URLhaus Database

You are currently viewing the URLhaus database entry for http://lizhongjunbk.com/wp-admin/Document/FCcqZkSkfLPxCzw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:200854
URL: http://lizhongjunbk.com/wp-admin/Document/FCcqZkSkfLPxCzw/
URL Status:Offline
Host: lizhongjunbk.com
Date added:2019-05-23 16:38:10 UTC
Last online:2019-05-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-23 16:40:03 UTC to esabuse{at}hkbnes[dot]net)
Takedown time:1 day, 12 hours, 26 minutes Poor (down since 2019-05-25 05:06:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-25INC_1189114675US_May_25_2019.docdoc a9725b7c79250955489c7f9b0ec5b21442115905140a1789c0bde677b0299345Virustotal results 26.67% Heodo
2019-05-25INC_66825718138US_May_25_2019.docdoc 29424f1cd19d0f0cb50e113f86e05d490a7071e6494fdee88af2a118857cae0eVirustotal results 24.59% Heodo
2019-05-25DOC_606218803470US_May_25_2019.docdoc 8d262e11a4d725c4e1282a2702fa6f6afe0dcdd86703fa51c3dec1ae9022c698Virustotal results 25.42% Heodo
2019-05-25INC_486005959613US_May_25_2019.docdoc 440b4d1d5d1443527fe29b5f142f81cdff8839dc09c2cc5cbe98c286a43759ceVirustotal results 25.00% 
2019-05-24SCAN_45320999944US_May_25_2019.docdoc 291dbb3e3d38f1528818833172bfbc0e2df1384ac9c4ccf92b35d12ae6d84e28Virustotal results 25.42% Heodo
2019-05-24INC_5162271649US_May_25_2019.docdoc 029ed07a45381598787146791bce6a8f20b2b500d19de4bb085e6598bb7b4dc7Virustotal results 25.42% Heodo
2019-05-24SCAN_2891199822US_May_25_2019.docdoc 166bad718e33e95490d5f4167175bf6c7600202dd8f4722d05125633db4adf5fn/a Heodo
2019-05-24INC_43072963823US_May_25_2019.docdoc 8da7abfdf789b3c62c9fc92a804d33b560d602bb2a3504eef6ab9168bdfb307fVirustotal results 24.59% Heodo
2019-05-24LLC_524957336395US_May_25_2019.docdoc 1e598d7a619361c5861a4f3e78d0c158daa23e869c771268e7de1f9ed0ae16e7Virustotal results 21.67% Heodo
2019-05-24DOC_78874340123US_May_24_2019.docdoc 43fd2fc7a0461750674256537ed35b76623eaac07ef086a13b0680646fb7df73Virustotal results 21.67% Heodo
2019-05-24Document_778880426462US_May_24_2019.docdoc 8aa364c7794389dc2b488d2fd90d4d791a5ed2710559912912d3c84c50a468c1Virustotal results 21.31% Heodo
2019-05-24LLC_729424116235US_May_24_2019.docdoc 8a0f94c4e0b04081a2f7fec8c6c001f903092a1110f07f46e1d2d1cdc77f2034Virustotal results 21.67% Heodo
2019-05-24FILE_553022587453US_May_24_2019.docdoc 00ea2e24de5e4e9a987fa8b235fb538e49b85fa64eae3011ee9ff44476213b1aVirustotal results 30.00% 
2019-05-24Document_5122635640US_May_24_2019.docdoc 20b919f24f70de2089a215d35f6ded75a5ba149fa5f8648f107c0a5a952b5ce1Virustotal results 26.23% Heodo
2019-05-24LLC_90855497739US_May_24_2019.docdoc 4b9fcd4189fdcab7434f28b57e585c9fdf6877065be361ee2bc7af7d14ace897Virustotal results 23.33% Heodo
2019-05-24SCAN_563665665669US_May_24_2019.docdoc 52113ec28c47265a473c2970d769c75baac1058bb9b5e3ec457e0c4f3b624c37Virustotal results 23.73% Heodo
2019-05-24LLC_096833126746US_May_24_2019.docdoc 08a71f81b1366785734f4c1db8bd5f92ec36f62445cb5a25afa6c0dcf5ed210fVirustotal results 21.05% 
2019-05-24INC_81604055678US_May_24_2019.docdoc e951c3db59142c02ebeefc5506d08626bb57dfde2b846c9afd21ce31bc2cbe8eVirustotal results 21.31%Heodo
2019-05-24FILE_509838467662US_May_24_2019.docdoc 65cac9c58fe03445f4ccd34499fa8c6951d85555d241818cc5a4d6037c062550Virustotal results 22.41% Heodo
2019-05-24Document_3669262209US_May_24_2019.docdoc 67f27ff168d34fea798552774ec1859f7ced8ccc9382fe2becd8f806403ee4beVirustotal results 21.31% Heodo
2019-05-24SCAN_263576715790US_May_24_2019.docdoc b0ba612cd5282fe21e64b6371ae76df59dd2d3da7541203d93b0202b426154acVirustotal results 20.00% Heodo
2019-05-24SCAN_616480959561US_May_24_2019.docdoc 55c4c3f89a961e9ba055e47b5875b7a945b97aee146f522c9a9f299dd989137dVirustotal results 20.00% 
2019-05-24FILE_169915186762US_May_24_2019.docdoc 32fbe8b5ba34d19c1be8b639490376bf5baad31f95f0fe2adbcaa79310a57347Virustotal results 18.33% 
2019-05-24DOC_54974366556US_May_24_2019.docdoc f3a97d8d40d49941a21e35c6fbd71e230ea29f8f1c478b4da514fb82eea8eef5Virustotal results 16.13% 
2019-05-24DOC_788304481748US_May_24_2019.docdoc c4b525a4ffb61823a7dec6ea0e121c025a2049fdb681f5f7320e60e6dd16e75fVirustotal results 16.36% Heodo
2019-05-24SCAN_381750238890US_May_24_2019.zipzip 8abd280fff79ceac724025ff269f7c00f223a6f58dbce5f4aff2f01f6e48e856n/a 
2019-05-24INC_953187599876US_May_24_2019.zipzip 0c3fdb867eb43ed372376d912941e1b7dcaffebb05c82397165b3c2cc382cf50n/a 
2019-05-24SCAN_2218726722US_May_24_2019.zipzip cf74c63f2cccd4deaca83bc0fd68876a907b67d9d61e97a521daf61812520162n/a 
2019-05-24SCAN_3165676222US_May_24_2019.zipzip a880fef380cb9be27a368d1e8acd25195b676e5415f55eccd91d0c5f70752e5an/a 
2019-05-24SCAN_391325126184US_May_24_2019.zipzip 4de8600b6ef501a0a55091b137be57494a2826419474623ff62703561ed3b529n/a 
2019-05-24SCAN_9281083672US_May_24_2019.zipzip 9ea45ac6f8f36d5c30d0a096726710de0a21a7a921147600e24a1cb99f9154b4n/a 
2019-05-24DOC_0197836223US_May_24_2019.zipzip 45ed2a90ac4e0856fa0cd4f44ac9e21a255611ddd68091576ccaefe516fcc6afn/a 
2019-05-24Document_39997384118US_May_24_2019.zipzip ba36de0292871b83c0b8f3356afbd37e9aa1202f206e40a96ddcb1e26809f00bn/a 
2019-05-24FILE_2232409878US_May_24_2019.zipzip c4aec669809e096c8fd787dbd5d56d52acfde9faab8e7bbd10db4bd9e3e723ebn/a 
2019-05-24FILE_8656972274US_May_24_2019.zipzip 569460b18ee1f17f62289ee908ce6b7292a48492aa30c7aa3d59d34617e91e84n/a 
2019-05-24FILE_536968695115US_May_24_2019.zipzip 8388f2578f5f84a610f3553c9cdc0e13c11d33074511f5caa90f9bf19e04a0e7n/a 
2019-05-24FILE_42580765961US_May_24_2019.zipzip 30bfb8a3ea15a3dc8b5d341b88308672027826f910dfd9126405943281270aa5n/a 
2019-05-24Document_915242967413US_May_24_2019.zipzip fc6bb43bd9b33c7b719b911344e896a890c6e7455f6a5be6e9472eab741c844en/a 
2019-05-24LLC_47106455076US_May_24_2019.zipzip 0f62fe46c780374afc6520137b8baf5ca116e2d9dc61b0b12d3b145035850647Virustotal results 21.67% 
2019-05-24LLC_90402490265US_May_24_2019.zipzip fd6ba8d73e76a9fdac1c2ae868f2d72bab3051593a4c88e43d4fc47f71880ec6n/a 
2019-05-24SCAN_16580046867US_May_24_2019.zipzip 3a769da440cbae8691ca321fe64d8fcd4014ac0be0a0d7096a1c1ea96870f1c4n/a 
2019-05-24SCAN_40748729177US_May_24_2019.zipzip c02b2b49279f858bba6ebeb2f537921c0ef3a500c5b9140860eb2103aa8a9ffcn/a 
2019-05-24Document_10589632920US_May_24_2019.zipzip 10667b6b577ff56a3f5f99e07fb6eb4d9dd7bcb00ef8f302f2d7d8ba9afaa903n/a 
2019-05-24LLC_9522882283US_May_24_2019.zipzip 3545f746539588bb53060e82a08815ebee26645308b1f1298162a7e60b1d959aVirustotal results 21.67% 
2019-05-24INC_1095508387US_May_24_2019.zipzip 63ffbe8986e29cb3a37560341112d7da83c37943e023749bb6c79884e0588173n/a 
2019-05-24Document_1787617061US_May_24_2019.zipzip cd5c5973ec57185f64fa3e1ef209b50c485010de911266df86ad4e199c69c155n/a 
2019-05-24DOC_912825145655US_May_24_2019.zipzip 6de414348edab364033ec7ffa59326c3703949044223f9463636f4e1c45eab74n/a 
2019-05-24SCAN_34716648096US_May_24_2019.zipzip 64e0307a28cf25f559466bb80ca452fddd7c92e817911526d4bddb4263766acbn/a 
2019-05-24INC_29599804531US_May_24_2019.zipzip 190f09117a6ac366ec39fe673252a9a49c762bba2170d0e8dd42b075ace8309cn/a 
2019-05-23Document_324140573668US_May_24_2019.zipzip 524922d1e106f9e0538eba39e23298104490d2b0a4436e288e41646fcf18d2bfn/a 
2019-05-23SCAN_6425817692US_May_24_2019.zipzip 19716564b5cce8e09d6ed85e5d1771b60e547857188af283b023150c5eb7f0ccn/a 
2019-05-23FILE_877485204207US_May_24_2019.zipzip 7acb00128d57bfcf2b6c6e7a1131cdbe591bf2072642b819bdd2f10b6ee4ff74n/a 
2019-05-23LLC_75591532772US_May_24_2019.zipzip 610ea02a9429b817634e91a20be70524d5392b0f1712e2fec665023367346bc2n/a 
2019-05-23INC_001549554810US_May_24_2019.zipzip 97af264b498da300ddd252f4f49ab9afd78b8245d285430a68f80995bec9ebden/a 
2019-05-23FILE_29428412519US_May_23_2019.docdoc 75adbe115f73e35a11c971337b60009417cac294b0f12020d15931a5882f3e59Virustotal results 16.95% Heodo
2019-05-23LLC_598995705767US_May_23_2019.docdoc 174fcc89344f9868e3d4cda50ab3c9f204b82fdb2cd41226b72d68bee270660an/a Heodo
2019-05-23DOC_3934287999US_May_23_2019.docdoc a2f7be05173d2188d3e3ef994e8e41812050737cf5648697ab507b042adb99a0Virustotal results 18.03% Heodo
2019-05-23LLC_8039774608US_May_23_2019.docdoc 7f74ef7a47cc278b40c37aa4b344faeb5c4dd9cd826dc2cf06ad2b489664b39aVirustotal results 17.24%Heodo
2019-05-23LLC_80505415804US_May_23_2019.docdoc ecdf34d04afdfe1985381229b6b1c25ae473d4702cf03015fc10b779cce49006Virustotal results 18.64% Heodo
2019-05-23DOC_095263429532US_May_23_2019.docdoc 99c6ca598f9da46e12b3945f74d8cd4f7be32a3e9a66d9b67cff45eaa2295965Virustotal results 20.00% Heodo
2019-05-23DOC_292667054207US_May_23_2019.docdoc 90c5cb3b8468e65c5c682a9c3200d4bb696f4269c0e56c612602e634659a7a19n/a 
2019-05-23Document_330438945388US_May_23_2019.docdoc d72e4a0feca275ab74555ea876a3d74fba6b5b9ad1b1fc3864f51fa776fa4798n/a Heodo
2019-05-23Document_4872261064US_May_23_2019.docdoc 5c0a12520509cc3dced61c92a635e06dc369f5fe537f6dd74cde28a383beaaf8Virustotal results 16.67% Heodo