URLhaus Database

You are currently viewing the URLhaus database entry for http://wqapp.50cms.com/addons/JMvvHuNs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:291186
URL: http://wqapp.50cms.com/addons/JMvvHuNs/
URL Status:Offline
Host: wqapp.50cms.com
Date added:2020-01-17 19:30:54 UTC
Last online:2020-02-14 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 19:32:04 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:27 days, 14 hours, 49 minutes Bad (down since 2020-02-14 10:21:04 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-11luaNfmnW1sp79iI85pO.exeexe 95f830da739b987cfdf09546cc0d720f557f69f7f63bc62e7365845d1dccb8bdn/a 
2020-02-05luaNfmnW1sp79iI85pO.exeexe 292a9855c5aecfa3e6e0ed775cbc13158d94ade1d137cef8d8b7a7298955a1b5n/a 
2020-01-31luaNfmnW1sp79iI85pO.exeexe bdda65b8a2aedf913541a9637940a95955f691778e0a65ea8f3e4eeb13ea63b1n/a 
2020-01-29luaNfmnW1sp79iI85pO.exeexe 39dcf802eb196c33eca4ab46a75816cd137ce64fd1c20cef91c93d637a10e73en/a 
2020-01-29luaNfmnW1sp79iI85pO.exeexe b2e15087382af276ec31d4954d474da9e619806b7d2fda1b7f7f969e589a9a0an/a 
2020-01-27luaNfmnW1sp79iI85pO.exeexe bea6d90e7b58a13735e40646db755a393ce0702f0925c114902c553e0ec89c2bn/a 
2020-01-18S9W4mJ8pvLxX6ANv.exeexe be403ce2d14f38b66528d438457927218f1aa44a68530bf46b2703da75dcc8bdVirustotal results 26.76% Heodo
2020-01-18jyKDOkgar8Vqq.exeexe 8ec47534c73e03302d650eb9e98b8ce9b048edd49cb68ed6061ffb9151248366Virustotal results 18.84% Heodo
2020-01-18mKGr0FxxzZ.exeexe b1e1931567195640c4e361cefb4e3ebc2b3588f2ff209e4e441db4284cb9111bVirustotal results 13.89% Heodo
2020-01-18cBa4.exeexe e9a40a3dffdf4520b286d3a3ba1c9a2ceb395459ce561b65121595086683eddcVirustotal results 13.89% Heodo
2020-01-18dF3OjHz5Qpxzl.exeexe 68e699b962af409b5e0cec19f0670991fa5b2dc59672c91cdc4f7a59c037dbf6Virustotal results 9.72% Heodo
2020-01-18G.exeexe c1dce61939aff1b41632d863038cbf9b9add39ddaee630367cbd210899026b34Virustotal results 9.86% Heodo
2020-01-18KfnIh7Nx3.exeexe eed6e133cc200be2be07df0a9e069be0e7633248b055bfb69b907af4a01c3206Virustotal results 9.72% Heodo
2020-01-18dubNJeZ4GVJAz0.exeexe cbf4d162acf55c6e5bdf5f80b313487426ecc6066306236cf8a95f7995b40d6bVirustotal results 8.33% Heodo
2020-01-182xr1.exeexe 34b5c666e95d914089e1b988c35bb69a2a9d3685a5460d4cf632881f8621c3beVirustotal results 9.59% Heodo
2020-01-18LLckyquCrrNe.exeexe 59863e214ec80f34af3635dff517541de923688239cb343c82250587c1e9c99fVirustotal results 8.22% Heodo
2020-01-17vU.exeexe 7b8672b4397bb9300e2b48400945727108f27aad2a32042f1b30494b8c2b3eacVirustotal results 12.68% Heodo
2020-01-17lVKSBTJxzfkYfd.exeexe f06c2d95c47b4510825a3ab1559191fed0838533eb1008b38fa0b29b72d56691Virustotal results 15.28% Heodo