URLhaus Database

You are currently viewing the URLhaus database entry for https://www.wnj.co.th/cgi-bin/OY0Zinga90YG7z1oLcuaKFi/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123182
URL: https://www.wnj.co.th/cgi-bin/OY0Zinga90YG7z1oLcuaKFi/?i=1
URL Status:Offline
Host: www.wnj.co.th
Date added:2022-03-30 19:52:05 UTC
Last online:2022-04-02 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:53:06 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 days, 9 hours, 19 minutes Poor (down since 2022-04-02 05:12:18 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01DZQ-23722796390.xlsmxlsm 394f2586f64eea33aee4936383a906ce8da124dfc3cc0a464897f776bc1d373eVirustotal results 41.94% Heodo
2022-04-01DYK-3312512817169.xlsmxlsm aeeb5ed9e799b620a487617a35049f204d1465f85fb5a5296dba3bd811c2168an/a Heodo
2022-04-01HHY-313552577.xlsmxlsm e4458a21923b4abdd20bd02710b29fafe8a0e249a9515cc2e4aff94a30d7d9a4n/a Heodo
2022-04-01ULL-687005951.xlsmxlsm 5118b85e7ffcf61644564e2660990ff4e6becc430b13aca19a931d25f3d4c1d9Virustotal results 44.44% Heodo
2022-04-01GV-885452941722282.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01YFF-930083453722834.xlsmxlsm f29f0ba02cb498dad7d65453ecc558f159db3694f8f5cdba8d96fe63fb61d986Virustotal results 41.94% Heodo
2022-04-01BB-1987240.xlsmxlsm f0f09aa290ea5163df87f24d45da92c595dbae836d83283915154fa7e2d0a3c3n/a Heodo
2022-04-01AR-2147882.xlsmxlsm f8f5316e59f479286d96010874074660c5afe3ddbbf1bb382c468904b9667595n/a Heodo
2022-04-01DL-39539602348665.xlsmxlsm fa5f3e1ad7a0966fac2a2d091be90b6c0d70c79e258c9b19a2e93c47cd0c4818n/a Heodo
2022-04-01OX-456031968122004.xlsmxlsm a952453aee7b5d358259b92750c559cdf583f54496aa8a8b81a5aa27d2b18dfaVirustotal results 39.29% Heodo
2022-04-01ZV-24071265716.xlsmxlsm 97fc1c969103278fd6fddd2f117d3b418d3f7925a9971bafa8bafd8b2d3df632n/a Heodo
2022-04-01AXB-72979463241.xlsmxlsm cb8b7ab96bb04ee8d5961b315979e71335c048e9eb3a3bfac2f273731544f0fbn/a Heodo
2022-04-01JW-661199712.xlsmxlsm fdaef695835e1a9e056fe2496ef611e4250388f7712102116b6717894e578f50n/a Heodo
2022-04-01GYZ-681952775.xlsmxlsm b42ac7850efc6c39b4c7db61d4be9a131d78b545eaaa868dab373c45bff2fd72n/a Heodo
2022-04-01DAY-948906388302.xlsmxlsm e407f7217907368560ef28caf164f34190a5295c4c75afaaeea21386e8bed99cn/a Heodo
2022-04-01MW-18920690343078.xlsmxlsm 4967f52b4eec67dedea5ef764a47c545db43f04f5b0f1355dfa16c8b8bc6e1e8Virustotal results 41.27% Heodo
2022-04-01ATV-2915474.xlsmxlsm 45a99040aab95ccb6eae75a169ae10f79883e11c53c29bc41ffffd0a329940cen/a Heodo
2022-04-01ML-43267637543.xlsmxlsm ea8981ffdb13c6d1dd874a5a86e7079bb053c862a92849bc571846a6762dc7d4n/a Heodo
2022-04-01TIQ-621853935.xlsmxlsm f44647dcfb785e6463e4203aaecc8f5d7dcbebf18418667ed31c226c92372383Virustotal results 43.55% Heodo
2022-04-01PUM-364350228.xlsmxlsm 038b2b0b380d3768f3d9527e452bde092d4900c621bdc393d324415ebac36b8bn/a Heodo
2022-04-01KM-6825036663165.xlsmxlsm 55af29e8285944f573d931d856bd099dac92ab1868000f8346d13a0bce7f1e3dn/a Heodo
2022-03-31IQ-00974408361731.xlsmxlsm 5165a1e19391e7f4c4a5d6f8113fb024b3a6ba299312f9cc3afab95d6bf84cben/a c8fc17ff030feb3383d8889f69abbb
2022-03-31WVG-417222828.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31VU-304321807.xlsmxlsm 47033d733745aada415882d83566cebcc301505ddbb55d72e84ee221332e812bVirustotal results 34.92% Heodo
2022-03-31AN-10185032014837.xlsmxlsm ccd9dcb6dc115061ff6e011cb77ac0c73d785a23c2019aabe11eba9b7500b118n/a Heodo
2022-03-31JM-8112399552.xlsmxlsm 83a8039af1534f4fc93efcdb7e429c799f144ace1f33b37ca42a57ee7a559499Virustotal results 45.90% Heodo
2022-03-31BPN-36906896626987.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 38.10% Heodo
2022-03-31KY-50525220528.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31HE-88055224812120.xlsmxlsm 48f3f48c930933448b555efe67aa364e098504f2273ec2a4792803cb4a21b8bdVirustotal results 40.98% Heodo
2022-03-31HWR-13816835487.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31OC-1657335379.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 43.55% Heodo
2022-03-31SJ-73763354245586.xlsmxlsm 2e1db4578a7534abbaeb0e65b01b0da5024a9e27d99c3a9b29b03cca35b3a096n/a Heodo
2022-03-31YVD-04009772696.xlsmxlsm d23b68a978873407e16fa4e380419519f8fdaf340245a8bed2182f15f9450a75n/a Heodo
2022-03-31KQ-7212166788528.xlsmxlsm 41a73a914406df97e2944f7742f48272bab7d25486c9c2a5084a7f158fdb2aafn/a Heodo
2022-03-31XTJ-482474408919.xlsmxlsm f869263419a75a1350a78400b9e3dd186488c7c76d299e7984af7e5e0c91d75dn/a Heodo
2022-03-31LD-859115342452889.xlsmxlsm 764d8e72174b0666952016caf95096e85219dba6554a8ce6db74b8244b3e7590n/a Heodo
2022-03-31YML-10751273046739.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30IZ-64292705.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30AUP-652818797.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30FMZ-6761301140994.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30QR-6622700288.xlsxls c37ffc0e87ede2e654c4112c8d1b9172041a21bc4174b248ee2c81af738bcaf5Virustotal results 28.33% Heodo
2022-03-30UOG-991506753003582.xlsxls 31ad327541ee0627096151e901dee22241e584b78b52c17eee5a1c40a6f25490n/a SilentBuilder
2022-03-3031051656852134.xlsxls 7c9ef24f3522ff243e77f5d6e0cb50f6766916fcc1ad2fe845f9d509e39a6b3fn/a Heodo