URLhaus Database

You are currently viewing the URLhaus database entry for http://zunshengtang.com/wp-content/lm/wTJceDgsfpYuNcyhsSDYh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:201046
URL: http://zunshengtang.com/wp-content/lm/wTJceDgsfpYuNcyhsSDYh/
URL Status:Offline
Host: zunshengtang.com
Date added:2019-05-24 00:39:08 UTC
Last online:2019-05-31 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-24 00:40:03 UTC to esabuse{at}hkbnes[dot]net)
Takedown time:7 days, 3 hours, 16 minutes Bad (down since 2019-05-31 03:56:55 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-29LLC_2703077235US_May_26_2019.docdoc 7eaaf8ce0632c9ad4fe9acb2b4a97da59085ee7ef6c842b13f7d35084b6b9036Virustotal results 67.80%Heodo
2019-05-25SCAN_153419626839US_May_25_2019.docdoc ceeb8557cb6cac7b9c92e95a2fe0a7a5244579229aa7db500e463cc87efd54dcVirustotal results 27.12% Heodo
2019-05-25FILE_803840016860US_May_25_2019.docdoc a9725b7c79250955489c7f9b0ec5b21442115905140a1789c0bde677b0299345Virustotal results 26.67% Heodo
2019-05-25DOC_15023660868US_May_25_2019.docdoc 7e9b16dd5303045e326c5f7c8b3be738d0f0a55f438596ebf266e53bdead7fcbn/a 
2019-05-25INC_564877984102US_May_25_2019.docdoc 8d262e11a4d725c4e1282a2702fa6f6afe0dcdd86703fa51c3dec1ae9022c698Virustotal results 25.42% Heodo
2019-05-25FILE_95395570029US_May_25_2019.docdoc 440b4d1d5d1443527fe29b5f142f81cdff8839dc09c2cc5cbe98c286a43759ceVirustotal results 25.00% 
2019-05-24FILE_4649449436US_May_25_2019.docdoc 291dbb3e3d38f1528818833172bfbc0e2df1384ac9c4ccf92b35d12ae6d84e28Virustotal results 25.42% Heodo
2019-05-24INC_905407317837US_May_25_2019.docdoc 029ed07a45381598787146791bce6a8f20b2b500d19de4bb085e6598bb7b4dc7Virustotal results 25.42% Heodo
2019-05-24DOC_530678792627US_May_25_2019.docdoc 507edca22bca111d1f63b9b9e41a2fdd375ef30d42c3f87d82e940f25fc4f34bVirustotal results 25.00% Heodo
2019-05-24Document_19329550048US_May_25_2019.docdoc 8da7abfdf789b3c62c9fc92a804d33b560d602bb2a3504eef6ab9168bdfb307fVirustotal results 24.59% Heodo
2019-05-24LLC_37917146903US_May_25_2019.docdoc d4451d58eb5d010afc870ac2fc85196a7eddeb526e41d7b8b061dfd220b63517Virustotal results 22.03% 
2019-05-24SCAN_8305579792US_May_24_2019.docdoc 43fd2fc7a0461750674256537ed35b76623eaac07ef086a13b0680646fb7df73Virustotal results 21.67% Heodo
2019-05-24Document_5689133483US_May_24_2019.docdoc 8aa364c7794389dc2b488d2fd90d4d791a5ed2710559912912d3c84c50a468c1Virustotal results 21.31% Heodo
2019-05-24INC_355590182154US_May_24_2019.docdoc 8a0f94c4e0b04081a2f7fec8c6c001f903092a1110f07f46e1d2d1cdc77f2034Virustotal results 21.67% Heodo
2019-05-24SCAN_146435330237US_May_24_2019.docdoc 00ea2e24de5e4e9a987fa8b235fb538e49b85fa64eae3011ee9ff44476213b1aVirustotal results 30.00% 
2019-05-24INC_63513267821US_May_24_2019.docdoc 5f3f990b8bcf42bffdf525380f74f20bc95b54aa8c14295cfeb429d95b6795c2Virustotal results 26.67% Heodo
2019-05-24FILE_35565467239US_May_24_2019.docdoc 4b9fcd4189fdcab7434f28b57e585c9fdf6877065be361ee2bc7af7d14ace897Virustotal results 23.33% Heodo
2019-05-24Document_955528096786US_May_24_2019.docdoc 52113ec28c47265a473c2970d769c75baac1058bb9b5e3ec457e0c4f3b624c37Virustotal results 23.73% Heodo
2019-05-24DOC_02116535413US_May_24_2019.docdoc b9a60d7dc140c79cf8b5409040bb7998f7f45dcb5eecaeaa3874a56f75df86afn/a 
2019-05-24Document_99128850266US_May_24_2019.docdoc e951c3db59142c02ebeefc5506d08626bb57dfde2b846c9afd21ce31bc2cbe8eVirustotal results 21.31%Heodo
2019-05-24SCAN_954193660374US_May_24_2019.docdoc 65cac9c58fe03445f4ccd34499fa8c6951d85555d241818cc5a4d6037c062550Virustotal results 22.41% Heodo
2019-05-24SCAN_65350198226US_May_24_2019.docdoc 67f27ff168d34fea798552774ec1859f7ced8ccc9382fe2becd8f806403ee4beVirustotal results 21.31% Heodo
2019-05-24DOC_068804891657US_May_24_2019.docdoc b0ba612cd5282fe21e64b6371ae76df59dd2d3da7541203d93b0202b426154acVirustotal results 20.00% Heodo
2019-05-24DOC_528140717767US_May_24_2019.docdoc 55c4c3f89a961e9ba055e47b5875b7a945b97aee146f522c9a9f299dd989137dVirustotal results 20.00% 
2019-05-24INC_701714115197US_May_24_2019.docdoc 32fbe8b5ba34d19c1be8b639490376bf5baad31f95f0fe2adbcaa79310a57347Virustotal results 18.33% 
2019-05-24DOC_941547946537US_May_24_2019.docdoc f3a97d8d40d49941a21e35c6fbd71e230ea29f8f1c478b4da514fb82eea8eef5Virustotal results 16.13% 
2019-05-24FILE_5430489706US_May_24_2019.docdoc c4b525a4ffb61823a7dec6ea0e121c025a2049fdb681f5f7320e60e6dd16e75fVirustotal results 16.36% Heodo
2019-05-24Document_311748721304US_May_24_2019.zipzip 978d7b92ce3b3a4822c80f6bbdbd775e9cc82e7fc806952ff333c54990a7f416n/a 
2019-05-24SCAN_975959862102US_May_24_2019.zipzip 1b51e1abe2d389bebb0156f6c63f27bb42a6971c0169db3ea19e4f728e7f72f7n/a 
2019-05-24INC_916565801690US_May_24_2019.zipzip 63525eff3ad8d210a6c7bcc2446c177c87e9633a6766a5d5e618c96e7c4dd5e4n/a 
2019-05-24DOC_67079975670US_May_24_2019.zipzip ca5f93aefbee4f5c5b1bb307f4c5ea5b9f6a4a59a6e364850a9dd4cb4edb9eb5n/a 
2019-05-24INC_250122958173US_May_24_2019.zipzip d7a6b96b49716ae5fd644ef7df51fadc5a8abc28060a880365e035a1815e9919n/a 
2019-05-24FILE_364869111942US_May_24_2019.zipzip 106bca356c05328e86017a9d35986efc25a06445220c234a0511c6f90c44a8f3Virustotal results 25.42% 
2019-05-24LLC_499629505485US_May_24_2019.zipzip 462adbcc1d21dba15bdec36ae7224c69d36ac848bdab8598a5436762b65f7a02n/a 
2019-05-24Document_264635285986US_May_24_2019.zipzip 61006a0850431c7da9278c8a26a836cd110320648c5ccd68207b66586f47359cn/a 
2019-05-24LLC_3142511063US_May_24_2019.zipzip 980702fec70e1f935258959c9c693b8eeb8e0e99e0b9f6ba8e373a598a844742n/a 
2019-05-24LLC_3441864340US_May_24_2019.zipzip dd56311c0171282205070cd76b1c99f5fd24ef8f29e3c73b1156bbb73ef20a7en/a 
2019-05-24SCAN_0653931881US_May_24_2019.zipzip fcaf6d32d452be6d54bbbaed53dbe5bb4cf15ca764faa53c4c5658902af41d66n/a 
2019-05-24FILE_9624742906US_May_24_2019.zipzip d2a8aaca252b4f6e1d82f82a423c449523ffcdc646de4b6d3877db54ccd1f167n/a 
2019-05-24DOC_8333209227US_May_24_2019.zipzip 34725fc842d776c88bee08230df6a41f85906ac8ab22838a0640e2e037352f97n/a 
2019-05-24SCAN_961335049085US_May_24_2019.zipzip 80ef6026f8a42e7ecdf25e7228c65edd7353746f388d8c0c40e49a50438498d6n/a 
2019-05-24DOC_80323308139US_May_24_2019.zipzip 718fb3574a285624e7957aefe2109c69b868788183d669455ecdec2e35a7a9dfn/a 
2019-05-24LLC_852031501071US_May_24_2019.zipzip ee0d778307c4827084d7a5a47a773e21b4875efacbe6d55b206aef6f9c2a5547n/a 
2019-05-24DOC_04016893160US_May_24_2019.zipzip ecf9039a521e131da0066e5dc087fa2d9d8115e791b2809cce827411aac13c48n/a 
2019-05-24Document_5180689315US_May_24_2019.zipzip b3e21821c83559b17d4c6a3bc4a04ce66fe31fc885245233d2bb036d044e38f8n/a 
2019-05-24Document_61934109540US_May_24_2019.zipzip c1271871772cd426556cabf8a177f57b4c52f5c83a021efa8ff42988ca32348an/a 
2019-05-24Document_31717212257US_May_24_2019.zipzip 57210ccf1377bcb5d76e0448c13d5e6d758d5666cf3b486406f65fb3ad34a4d1n/a 
2019-05-24FILE_72317664029US_May_24_2019.zipzip ca28804ccc00ff3b33e115830e073e6588f7254d226d3c980ef6176133672c6an/a 
2019-05-24LLC_119533539636US_May_24_2019.zipzip bf5780098d1109dcbba8b70bb8619200167fd2c2d6b00edddc5ceddce00ea05en/a 
2019-05-24LLC_567041205953US_May_24_2019.zipzip 715bb73b784cdfcab849beed3c76867e8a577dcb93fd69453b94c5fed74278efn/a