URLhaus Database

You are currently viewing the URLhaus database entry for https://www.wnj.co.th/cgi-bin/OY0Zinga90YG7z1oLcuaKFi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123183
URL: https://www.wnj.co.th/cgi-bin/OY0Zinga90YG7z1oLcuaKFi/
URL Status:Offline
Host: www.wnj.co.th
Date added:2022-03-30 19:52:06 UTC
Last online:2022-04-02 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 19:53:06 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 days, 8 hours, 33 minutes Poor (down since 2022-04-02 04:26:40 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01KIC-98096031331758.xlsmxlsm 038b2b0b380d3768f3d9527e452bde092d4900c621bdc393d324415ebac36b8bn/a Heodo
2022-04-01XYQ-4106233373.xlsmxlsm 60c4d1f685f36a0120a23c7fd8aa5ca2ae442c84ade6fc63771c5463defd9bd7Virustotal results 45.16% Heodo
2022-04-01NN-11797685230.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bVirustotal results 47.62% Heodo
2022-04-01UTE-2072134842.xlsmxlsm fc98891573651d036bc91667cbf079a445077325572a44f03802b5d6974c9ff0Virustotal results 43.55% Heodo
2022-04-01IL-39425907353080.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fVirustotal results 36.51% Heodo
2022-04-01GV-885452941722282.xlsmxlsm 534f4ab246459c91599d4d14e916a2f16707134075a5a88d897105a0e782632bn/a Heodo
2022-04-01DF-186634381874.xlsmxlsm 2efeae28ad35e91b7abb28eec555e20e394693d8454514a43fc119fde473348eVirustotal results 42.86% Heodo
2022-04-01BB-1987240.xlsmxlsm f0f09aa290ea5163df87f24d45da92c595dbae836d83283915154fa7e2d0a3c3n/a Heodo
2022-04-01OOI-3368895790001.xlsmxlsm dd701c6097144f29f8fbdddc93a18a1c0ce3c3b51d5b4f0c6683e906ba8426d9n/a Heodo
2022-04-01DL-39539602348665.xlsmxlsm fa5f3e1ad7a0966fac2a2d091be90b6c0d70c79e258c9b19a2e93c47cd0c4818n/a Heodo
2022-04-01MN-00373760966818.xlsmxlsm 393d4fe454720708127a511564d5d5aab745e714a3e0dedafea5aa94c2d4980en/a Heodo
2022-04-01BO-414436167.xlsmxlsm 989afb22d889ef10aefc7185c5a8d051fa3dd6c0f2a6a811c1a89498e293b615n/a Heodo
2022-04-01JW-661199712.xlsmxlsm fdaef695835e1a9e056fe2496ef611e4250388f7712102116b6717894e578f50n/a Heodo
2022-04-01DR-4063106.xlsmxlsm 09e3e96e0e415868e1458e08a45745eefd6455c7bc1d978a1dc345c4274c15d2n/a Heodo
2022-04-01JP-8200819171431.xlsmxlsm fd9c7b2de5f9a936c9a16ba8ae8e5215dc92021e435a8285fb36ccadd20e871fVirustotal results 38.98% Heodo
2022-04-01AI-2976296.xlsmxlsm 21878746d787b1e233ca736e023094af743ff3c853baceaaba65afcd7cdb6823n/a Heodo
2022-04-01UZ-62384009673.xlsmxlsm e40bfb9b0a236fa78f9150e560fa82b899430dd6cf6da41388a30f8e09496ecen/a c8fc17ff030feb3383d8889f69abbb
2022-04-01ATV-2915474.xlsmxlsm 45a99040aab95ccb6eae75a169ae10f79883e11c53c29bc41ffffd0a329940cen/a Heodo
2022-04-01RTZ-44877938.xlsmxlsm 4c7b060bb7b1693ef3943692ce9c62204426393f9af92ca39c4c57e09b03cc25n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01TIQ-621853935.xlsmxlsm f44647dcfb785e6463e4203aaecc8f5d7dcbebf18418667ed31c226c92372383Virustotal results 43.55% Heodo
2022-04-01KCZ-95277806748456.xlsmxlsm 9703f8b1fa17b92402d32f6c4862122f218a13d6f0a11dae499dbc77d7a9cdc3n/a Heodo
2022-04-01VMR-1012397.xlsmxlsm bad29f90618ce3abdf8296b3212e2b256d0ba9047f64c50681339f93fdc7a729n/a Heodo
2022-03-31JWR-415548372473804.xlsmxlsm 1f89665519be0af8fa6ccf11e12d78adc54cf5560f8826352dd036d8663a9bdbn/a Heodo
2022-03-31WVG-417222828.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31XJ-6501732790479.xlsmxlsm 65d9f4ae7d90232314fd04917e53e9f4e2a214ec3670daad35bd2f51fe9a45d7n/a Heodo
2022-03-31XJ-213670698199130.xlsmxlsm 73a1d60faa31200f09f2567671137d6b5f9be02a97eec33fc20971d151d5c8f1n/a Heodo
2022-03-31VGR-258231025.xlsmxlsm a395d2ca627270c1b53481050d39c6395c778682e98aeedcb00d1f68fd1ec23fn/a Heodo
2022-03-31IPS-422523744.xlsmxlsm 99bacd00ff714e00339dc64c1418b2c0c26ca69120e34bd32ba8e73d2044cd9cn/a Heodo
2022-03-31XFN-13684949178.xlsmxlsm 8115bc600c3294ed207ae6a9310eb986b107f74f69a64db674837ba2e2957ac6Virustotal results 40.32% Heodo
2022-03-31YJ-542508272883488.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31WS-906681652988.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31TSF-043902295124212.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31OC-1657335379.xlsmxlsm a7ae8fb40c5d93e9ddbfc68b000b65ba19b085e7a19d3a5d9bef1c243a6add91Virustotal results 43.55% Heodo
2022-03-31KOP-69009598689775.xlsmxlsm b5df411a9037fcd4dc6b3e92145aae14064c20edf7476a543c778bdb8af22600Virustotal results 36.51% Heodo
2022-03-31LT-938665409809381.xlsmxlsm c3a5d5bc890f935056c127bdeda35cfcfbb8e292e59774a24ca5611e94430907Virustotal results 37.70% Heodo
2022-03-31KQ-7212166788528.xlsmxlsm 41a73a914406df97e2944f7742f48272bab7d25486c9c2a5084a7f158fdb2aafn/a Heodo
2022-03-31NW-360524980930341.xlsmxlsm 4409b097292f1ed1adedbae38fcecf71370a64209f9bb5ffff019b71e8a88533n/a Heodo
2022-03-31VEV-1141421802.xlsmxlsm a4e22b806505d549a037a67123efb6b397193d7d2ff28e32d8b73185438fb5acn/a Heodo
2022-03-31YML-10751273046739.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30EH-361212931.xlsmxlsm f6d9028f6903f57570a969a97a510120fa11d93ce778cfeac61862c36d6b6bd2Virustotal results 38.98% Heodo
2022-03-30AUP-652818797.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30ME-38293044589017.xlsmxlsm a9850d81856c9d96fc75ccfe0a62c2142422d5feb66ad218a0b057a52bc4c554n/a Heodo
2022-03-30EQT-940601011.xlsxls 82be92d18fb73fad9b6f0e90da074abbf2aaffd91c4493491620452f19bd281dVirustotal results 26.67%SilentBuilder
2022-03-30n/ahtml e37923f9424ab6f89390d5ee0405e46d579d3db461c2a4698ed33e5c4f8f56e6n/a