae834c159756ad0f84c97f0ed63cd08abc7cdafad1d1bc83caf7eVirustotal results 20.37% Heodo
2019-03-282019_03___US___V578849831___479013682623.docdoc 24ecfe71f85e9c8d734e8438171c62e5982fa9962e28600f2dea828b91d510b8Virustotal results 19.64% Heodo
2019-03-282019_03___US___ACC689446796915851___054731537479544982.docdoc e9b57e2b29288ee0c219029141219b9064d8021aecf255cc9ea41198486daa55Virustotal results 19.67% Heodo
2019-03-282019_03___US___INSTR38046180441539417428___33025556226.docdoc 7d805fd6032eb14134efe16f128638bb6ea296911ad55fac6340ace72707f251Virustotal results 20.00% Heodo
2019-03-282019_03___US___94788804344365254___575631993285631.docdoc 1da44ccc2eb250ca1283e6b12e92d326169112ae88c9b1b9800fa1868257628eVirustotal results 20.00% Heodo
2019-03-282019_03___US___ACC90448789555085134299___834334943489622595.docdoc 084d0997def7560fa87cb31751f21177cc3d0efc904a4901472b2cdb5225ee5cVirustotal results 20.34% Heodo
2019-03-282019_03___US___ACC35020224450766698___47321962921087159.zipzip f2eebc8a7c96f82559c2d76c45b07d0afc4fcfe9721be1a506a4e5d5f0f780bcn/a 
2019-03-282019_03___US___INSTR302986064335___049867047484528161.zipzip 6a512ced54b6d33f05a6482db3cbd5aa520cb90aa281a3865cc25f3845f1980en/a 
2019-03-282019_03___US___PAY56990707695235___48135141394.zipzip e08fa6a5d335450ddff5b95d6cfe01e37aad9dc05a5404a28b46950b93fe5f63n/a 
2019-03-282019_03___US___INSTR4993935169375162049___707641201663719237.docdoc de63afa47476b9b004e6895584048b955b65c608bda044f359e654e9997fcd51Virustotal results 19.30% 
2019-03-282019_03___US___US57755693234881378139___2399566787367700744.docdoc f7c389a98aa92bea8e2dc4f4c99a310a8351ab4dbc636cb4c41b00df79ea5c95Virustotal results 20.69% Heodo
2019-03-282019_03___US___ACC91471433182943___9046162528271626118.docdoc da6b8f02973ef4e3fd130c144e7051b7cd7e80a521ade52492b859ec517978b8Virustotal results 19.30% Heodo
2019-03-282019_03___US___ACC628343797533642488___78476187041451954843.docdoc edc146112180155f75d4c47734bd5a6e552481df6e7b9307c939157365c2af73Virustotal results 24.14% Heodo
2019-03-282019_03___US___ACC5811911430312012___53993450721623615.docdoc 9a86d9a82a87e2510fe2814eb2afa2c3af8c73077ebbaa6b785f23148e4901a4n/a Heodo
2019-03-282019_03___US___162979766___24700815873.docdoc c73b153ac9cf42cc3fada057a60486d5d9c55934621f5808ae659702c8f179c0n/a Heodo
2019-03-282019_03___US___PMAX0631733010821___1082929089.docdoc 2b9604bae3248d8a134c549e86ca36649cb5e558a08e9e2a60d476a31b0294e2n/a Heodo
2019-03-282019_03___US___741092608926999105___8085905978124459686.docdoc 939fd6d752669eeeb3bf135cf1a64fc38fb3ae650b85f1fe3fa471100bb28981n/a Heodo
2019-03-282019_03___US___21306633366413657___1484959882409511109.docdoc f8209146b3ba58be520594e795a4207eb5e76282b9f9b4722e6dc3d18fc1d4c7Virustotal results 18.97% Heodo
2019-03-282019_03___US___US78394911939253___3466019686.docdoc c0e334e36a81f68f1c858422edeb2452483b808e2f72e2de289b14f90b6d4269Virustotal results 19.67% Heodo
2019-03-282019_03___US___K090604708971___71563281421687819.docdoc 3f4af62e65ef4eed255a1cfdd1a2bcd54ce49e3f7b80997ccf1184e0191b697bVirustotal results 16.07% Heodo
2019-03-282019_03___US___PAY347719039008917___50191077377024552078.zipzip a5b0505d47acbf8d88e228af6e44d2ec3158bc9cee81fd89464165e99faa5780n/a 
2019-03-282019_03___US___ACC737372883___1822857660.zipzip 1c74047224aabbea6205022d2cfab88b2477c21c75831fc8661d7a1c2389041bn/a 
2019-03-282019_03___US___US4936591874486___75870003546999.zipzip 6ae74e540c6ee7a0f5e2416bf127cbe99df46590cbee9114280d2a7273d34c45n/a 
2019-03-282019_03___US___PQNKO7921158726___9741806587511280.zipzip f6f52e560bbb90036cb47de96d6ebedbeb91d8744c24ff15441265ca3b710debn/a 
2019-03-282019_03___US___ACC542464330___91434450020410008207.zipzip 1c3e08614e5f88ed1a2bc1f17d43df4d567ea2689cd56c40853c990b5e7bccc3n/a 
2019-03-282019_03___US___8407195706137783___006080536079398730.zipzip d456f8b70df8ab96bc1098752b8573950aff3ee77525907d23dde4ed6a7f553an/a 
2019-03-282019_03___US___US42642042685___4652039313.zipzip 4b4517bfb604b07f21e39013ee66fd4ae3b560a9890e30b8d659c3a1d71d8c93n/a 
2019-03-282019_03___US___US082297437990___679684039791073.zipzip 1cd3754ba9d93e9072308d16e113032000d06fbfd0800f740e149973a350dc35n/a 
2019-03-282019_03___US___TXTC496218393___943537145557371.zipzip 7e61065f241e7dd74f7f900f81a9b4ba0113c534f8dfe0a19a597204be1b89aan/a 
2019-03-282019_03___US___PAY421739149919___9515709128675.zipzip be361f06a0e7b069ded7049b566ed2eb3f40978799b9b3a5002faef03eb5fc61n/a 
2019-03-282019_03___US___US626458603439501539___615290521.zipzip 0711b88c13d1404ffe0a85748254d475f6788f4ae868c632f8fa0439737dedbbn/a 
2019-03-282019_03___US___SU127959472406108288___513227845.zipzip 972310158aa01216adf420fbfa40c29383eef1a6ced4bf476b7416d64fb8e599n/a 
2019-03-272019_03___US___ACC5412342851___255651623.zipzip c30cde3722d143cc686ffac0dd1e1f9cd8b48414de638ba060e9736a5e40435fn/a 
2019-03-272019_03___US___US910365388771___5860424794282.zipzip c303243ae162f3caaa6fecbd78530e3b5b6aba88e282110d7880c716a4f4a31dn/a 
2019-03-272019_03___US___INSTR4908718842128109___0309662430433542.zipzip e7ff0bcdc82003fbf896a4edbacd9dab229d03dbf034a8731e798cf10f005f16n/a 
2019-03-272019_03___US___INSTR244868746___771084422143962284.zipzip 41b18a8ab2450609861f8ac2e1e5f5f1c08eb10de78eaf586d9f2134df2d2db8n/a 
2019-03-272019_03___US___ACC0622718332024___13904165206.zipzip c415f776f65ea6713c95c19d4f3566efd48b1a4924296632c8b12a11a505807dVirustotal results 23.21% 
2019-03-272019_03___US___15073370202___32919521159916.zipzip 7f55d26d4acc92faeed4fbd488801ef8f47a93713c3360e8224bd0f27b75f472n/a 
2019-03-272019_03___US___X395952389108___87901958107237.zipzip beaa57f50584cf67d3e9d7fca1ef0d5fd7acca94b38de614b7072cd4f9dd9ff1Virustotal results 24.14% 
2019-03-272019_03___US___41726618199216702134___28687368120480390.zipzip f23607c9675cc9fb9a850550b2cf39276451c0a4622e40bf02735eadbaa63d90n/a 
2019-03-272019_03___US___PAY640805079389471922___30430468026112.zipzip 1f9568baf27caf4072648c6f7feaa6b9544bfbc9bee0de6e69d17c04446783c3n/a 
2019-03-272019_03___US___INSTR9691210959781438255___46405033788113540.zipzip f225ffbdcde47355607b946daf21a2ad38b574c11f2e6c01eeeec976997ed698n/a 
2019-03-272019_03___US___ACC71778182915___11119915253477810121.zipzip 3f10166b67ba0eeef30449252b43fb8cd8b5df73901dcb34da78beffd576b444n/a