URLhaus Database

You are currently viewing the URLhaus database entry for http://demo.yzccit.com/jslyzyxy/wu702wusdraj-3f4r45q-sector/8lcix33w-k8l1-space/CdTSgcTL2aL-LrbnK3yjfL9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290247
URL: http://demo.yzccit.com/jslyzyxy/wu702wusdraj-3f4r45q-sector/8lcix33w-k8l1-space/CdTSgcTL2aL-LrbnK3yjfL9/
URL Status:Offline
Host: demo.yzccit.com
Date added:2020-01-16 18:48:05 UTC
Last online:2020-01-24 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 18:50:04 UTC to abuse{at}amazonaws[dot]com)
Takedown time:7 days, 11 hours, 45 minutes Bad (down since 2020-01-24 06:36:03 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-201605044-2106106551.docdoc 85df9b99b6ef90dfc11b43e0e412e5379f0d77b2d4293a04705987d3ab92968cVirustotal results 38.33% Heodo
2020-01-189560990.docdoc 05ed49924f9a734be2613850bc14127dd985d33127bb4974abe4141032765d35Virustotal results 29.03% 
2020-01-18Untitled 60228.docdoc 382d4b003341ac1a0515f9034bbc23810f761be5352f3d7879cc42a688d7faa7Virustotal results 27.87% Heodo
2020-01-17866163-0899315.docdoc 934d09dc782edf79b211e9f093e41287e15c64271bb2075d1ac9c9326f1db595Virustotal results 22.95% Heodo
2020-01-17079.docdoc 83ddf410b62973fc0fe5722afa6b78fa67eaecd15d7e313cd7113de8f362061cVirustotal results 18.64% 
2020-01-17UNTITLED 4240410.docdoc d293b2b91bd68c8b8ae7dae6cdbbcac02a533dd9256195096f026bd42d896b7dVirustotal results 19.67% Heodo
2020-01-17UNTITLED 2446908-868357.docdoc e7c83acc1f74cebdaccbfd1af1697b358dcc86a93cc49a977602623a237a7b6bVirustotal results 19.67% Heodo
2020-01-1722644358_723.docdoc ee7c4202139ddfd772aca3c315abdfd96be26edd0bd7a63c9f215fbb7d3ffd22Virustotal results 21.67% Heodo
2020-01-17855240104.docdoc 5a0bb9b15555a25dc31379feede50b11df32b3fdcb7fa379d4e0a04fab25a7dfVirustotal results 20.97% Heodo
2020-01-172411.docdoc 46ea2710d8a7879256b328b5e5d93d1c3d784d463a093cea5cadf590da608876Virustotal results 21.67% Heodo
2020-01-17Attachment 7422776.docdoc 6e6f3a8a41c935b71774bf8e2626d22f8a9e945be48d32174dd7dc8d4479df4dVirustotal results 18.03% Heodo
2020-01-17Untitled 3862441467.docdoc 4926c006521338ee85d1c82e53db2c39908c6e427d7570cfda91eebfd40b04ebVirustotal results 22.95% Heodo
2020-01-17Attachment 66044-7679020908.docdoc 2aa190aa43a9b64ec5c9829d4b00ebe3a0ff10d0c0604e8701023ba9277094b7Virustotal results 24.59% Heodo
2020-01-170004772.docdoc 3b413847d0f9ccd627ced7d72c5982cd9aa79f63770e4d130309547599f09229Virustotal results 20.97% Heodo
2020-01-17Attachment 6683937_7657.docdoc 099281bc0f4679a95bf4918039cc7fd570abd7b07e0f00e304d3c6ae221fc804Virustotal results 18.03% Heodo
2020-01-17405.docdoc 6887eee1f9548eb848d7563e4759f3e027595a199a3336c91efe494a554b881aVirustotal results 19.35% 
2020-01-17926.docdoc 17e6fbbc141f6b7e27df7ddeb423b4aee5adfecd80db00b9990b85ca7d75fa88Virustotal results 18.64% Heodo
2020-01-17Untitled 330941-11722476.docdoc e0ad47140e2313f3bfef8babb2fc62ac841aba00c47b310bdbbb53a1e6de73b0Virustotal results 42.62% Heodo
2020-01-17Attachment 0331-489015.docdoc c337f30bb0849f7809a7492b21ac4096beb20d982dd2080d1879c14cd84cd617Virustotal results 41.94% Heodo
2020-01-17873933_503468.docdoc baff02e524a1dc5e3aa3c7d79cd378bc8c858c899d1e25e75b0c13bfcbeb48feVirustotal results 40.98% Heodo
2020-01-1701210.docdoc de8f84ced2a3a6a85aeb9ff016c38d519a51898a16fb059a6555f9df453c4595Virustotal results 36.21% Heodo
2020-01-176401.docdoc 49a2ab600f53f77b09bf90962731f7559940c6dba4c5151d67ff9bd581082d9en/a Heodo
2020-01-16UNTITLED 161398206_817.docdoc f942462b771aaec7fb9e1bb8fc3eeeed0fa6c2b229eb6950b8135afa16403305n/a Heodo
2020-01-16Untitled 73945185.docdoc ff459925a85db389a7edc8d34a3790aa03a75c0169484d7aed22ed773e14016fVirustotal results 37.10% Heodo
2020-01-16647-0558816.docdoc c72ff1f75ed19acac36642556195af80d960cd66f339fa14fd1df1f32b09f1a8Virustotal results 38.33% Heodo
2020-01-16Attachments 457991_9191.docdoc 8093f212a74f3a761bdb0cd3df8c0a2c745dbaea2c4ec4592d5eb4c1963c2e60Virustotal results 31.15% Heodo