URLhaus Database

You are currently viewing the URLhaus database entry for https://www.52osta.cn/qza/l48/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:248066
URL: https://www.52osta.cn/qza/l48/
URL Status:Offline
Host: www.52osta.cn
Date added:2019-10-23 19:16:09 UTC
Last online:2020-04-14 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-10-23 19:18:09 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:5 months, 23 days, 7 hours, 36 minutes Bad (down since 2020-04-14 02:55:06 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-25zzZJKb2SFwik3xyhWVQ.exeexe 033db3f346e94c3cfdca8210a26a148506d53b5167b3cda4af1721116f38aa08Virustotal results 13.04% Heodo
2019-10-25peyHdwoLB2u0uwNJE0.exeexe 6109a86717720c78340b62121d959e6f4cac6c10b70c248b5327a6b5b0d107cbVirustotal results 15.71% Heodo
2019-10-25BlwajOv.exeexe 41e0ae1c1f3137cd6a63d4dd586388878c7df93b3c9ba314103fb00991c2da62n/a Heodo
2019-10-259rj3PS0nBrwM9iA06.exeexe 514f013d9848a19291a2cad493a3b3a5c2f37661ff1a713eb21716b39e5afb5en/a Heodo
2019-10-25bkVOaOkBaOyh.exeexe 6c4beb4b748544ee3dc71419a0684f42659f63ce87cc4fc9526f7634da6ab900n/a Heodo
2019-10-25IwrPIV8TV.exeexe 5ed1d51382f493a1bd562f4716ab2b6029dda3d44587d2d3ae500e99bd1247c6n/a Heodo
2019-10-25uKgGcY.exeexe d1deb7f8195050e4412311ad96980dccb50dcbf24b61e31af577104bee2877f4Virustotal results 10.45% Heodo
2019-10-25YBnD9kmIbxt3hG.exeexe b17cb9569882ab3f112045f53221caf82166325ece975280d07bb38fd2d9edfbn/a Heodo
2019-10-24pC.exeexe ab264199a77bc7d6ecc258b5ce4a7437a7f2423e07a29cfc7721aa5894867820n/a Heodo
2019-10-24ENpLVLITQ.exeexe b6f1979710f493031aad21c1861043ff28822accdd4963dcee373c608ea21af1Virustotal results 21.43% Heodo
2019-10-23O1HZdTiBpNAxG98TU.exeexe 5c138290815cf635fb9947f9753c73dac1dbd855a2153116cb0a3a4e6e07944aVirustotal results 14.08% Heodo