URLhaus Database

You are currently viewing the URLhaus database entry for http://www.51az.com.cn/wp-admin/open_array/special_space/62755401108_1E4jGeTBTGcu5n/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:271449
URL: http://www.51az.com.cn/wp-admin/open_array/special_space/62755401108_1E4jGeTBTGcu5n/
URL Status:Offline
Host: www.51az.com.cn
Date added:2019-12-18 07:52:28 UTC
Last online:2025-06-30 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2025-06-29 05:14:10 UTC to abuse{at}kurun[dot]com)
Takedown time:5 years, 7 months, 17 days, 8 hours, 47 minutes Bad (down since 2025-07-06 16:41:15 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-2986171cbe531f681e97798b87784f24f6acb8eeaa44696ee2a14a04cb1414a500.unknownunknown 86171cbe531f681e97798b87784f24f6acb8eeaa44696ee2a14a04cb1414a500n/a 
2019-12-20part_12_20_2019-5F031033265760.docdoc a35d23968eae8e3f9825a4f02cf04ddeccba1700c9cd890ac37ede3ad01c9976Virustotal results 37.10% Heodo
2019-12-20unit GU2089884130026-60825448.docdoc 6e5072f64657ec476491b85f1522366eb46e5b23dac47259abe2bd34a2e7e5f6Virustotal results 33.87% Heodo
2019-12-20final data_40423.docdoc 27b25b36f565ebe1b9fa0450584e3e8326ee1e48bb32bc9618e2f87dfbcc63b0Virustotal results 32.20% Heodo
2019-12-20notice BM053120124_14863.docdoc 9c8a67a4cca28b33344ba9e2bfdf954e7b3de20c7e7df17d0bc9940c94a6a898Virustotal results 32.79% Heodo
2019-12-19correct notice-7405245o5756p5.docdoc ef2f6014b9f926466073f7e036544e5188ac00b96f5f321e12c8daece16e3b94Virustotal results 32.79% Heodo
2019-12-19Christmas-Congratulation.docdoc 8a2265802819dd5ca4f6613abde71b3c378f0ed75aafd74217c7c67dc6d9aae3Virustotal results 32.79% Heodo
2019-12-19Greeting_Card.docdoc d394ed6a30ff8bd2c2812675561d9662c72ea9d8c987dd329046f0ecfdeb9177Virustotal results 32.76% Heodo
2019-12-19Christmas_eCard.docdoc a9cca87947019b1b0d20078ba9b821216910be4c95472394cb11aaf5792d0b58Virustotal results 29.03% Heodo
2019-12-19Christmas-eCard.docdoc 24e179433d71db6342574fcfd773f0be4f8e674faedfa4b2366dcea8eabf72a0Virustotal results 24.19% 
2019-12-19Christmas-Card.docdoc 201f102cd65086c997ff32e201c77e29e3161aee6160114be1732a34d2da1305Virustotal results 25.42% Heodo
2019-12-19GreetingCardChristmas.docdoc 77d6e16bfe0c08553094c4d421b8fbe2e19da685a837ec432e153c31376fc803Virustotal results 24.14% Heodo
2019-12-19doc-87182080.docdoc 27820b2e783ff5a9817650a7f8a04b23a41db0d06c86748ef6a1c4a1fdf9f43eVirustotal results 22.95% Heodo
2019-12-19Untitled_file_12192019.docdoc 041a71ad48a82b592d829f056edcc4094680ad32648b539a44f0187399b61734Virustotal results 22.03% Heodo
2019-12-19Untitled 68492680729.docdoc a69368b822784cc6ac553c58fbdacd6e8303a8824a6889114d2ad7bd2423b695Virustotal results 21.67% 
2019-12-19INFO-955215882896.docdoc a67088ef976b76ffe088c574069558a6da9e6d1232b0f1d031f8a92deca094a9Virustotal results 21.31% 
2019-12-19UNTITLED_494390550989.docdoc 6f4b1b5c9f647af4523633a77ba84036e95619e1114b0c5fdb179a62224db00cVirustotal results 25.00% 
2019-12-19copy_SHR89371.docdoc 9dd56b030a5a2f236d92a69263d255bd3967925353533e3f6ec530bbc0c5a7f8Virustotal results 22.58% 
2019-12-19Untitled_file_0250r91l.docdoc 3cb1650cac5770870949aeb67823e4c9f1b8bebc56fdec50beff5eac826f98feVirustotal results 21.67% 
2019-12-195v9nup54w.docdoc 139113f465022b7336c3cfa9e2ea54952d56825d295a0ff62dd3e8cc09483d24Virustotal results 21.31% 
2019-12-19REP 12192019.docdoc cf080cecf871d837c84b70ce57518579cc126c06cbcc720771ec723aaf44813aVirustotal results 20.97% Heodo
2019-12-19INFO-41w1m41.docdoc c2a870be9ac4430222a860da9ef1b34fae2a78a8d16cd1d1bc28e0f3ba78366fVirustotal results 31.15% Heodo
2019-12-19VER_083466098.docdoc cf65b38b2650623e1361a482d1e8e8781019d7a29cb757cf79c1e276583838a8Virustotal results 30.65% Heodo
2019-12-19rep_1omw947k5o.docdoc 13adf04d2b552069ad8870dd21dc5fc100bda4a2657644deba9ac368a022754fVirustotal results 31.15% Heodo
2019-12-193wk46nl56pu26q.docdoc 0c45e14f368d59e03d4881e280642933dd8287a088108931f5c4f1425c442300Virustotal results 24.59% Heodo
2019-12-19info C359959 6294653.docdoc 29b09a38dd8a80d4166fa0bd02fc00380f70cc097cffc0eeb9d33e8af35e8b62Virustotal results 24.19% Heodo
2019-12-18RP42469367_7947465989.docdoc 2096aeb29e7f19f81c094a0ef93d2fb2a64ba7a29bf972d94e1b469ecf5968d8Virustotal results 24.19% Heodo
2019-12-18558654837460.docdoc ea94f3a10992fd81fb798921e2c9207f21f134cb7784f1f201d750587f25eebaVirustotal results 25.81% Heodo
2019-12-18UNTITLED-12_18_2019-90162.docdoc 3be9f66ef6e3feb291bca66c44fd8651d392ab19807b9bce1a7fad00d4a518a6Virustotal results 25.00% 
2019-12-18Untitled file 12182019.docdoc c3667c7d284b862051f4f8673af3a4a55728724e4791391882ba0b437a6eaf44Virustotal results 24.59% 
2019-12-18copy 7976671.docdoc f0d2e9149e26bdccd5118db6f99c8cff45e46f9471eeca2f2680742df15f9ba7Virustotal results 21.31% Heodo
2019-12-18Doc-N70844.docdoc 7d4dccc23bf9da5fbb6f74c516115a47ab6812b79175db351f6a331dee5c9691Virustotal results 24.59% Heodo
2019-12-18889283332.docdoc 854d5fd9c1117d7589ba87ffbe6e0016902612837bbd0975a230a5fbb65457f3Virustotal results 24.19% Heodo
2019-12-18copy-602008913242.docdoc a435b8c41e5a3d8b4fa32af0925ee6df051d375fc1b27a278d7c7b30d218fb82n/a 
2019-12-18list-915587472015_0749.docdoc a5c388ebbee623f26938d67427170bb063976b1dd0524f6ea18b402809afed4cVirustotal results 21.67% Heodo
2019-12-18UNTITLED-9731897995389_8898412.docdoc a5e5e4716eda5cccc9d9b8a61517b4fe21e4fbfcc4ecabbd3d08fc89b0f33f29n/a Heodo
2019-12-18copy MX4074082991644.docdoc 4b374d00508fa0a57fcc0ccd6b0246b913a9815d1123826e6ade818535e775f0Virustotal results 27.87% Heodo