URLhaus Database

You are currently viewing the URLhaus database entry for https://www.yzmwh.com/wp-admin/eTrac/yqpzd8s6i/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:265790
URL: https://www.yzmwh.com/wp-admin/eTrac/yqpzd8s6i/
URL Status:Offline
Host: www.yzmwh.com
Date added:2019-12-09 23:25:35 UTC
Last online:2020-01-18 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-09 23:26:08 UTC to ipas{at}cnnic[dot]cn)
Takedown time:1 month, 9 days, 13 hours, 7 minutes Bad (down since 2020-01-18 12:33:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-11DOC_PO_ 12122019EX.docdoc a58b2c2807223708befe5791cb88cce16750d7b7148e48f82d7297db009bf603Virustotal results 41.94% Heodo
2019-12-11LP2071169342UE.docdoc 139b05a61272b421d4e9e0f4f9890837810349b07207f762cab5c4897a33c002Virustotal results 41.67% Heodo
2019-12-11CKC_07LBFL31NH.docdoc cedec09a05fcc90ba1bf5b84f0a2b0ea2f384029fb3d280a67442d359d3885efVirustotal results 38.71% Heodo
2019-12-11GVF_120119_OQR_121119.docdoc 90e23974d581520e1b57be4e012a78aa866183d2c77fb67d3c2458746ca41481Virustotal results 38.71% Heodo
2019-12-11KAN_120119_CYD_121119.docdoc ce74e6d5c2375c3da3081f688225762fc61ce5f3181d4cfc2b517ac4d991bfc8Virustotal results 39.34% 
2019-12-11Y_RZA_120119_PMJ_121119.docdoc 3c9878ac9b57d307a1228fa03442b11056e72d2c0fadb454e70f32aec28b4b6cVirustotal results 35.00% Heodo
2019-12-11DOC_JJC_120119_EUP_121119.docdoc b4eaf914ccc446ead4b90498e82aede354a3f4235774baab829ac5cde833771bVirustotal results 29.51% 
2019-12-11REP_5689124600040489206.docdoc ff597f32d0ce8075dee86144da7e709be5f45abd154cc33f67b5198aab6d9ba4Virustotal results 27.42% Heodo
2019-12-11REP_IPWB0HF.docdoc d5c9c16d38cf7070fb8014414a6633ed14e7f0e1c4569615dc416a01e259724eVirustotal results 25.00% Heodo
2019-12-11TAY_120119_MDX_121119.docdoc 90348b4d3ac94dbc837178f28d608e0d5f841267ac43e98cfa355e8973c34896Virustotal results 49.18% Heodo
2019-12-119553714895309670111121.docdoc 1129e9ef65995a84756f17a1b6581f73a3aa95942bee03c1d45167f168d79805Virustotal results 48.33% Heodo
2019-12-11CZ_42689001.docdoc 1720bfdf1d005d4a282cb540af16ffd8f0d7735f46e3bbbbaae5517e43bd7bd5Virustotal results 44.07% Heodo
2019-12-11QH5090729695CY.docdoc 7dc82afc58fb81a256c24db77f61c5f95de8a9792502edc42fc84692572fcd97Virustotal results 40.00% Heodo
2019-12-11DOC_7487631175107760349.docdoc ececa128a027e4dcbd41d97bc3378c242a9701e8c583b0587b867621efb1503dVirustotal results 35.48% Heodo
2019-12-11XS907UI2DM7.docdoc adb56550e01e0f40b85119ccfb67cacc100e0e353656ea29b36d5250d7e14e58Virustotal results 34.43% Heodo
2019-12-11REP_777106104578478860776558.docdoc 9e414c53f146e586e8fb0bfbc37cf4cf38dc13c90c923ed08f8cc2a6b84b31a2Virustotal results 32.79% Heodo
2019-12-1189561563.docdoc 4face44e712880190ed46611d9e2c94b7fddc704e8580accb2f4fec0e02692ddVirustotal results 31.15% 
2019-12-10KTF_TU9585741978GH.docdoc 95ea8af7b6daa10fb5d0b502c3ef0b00ebabe9dc3ea809fe677b9bead870b93cVirustotal results 30.00% 
2019-12-10FILE_LX8S9O3.docdoc a26dc8a554ee1fb2a297968a6dd0c3908bbc7149ec9df10b6ce145ee4fb73318Virustotal results 26.23% Heodo
2019-12-10FILE_9500153224702.docdoc bb3ec9f8c89b683a1b6bc4556153a9f20b9180122adf5ec4b014cce1e90478a2Virustotal results 26.23% Heodo
2019-12-1007537673.docdoc d2a37b2f1107177ff1ab49768e740e747144aedac86323f227b880201ba486c1Virustotal results 31.15% Heodo
2019-12-10O_501221718.docdoc b103e80d28feaf7a6e835168420bb16e18e69bfec44ed4789207fb882eaa8b80Virustotal results 29.03% Heodo
2019-12-10LDT_61107117.docdoc a72751172f836d8cca93249a226ce850b7f32c85163bfb92ec9892b2aefcee53n/a Heodo
2019-12-10F_77244180.docdoc 834e4fc32656fab69a94239d34d8feee7c33b017e6b40a06456b9cf1b6c2aedcVirustotal results 25.00% Heodo
2019-12-10FILE_DB4964383959KY.docdoc f2afee4962b529df9ef6ac0e75eb79d75de99c2fba61bf60410116510a4e910fVirustotal results 33.87% 
2019-12-10IO_ZX1625162484YJ.docdoc c9d24a9b3955e002768d1b9d5f18f8aa0bb81726d8e41d92a97fa3a4f513eb05Virustotal results 30.65% Heodo
2019-12-10DOC_02610578.docdoc 08ef301df4dd764b31c2ba72b9ffecaaa9ecd0e3847d007b6f7075eeefab3bf8Virustotal results 27.87% Heodo
2019-12-09H_VK0980160157BM.docdoc 1392e0c852f6b40224401c1b1477372a0687e574ccaaa312b86b57771b1ed773Virustotal results 26.23% Heodo