URLhaus Database

You are currently viewing the URLhaus database entry for http://ziyinshedege.com/wp-content/TIGc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288565
URL: http://ziyinshedege.com/wp-content/TIGc/
URL Status:Offline
Host: ziyinshedege.com
Date added:2020-01-14 22:19:42 UTC
Last online:2020-02-14 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-14 22:20:08 UTC to esabuse{at}hkbnes[dot]net)
Takedown time:1 month, 0 days, 5 hours, 22 minutes Bad (down since 2020-02-14 03:42:45 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-169v6UUTtwIMpdX6.exeexe 6b6bb6160907d2963607bb41ec0f1c7d391905cd7f582564de3069bd71563aeeVirustotal results 10.96%Heodo
2020-01-16KZ1FsCdR6UbnEl.exeexe 41e37685e1549b54544d9f909065c769d29b2f4f509aa3c0c77b98fcd4adc648Virustotal results 11.27% Heodo
2020-01-16WR6AX7FDToH5BAITCDtHe.exeexe e7d75ee781a50d4e524e3576f086660fa4daceb8f9c7d7bac34680ac69348996Virustotal results 10.96% Heodo
2020-01-16PmwEZXiBqJRD6.exeexe 218226bd85f6c2de19dadfca664cdd6f08c563a2beb00abddda0774996a36175Virustotal results 10.96% Heodo
2020-01-16YBIcPckGbO.exeexe cb6719d8b59c50f3e2187977aac496fa5b36faa7f853df05fbb7c816b349dde1Virustotal results 11.27% Heodo
2020-01-16nE7Iyusd6sgU5EF.exeexe 9df8a0817f3d2d5c8c38cda5e544d4bd83b8c390f1092ea658d0a80609b1d0daVirustotal results 12.50% Heodo
2020-01-16t43un5.exeexe d64cbb8bd3719bb94fa9f41d0517de4ac3a4263e94c10a53773473422db2b2ffVirustotal results 12.50% Heodo
2020-01-16eReeudLMTnIZ4bUc.exeexe 77642c95a13d78fd7b19c923fd1c6594c11e95c455afe99f9f5b690f121860edVirustotal results 9.59% Heodo
2020-01-16Ly56IKbfm0G4wqcNzyApA.exeexe 03c6a147e6e33b70f3fb19f005101559f85d081388b71a11c2b7bd0c84354aa4Virustotal results 9.72% Heodo
2020-01-16Ue44vCNjipwpWPc5wkPRR.exeexe c73c08f5d977d0bcf811a42f078713f46e4e885eab70ed5c4894a1c7ceb07296Virustotal results 7.14% Heodo
2020-01-16HZGKPU8MW5.exeexe 9e0255b6b5c9297e998b374ecb1f89ef6be47c421be9d16b8daff219ba999fadVirustotal results 6.94% Heodo
2020-01-16K1YYojbqdzaGqv9.exeexe 33459d987b1157667de13a736b62717e4b0bd6d3115179296e2d6d335ef4ebb1Virustotal results 5.63% Heodo
2020-01-16C0o2TYGKXWYTeYC.exeexe e903a7f978598d2615464425cef81e32fe55c5b7f914e19cceffd11a63ec6ab6Virustotal results 4.17% Heodo
2020-01-16Ek1DlgS.exeexe f4a5804ad4ef8ce195027766679919d3eb26b3c568b7ff5e88de1b6d5c3610d3Virustotal results 16.90% Heodo
2020-01-16gTprcljc40oyhCcE7e.exeexe f6f9ecfb29d503b879b59d538987a595c6472102394d4ab0d8533b911b1bcf40Virustotal results 8.45% Heodo
2020-01-167KsItj5ll.exeexe d349c7d86ae12104dbf9cfee2db4e3e717c1143c844712054f02669f25e4fffdVirustotal results 8.45% Heodo
2020-01-161UfC12IiQ.exeexe 951bf8425e8bc2af26c50b7d1fb580ee2cd3c0d93b753894844b4b4040a12695Virustotal results 5.56% Heodo
2020-01-16mPkJa0pgq7L8abOH.exeexe e4f05753989e0eebdafe70cb4e22ced38663f27880f9285897e63bba843b1d84Virustotal results 4.17% Heodo
2020-01-159Js1.exeexe 19ff6c807c4267a7ccfd032ce1406d74f36ea63644428cb8034df8591d6c3c1aVirustotal results 5.56% Heodo
2020-01-15TVXGMgzsR0oVcX7C.exeexe 7fbc314f9ef020fdd1e1e5b3326fed20525538fd2aa0f245ce31f69038b8b634Virustotal results 26.39% Heodo
2020-01-15Uu9LTcMtoxWULbBssVX.exeexe 0ad6d45f14c02bf069e4ff4e74cc3e9135ebde9f57f2316a9210be5cb0964428Virustotal results 30.14% Heodo
2020-01-153EGtbw0.exeexe 8d617ac4ee979cf26aac32927ac85ad5d5be53d27ccab9e5b62b9bbe10fd473aVirustotal results 21.13% Heodo
2020-01-15NyoornqCiG.exeexe 555850e863dd682ece7944857b1a82ac095cb99640d3e73209153419f1a2bec2Virustotal results 22.22% Heodo
2020-01-15w62ofLNRpobeyF5r.exeexe 21bb5da42deae1872d427a83e1ad3f24d3db215facdc7ad154d507da45e55ad8Virustotal results 19.44% Heodo
2020-01-15Gaxn.exeexe 7df07e2bfde9be3d3235887378de97f36dc68894ad8c730299efdaab7f1d84d2Virustotal results 15.71% Heodo
2020-01-15myxYSTLGoxC1wXucs.exeexe a665f28be61e46b3670dc15be76fea22ff7b3e0e5698fe9eea2c73d655d18f72Virustotal results 30.99% Heodo
2020-01-15VD6Dh6QqSmmIc7hQgMA.exeexe 3986b6de95ec84668bd51060c960ae2f1e3e05d5107fd4815b0b42394cff2f77Virustotal results 29.58% Heodo
2020-01-156y4s43X7qtqbSLUlCH.exeexe c7b1d16675e972a28557b810b3c126eeed83b1c270d4138ebc0f09727575730fn/a Heodo
2020-01-15S4AHXHMfJNsvxKgsFsq.exeexe fd83c72e85e4df0eb890efc210dcdada8ed75d3a3e4c4d4e37e00944dc221861n/a Heodo
2020-01-15iEW7nQtC.exeexe 3deb68208c8fd88d698e0e77d7a8d4c8d98b12e4a3cc1549e9a9996460638e3dVirustotal results 20.83% Heodo
2020-01-15bUw99Dwzp.exeexe 3a8435df5ff02eb7664c16caa1713f1881a891f8fb13a45a4c099f808f0c5e01n/a Heodo
2020-01-15sqGuBqe.exeexe d33997e5f209057f5e408893f0d2afd2bd9552b0c57ccfeaf4da3f6e7cf5858eVirustotal results 37.50% Heodo
2020-01-15Kdel6q8ueuTpURoRE.exeexe a354d4d300d5f12577a95c48f96f79ee838f3a4a9226ea0fbc1bac2e5d73bc25Virustotal results 32.39% Heodo
2020-01-15x9pqzfaPbR5p193RGF.exeexe 78095f9bd4484673c003e0828b4aa72b4a56be77927d859acaf1943e1805db5cn/a Heodo
2020-01-15vdfaeJaxB9OMb.exeexe 6fd6da9270d03478dadfe4375e533b2c5a1f1092c39dc364e69bdc8e1a97f711Virustotal results 26.39% Heodo
2020-01-14d2vKNgiKwdmjfcs1EHQ.exeexe 1746c81d1d2bcd7bca7346b2a1e0bb036c927b3e9d8629af8c7a442dc03785caVirustotal results 27.78% Heodo
2020-01-14sasnOwt6LddWG32.exeexe 7f77dada2fe25ce423a169d1229b4aa926b4b5b3be976d1981c2b5cae48e9ee8Virustotal results 26.76% Heodo