URLhaus Database

You are currently viewing the URLhaus database entry for http://w04.jujingdao.com/wp-admin/r8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:296734
URL: http://w04.jujingdao.com/wp-admin/r8/
URL Status:Offline
Host: w04.jujingdao.com
Date added:2020-01-24 06:42:21 UTC
Last online:2020-01-30 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-24 06:44:07 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:6 days, 7 hours, 7 minutes Bad (down since 2020-01-30 13:51:55 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-25EO7edyk8mF2b8Z3.exeexe d0733ef087163d39bac9052c7ce081b7f9cdef3b6cf76399bf20981fee035d7bVirustotal results 28.17% Heodo
2020-01-259HtXRzBBwDV9mK.exeexe 624e415d5e8d618ca5aec90206b135ca09d447f2f93ba13c9d29936e1e82e663Virustotal results 25.71% Heodo
2020-01-25b6JGE.exeexe cfeb13e1b9ee13c523728c2f50b2f0d4687e201089354240d4922c8c4ccae693Virustotal results 24.66% Heodo
2020-01-24i8.exeexe f5c796677859bf77c9ce7c932e06044c12a222acbaaf59b8bc148152b3c2a46bVirustotal results 21.92% Heodo
2020-01-24EZVqMCwyXN.exeexe 4bed98bca264441964eeb7d6487b97319403a8f8821e93e12ac99f9b4fee0f40Virustotal results 21.92% Heodo
2020-01-249umiFG1yLi.exeexe 2477ef43b907ffe775ada1423f80da542b485ecd51d7f7cadb364a79f44ad217n/a Heodo
2020-01-24eWVYFuiML4Nfq0IOR.exeexe 6b6338adc49e7320d6a691b7013493409763cd803ca2e05c757e2f60c2011a73n/a Heodo
2020-01-24WEWI.exeexe 239feba9b3e4e49205b9923f262c9632db1861907eaa3f6bf33dc2df04bba67dVirustotal results 9.59% 
2020-01-24ywh.exeexe 9889218670d6df6c78c9f2db63d3258e638d65c6df758c23a99b1b2444fe5772Virustotal results 10.00% 
2020-01-24E1LuJIa6qm.exeexe b6ef484c1968c704a75ce2bb55af59bd6a8e5df87e26fbcb2ec0cc4a555578d1n/a 
2020-01-24jbAs.exeexe fe2d818f18aaadf4880bfe630b2785b6ecac1fda4969ea302b13daba8628cd38Virustotal results 8.45% 
2020-01-24k0Ag6rYLQo.exeexe e89eff09e2770c06eb1fbc363abc9b84ff32380d8389d576b9263cb29ddabcbbVirustotal results 9.59% 
2020-01-24Sa3L6F6oRrBJrWA.exeexe 412da91c22c92cd94c70f6a54348ef58b8c773c62e437719942daef74ce34ecbVirustotal results 14.08% Heodo
2020-01-24Jpq4bhQd0Rr6T1.exeexe 151f8626952174a53e07e35f1a0f9a224cb52ac14920c0ee43638fa4a14e71eeVirustotal results 11.11% Heodo
2020-01-24uvt17.exeexe 08bb9527c637f8b1d891a62b65aec91ac61ad7f092edadb876321d3a7020a7c8n/a Heodo
2020-01-24Lf.exeexe ebcdafa9988b835358b62a7b06c0816c44465f1ffb03e96da27963e5d6d2ba22Virustotal results 9.86% Heodo
2020-01-24Md1xDttTE3y07LviLN.exeexe 7ddd10db13581b72bc7f4a036127c5ea8e7e4f11676339259d8c1788a8406303n/a Heodo
2020-01-24Gt6Pp3UZ4FqVzhXe.exeexe 6dee4a060388c165f7978fe1773628dcf111405983e312a04183e042f957a211n/a Heodo