URLhaus Database

You are currently viewing the URLhaus database entry for http://www.maisenwenhua.cn/wp-includes/Documentation/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273805
URL: http://www.maisenwenhua.cn/wp-includes/Documentation/
URL Status:Offline
Host: www.maisenwenhua.cn
Date added:2019-12-20 08:26:04 UTC
Last online:2020-03-23 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-20 08:28:02 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:3 months, 3 days, 19 hours, 1 minutes Bad (down since 2020-03-23 03:29:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21ST_6491220029634.docdoc ad253e6647362deb3c0d03399e7f512ef78a155763d032eab642d24c4bcec1b8Virustotal results 50.82% Heodo
2019-12-21RP_547382597826149489706.docdoc 0dfb5cda8b86af6c45b6bd4bc68f9e23f7b6723b29f905008f1da435bfb93bdaVirustotal results 49.18% Heodo
2019-12-21SW_5325059MAQLSMD.docdoc 8d9d12f6119eb1d07db8c86dfb9ffb0db42075adff311005e0dcefc4db4362beVirustotal results 46.77% Heodo
2019-12-21REP_WTI_120119_BYT_122119.docdoc 08bab149c893a44f23ec39c10a85432c1180d99c868dfee6e7603a215f1c37e5Virustotal results 44.26% Heodo
2019-12-20RP_PO_12212019EX.docdoc e23bc5ee382cc5f5a5c5a62deca1d119ee4347bfd72aa40765a336f933d1f7f8Virustotal results 37.10% Heodo
2019-12-20DDNH_PO_12212019EX.docdoc 085190935b08f49102610d5161e97892089f567965412b270f354cf088338edaVirustotal results 32.26% 
2019-12-20PAY_DT7819519036ZU.docdoc 638f804c57e51f7ed5541d7055df81789b0075058ac6bb3681f2927527e3f173Virustotal results 28.33% Heodo
2019-12-20E393CEPC6.docdoc 8c3f2d0b5b55dc7b3de092f33fbd964798ad9801328e4e9b3350014af6353436Virustotal results 29.51% 
2019-12-20PG6754746796UD.docdoc 1a9e857c9686286a7c762d60ecef96c40c44ea56d89bc571a3e4d6a6abec38dcVirustotal results 29.51% Heodo
2019-12-20N_PO_12202019EX.docdoc 050f8bc2582036b0cf0d47a35c265fe0240f670f863d8a5478eac83f7cce1179Virustotal results 29.03% Heodo
2019-12-20B_PO_12202019EX.docdoc c99bb3c412455179a75cc6c83d36a3a13888e0a11a9ba6480ed0e8445ddc9ff9Virustotal results 27.87% 
2019-12-20C_3Y48ERRZT.docdoc 3142e7e7f2170357a683d301a7427d29eb6751d1adcf1741b3b861b58831b6f7Virustotal results 27.87% 
2019-12-20LOPZ7PDXTC.docdoc b296901aee4b73fba3d6f27601cef86eebadeaf229ee76a503c2cf113c3b13d7n/a Heodo
2019-12-20N_BB1833557419LB.docdoc 196f29371b2c77a572408329b348cfbc56481c42d1b46882bc7b6f3abbd1efe7Virustotal results 26.23% Heodo
2019-12-20D_77824271.docdoc 563f9a0ddae1277f7e3effa4a945f9a6efc62a9c173b26c9a41fe23b62559bb5n/a Heodo