URLhaus Database

You are currently viewing the URLhaus database entry for https://www.yzmwh.com/wp-admin/docs/jgndp-045-73-085s-5lbo1w85dw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289712
URL: https://www.yzmwh.com/wp-admin/docs/jgndp-045-73-085s-5lbo1w85dw/
URL Status:Offline
Host: www.yzmwh.com
Date added:2020-01-16 04:40:08 UTC
Last online:2020-01-18 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 04:42:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:2 days, 7 hours, 47 minutes Poor (down since 2020-01-18 12:29:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18MIG_3786886549655.docdoc 9360a477eafe49b7201165c2b2992b85819430dedf852f679f29e03bcb183522Virustotal results 27.42% Heodo
2020-01-18DOC_RIB_010120_MIJ_011820.docdoc a54e809b6163c56c3a3f25d2c7a54f2240785b00414dcbe2ad9b8c687f6eea2eVirustotal results 24.59% Heodo
2020-01-18BAL_DE9606820910VD.docdoc 9ba523a49280a5213dbdd7832ba69bbfed94fe8c05f269bb8319c05003a1a1b0Virustotal results 19.67% Heodo
2020-01-18SW_RG5538402942MY.docdoc 910cf54e7950d880c8bc459c76df3dfa906226ac6eaa41adc218c83a0bf03078Virustotal results 19.35% Heodo
2020-01-18INV_TS2MQK0P.docdoc 898938c960a20b8e73e9c648590cf2a66a823aa28cec79d54c0a3a6db9176e5eVirustotal results 18.03% Heodo
2020-01-17FILE_35671638.docdoc 5634f4ad6b81c51e0cc594f04f8f73acdfacdeb33707af138d032b57e955c322Virustotal results 20.97% Heodo
2020-01-17ST_EX7262852417SH.docdoc 397485a2bb27c1afd95ff7c8b962c7ebfe4983db30d1e65b71c0529cdddb2f08Virustotal results 18.64% Heodo
2020-01-17FILE_RTQ_010120_SYO_011820.docdoc 7e89360cca8f0234341841cbdf174fef602631feea9e9870c553d8dc29a7b0f0Virustotal results 18.33% Heodo
2020-01-17RP_JN8164438161GM.docdoc f992323a7ee7f0d396af278c17ad7c3b36e093c235c3c9057ab2c3728e370b36Virustotal results 19.35% Heodo
2020-01-17967759084918737.docdoc 77a0a8de225a0e6c5933bbf470c5ddc67e19d5ded59985a1e7a1b2316241ccabVirustotal results 22.95% Heodo
2020-01-17BAL_P17BYQ4N32IP54FB.docdoc 2dcd7158664b730a2b88ed5e36ff5fc8da8a49a3668ce6f3bea6a364bb4ccca2Virustotal results 19.67% Heodo
2020-01-17SQK_010120_OIX_011720.docdoc 5adadeaaa1059838cc3e87dbe95d95cc37a4699a94fa1ebb2f4e85e67aae6d3fVirustotal results 20.97% Heodo
2020-01-17A_01097694115321.docdoc 7bb5fdc2f055e22227b6471aa23ea22c95fa0235bc96bb40893513d1fc6e6d76Virustotal results 18.03% Heodo
2020-01-17PO_01172020EX.docdoc 1cccdc74817414b1cd45f3994d81744f4c979dcc6017f6ea3f7b15b3c720faeaVirustotal results 21.67% Heodo
2020-01-17OF1351946473CA.docdoc f1569c025b21d44c68867d142ebb944c3550240673430dceaed626e80acf386dVirustotal results 22.58% Heodo
2020-01-17SW_07247411136764811388611.docdoc a13b037457db0cfd6982e62e3f76dd834a9ae2ab29af1bbd7b72023221c47e69Virustotal results 23.33% Heodo
2020-01-17NN5066385002MY.docdoc b341338022811ab111de218e305ca99facf3a53ac083bc122255f0c2c9b8fd79Virustotal results 19.35% Heodo
2020-01-17DOC_U9GNZ6LZ.docdoc 496e82b4aac77a47fcb312c63e8f4061b480c523124f87e037522a5ecec5aa5bVirustotal results 18.33% Heodo
2020-01-17RP_IRI_010120_OGH_011720.docdoc 37278a792abb805166b18e71b5ff929822059156a73f739e9633dc16984d28ceVirustotal results 19.30% Heodo
2020-01-1726079102.docdoc 01803cd4cad276de7bde227f5eac222a512d1cdc85252fc4c34d23c36296fb05Virustotal results 20.83% Heodo
2020-01-17ST_JXAAK67J3.docdoc b5b1a9c9342c9be2197fc3f9fc5c0a9138b052bfc06583f9719773397f567e34Virustotal results 43.55% Heodo
2020-01-1711215119.docdoc 9db035bd19c8d9db27e5c352d8e713cfdd13b9a155772e9266b18ec30d67fba7Virustotal results 41.67% Heodo
2020-01-17FILE_55013724.docdoc 534d37a11e695ad6fd5b23ac1a8cb87571a5865e5651f954e3fefbf355ac737aVirustotal results 40.32% Heodo
2020-01-174022918692452886.docdoc ab93bc28a4a2dba3db6e1c25750476a6691de8988744db041f23d9d5c16e03a5Virustotal results 37.70% Heodo
2020-01-1742808820055625.docdoc 48844b331c7b74aac980dd55bd8d8388d187e2d3041712303c59644ef3fa16b7Virustotal results 36.07% 
2020-01-16INV_5117487825.docdoc 37b0389ffe84107582dcc9d62fc7091cc3a71915977dc69f605fb398902b3ce4Virustotal results 36.07% Heodo
2020-01-16SW_OKVI1A9T3.docdoc 58284dd1bedbf2c82204eb15cdad07525a70b52ff1729e051ac101c066531ce3Virustotal results 37.70% 
2020-01-16DOC_PO_01162020EX.docdoc a1a7bf3c673d0f16683303b44ae4f3aac3b77e1d419397ea09fc45b3a5b9dd77n/a Heodo
2020-01-16T_29495663.docdoc e314c8b472db81404961016b49758c54595600e83fa2801d5cba0089cb8b2223Virustotal results 32.79% Heodo
2020-01-16VRF_85174337099144942830.docdoc 6dc7f5025f0a9ba2abeb82a8db9a479f41a3a3ec8b558455b930d54029108638Virustotal results 30.65% Heodo
2020-01-16SW_0545722225780618836147104.docdoc 67e4ad463f707098e9dd3aa9ef44543687de41237cb6bd15500e428aa17c34c7Virustotal results 31.15% Heodo
2020-01-16SW_83255608.docdoc 3c99ebde95d760948c4ff5db925c0272ec89b8409d698aab26e5785a42c88243Virustotal results 26.83% 
2020-01-16BAL_64166653977.docdoc 9aa8f08a047314cbf2c0a541131a486282da8e2657c69fd731624e2823ada6c2Virustotal results 27.87% Heodo
2020-01-16959693223634.docdoc 1126c643bff1cbc4e48db0e96c1bb7522d89a64e31bccdf10629cc5402a5bdc6Virustotal results 26.23% Heodo
2020-01-16NY_DZ6999476094CC.docdoc 14aea8de9f3177801134498a4f81de17f490b3cd087fb826e8383a2b1f1e7049Virustotal results 26.67% Heodo
2020-01-16S_YDX_010120_WQJ_011620.docdoc 9d8dbba8a0e996de7449c8dfe3136a7eea73a02e9b6f67a095c53c54abb04111Virustotal results 24.59% 
2020-01-16RP_33515932.docdoc 2fab2f5e3f28d6a81ba72956df8ac00de3d7dbea09496ae791fd20a7954fe1ecVirustotal results 26.67% Heodo
2020-01-16ST_CQ0324573858RZ.docdoc 9b114f67484468604da8e6d028500f9e0fb32be159dc5dba550cd295be425b1eVirustotal results 24.59% Heodo
2020-01-16SW_49892514.docdoc a8daa5abd8b28562b74c89b4eb926bba5e5bfddc7746e95a5d4055896680ea69Virustotal results 22.58% Heodo
2020-01-16FILE_RQK_010120_OZE_011620.docdoc b56a6e25f16b75f974d90ac920bb38757ba86412909d0844c3195a7b0a04c757Virustotal results 43.55% 
2020-01-16PO_01162020EX.docdoc fc68dd9971f85e873151fa2dae765c3406a74e35a608879a7b46cc250986b63dVirustotal results 43.33% 
2020-01-16RP_YT0112902059GP.docdoc bbc7c13dbd64502c59d3890785c0a821310d29c04a915a23e62c31ed0756aea9n/a Heodo