URLhaus Database

You are currently viewing the URLhaus database entry for https://kimjikuk.luxeone.cn/app/77P/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1994005
URL: https://kimjikuk.luxeone.cn/app/77P/?i=1
URL Status:Offline
Host: kimjikuk.luxeone.cn
Date added:2022-01-20 22:19:06 UTC
Last online:2023-08-13 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 22:20:14 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 year, 6 month, 29 days, 15 hours, 42 minutes Bad (down since 2023-08-13 14:02:15 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21896108059019999308.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-215604144299215.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-21658064252270.xlsxls aba8e5024172cc0cd240eda2c379e91825cb922f0c5d56d82a560dcb15eef097n/a Heodo
2022-01-21653263054588388301.xlsxls b8fef9073b247386d53e1eba4723994cf6300b257f2b637cb1eccead6b68904cn/a Heodo
2022-01-2100837591950773763011.xlsxls 7efacaa6dacfe6bf20d27faaf86184458461e64165c615cede70b42cf913f8aen/aSilentBuilder
2022-01-219984149009281410371.xlsxls c60a6861fc63f90b9f872e0bc131fa85f6af0daef37063eadf6d10890acf3bc0n/a Heodo
2022-01-2160492617892882600.xlsxls d1f5ad731dbf6263cbcee95b142ffb0ebc190205ae58d4a4948bb3e5ad09e4bbn/a SilentBuilder
2022-01-213972936283988449728.xlsxls c3496d8e7d2ffbb343cb44911bd859ceb08cbac8eb09ebfc58ce6cb1208f2d8eVirustotal results 28.00% Heodo
2022-01-216171286612058720.xlsxls 6027b0c0ed3191c277bd14f9bfca0e7110c5b306dba6bdc3e5bf123d0b31e6aen/a Heodo
2022-01-21186404322345.xlsxls e06d794800a6c8e29eaee2ec0e2ccd9f60b00c7d6c9b4a80ce605a4c156f9982n/aHeodo
2022-01-2191240333835.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885Virustotal results 38.98% Heodo
2022-01-21204604962056951.xlsxls 702e9fcc889535f1c31e1bad34de6e4456520ca0687f9240a318140924bed3cdn/a Heodo
2022-01-210835378954560.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-2159633010548757207137.xlsxls 053d625d162a5e1ad61603ca7d6dfd915cc175e991eaf3377a55b00853fabd07Virustotal results 30.00% Heodo
2022-01-21010212033539283.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-214583959385969.xlsxls 2847438e4b48ee5f630b8d0a3d5361bf4071aa308d8999a69cba995fa548add5n/aSilentBuilder
2022-01-21296712728661.xlsxls ccd9c6eef79a18615ba690a35d8a2f238ef0d6cf1e715536299b42f9e67357d6n/a Heodo
2022-01-211805736796609219.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-2125737726340932133455.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0n/a Heodo
2022-01-21613144743636639142.xlsxls 278e2b44764f4223799867c585d886b7fe57313055f5f82d983f7e13e1a49aedn/a Heodo
2022-01-217344282861123109.xlsxls 3accfd2337522a6c68a1018979e3ac6603237e13aff0b962ae093662129d8609n/a SilentBuilder
2022-01-21706842433481.xlsxls 4520398e8aeabb1aed9cd4899a2ac014545d9ad9383959288cf2470f9c1c4731Virustotal results 22.41%Heodo
2022-01-212080801989.xlsxls bf377a8c8ae5170949a1ea2d2f8fb6d63a24839276a2fd63bc2a4525f1839a59Virustotal results 24.56% Heodo
2022-01-216020610113099.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874n/a Heodo
2022-01-2122875628973362.xlsxls 01bab18ffb7052e8d67dc6447267ec775667a721592e609cf62dd08649d7a807n/a SilentBuilder
2022-01-2187216015238463.xlsxls cb72aea24f710a0d9b643de1e759ace18205bc20aa8aa7a91ecf20e556cad41fVirustotal results 22.03% Heodo
2022-01-212876213521808852.xlsxls 2d259bd946fb388d1a7d75d28ba591aca3377e0ca8b49e0add414fe82b76f483Virustotal results 20.34%SilentBuilder
2022-01-203049353590386.xlsxls 2181997083632b17484474d7152e18c8a65175b823c871b164d15d2e20a8ae16Virustotal results 22.03%SilentBuilder
2022-01-2081755037247482877147.xlsxls 39123bd1932920eca6749593bee628c405f8bb88114d8647a5d9db8b5914f46cn/a Heodo
2022-01-2088381294553876.xlsxls c3782f393e6dca8cbded5a7bbb73789792cd1bf807f4f71cd863b12992beda95n/aHeodo
2022-01-208736699248.xlsxls a72795a18fa2b90928f307e227b1f1a57590672870b3acc9e8cb0eb4d38bdbffn/a Heodo
2022-01-2092244863304383.xlsxls b069423ac3753a4878bd652c9c55362c541db7529bd0b294ddc47bb7c6475946n/a Heodo
2022-01-202074297684825210.xlsxls 0aa692cc9abe6360ac72502a9f27fb0e3d401153dfe067524c82c56b7e5f8625Virustotal results 22.03%Heodo