URLhaus Database

You are currently viewing the URLhaus database entry for http://hxzitong.com/wp-content/closed-dw-21xsfx04ef4j1i/45710363744-gh8bXl-space/i3ONFALaMb7-yI6m13oH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:298972
URL: http://hxzitong.com/wp-content/closed-dw-21xsfx04ef4j1i/45710363744-gh8bXl-space/i3ONFALaMb7-yI6m13oH/
URL Status:Offline
Host: hxzitong.com
Date added:2020-01-27 17:27:11 UTC
Last online:2020-01-29 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 17:28:02 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 day, 11 hours, 7 minutes Poor (down since 2020-01-29 04:35:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29File-Z657711.docdoc 21c2a2a3240b1a41cbae3e253d00e74065f031a23a74bb27493c9473fe9a4c02Virustotal results 45.16% Heodo
2020-01-29mes_2020_01_29_OHE2807.docdoc 623303d6b597c92e43276ac21c6338a64cb078760e9a74bd08050666a3aeca13Virustotal results 43.55% Heodo
2020-01-29DAT 729.docdoc 0a0530b377e9bcaeea9205f33707dca59fe46b7606072993d55bbcc08b010740Virustotal results 45.16% Heodo
2020-01-29ARC 20200129 OBY259.docdoc e26c4466ac96339cf441036fb05d86cba2f624e2c7481c1ca86209c19122cbc6Virustotal results 40.32%Heodo
2020-01-28File 20200129 0058.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28MES 2020_01_29.docdoc 4b4867516d0fd10fb9b46f9474a7db95edf90a09b41086aaa1eef12ed73664baVirustotal results 41.94% Heodo
2020-01-28Doc-2020_01_28.docdoc 9a1962dfceb1a62ff349d932160c03ec9304954e3a0fb69e25b672fbef7b90b4Virustotal results 36.51% Heodo
2020-01-28MES 20200128.docdoc fcb69f15a7e0e60e6d3b818f8c82d51c5a011ff2fa5097c6e85fdccc1781049fVirustotal results 35.48% Heodo
2020-01-28list_20200128_6211.docdoc 2063f0749cb5832ffe25435cb2bdb2060ee2aca45409e0990772283bf9d37d72Virustotal results 31.25% Heodo
2020-01-28FILE_20200128_295652.docdoc c1cab8e632a4cf554ec0a4d36e228aae0333fbf9f2bbf06bd23dfe0197bf885cVirustotal results 25.40% Heodo
2020-01-28FILE_20200128.docdoc 94f8366405f8ad59fd932115696494dfec9ce3197e7b499a51717643d0325df1Virustotal results 25.00% Heodo
2020-01-28Mes-20200128-L8823.docdoc 2fac5572f786da32ea0810309138075fa6d25b8fae0f0f92a0c7e539353ca05eVirustotal results 23.81% Heodo
2020-01-28ARC-2020_01_28-767870.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28doc_20200128_PM90451.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28List 826413.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo
2020-01-28MES_2020_01_28.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28List 2020_01_28 H311087.docdoc 425b0713c3b5db493d0272ed01e04f9a1e5309884f60e13d4cf0edc6637fff57Virustotal results 22.22% Heodo
2020-01-28Doc.docdoc e7ad66bb697a067a77d8161ea282f57732ad655dde508698cfc0b31ffdc18988Virustotal results 22.22% 
2020-01-28Dat C8997.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07n/a 
2020-01-28list-2020_01_28-MD633141.docdoc 61d0d2aa3f2b0af2db0d2e4037ac0753965f1d03e0231b17a3695337b66ddd79Virustotal results 40.32% Heodo
2020-01-28arc-2020_01_28-OSW76136.docdoc e5f579ac649c7d63c79885d849d0631d7a0fdddabb60cc9fe78f0583a9d00396Virustotal results 41.67% Heodo
2020-01-28file_20200128.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28arc 2020_01_28.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28ARC-UJ220635.docdoc c13b52eb583794eb0a50cdcaa031505507d999bc95725e77c29eb6b1adcfffa8n/a Heodo
2020-01-28arc 20200128 915.docdoc 5d122705ee27c72e755eb8df3baab283269868ae0095c36474b8195aa96048daVirustotal results 41.94% Heodo
2020-01-28INF_20200128_0556867.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-28rep-20200128-IMG4224.docdoc 3927da4014a56e521774e33625a1ac60e65e39edee26dca5fc703fc240bc0c99Virustotal results 37.10% Heodo
2020-01-27arc 20200128 3202826.docdoc 010557b57dc7eed6705961196595b0ee3d067ad35d29cf8d4a7c8ee9de520077Virustotal results 32.26% Heodo
2020-01-27List-20200128-BP602680.docdoc 105d24ebb512c02c992f5b330459830f12ece2b54011cd65914e673f0617c8c7Virustotal results 31.67% Heodo
2020-01-27Dat 2020_01_27 UC64339.docdoc a8c9af0be1439e2adf85b682b03a2fb83562da6dd8c40ed6a07502d1ed966b2cVirustotal results 30.00% Heodo
2020-01-27Doc_650.docdoc 6622600c3f950cc551f08835827909fc6c40b84c79af134de73acd5982549bfaVirustotal results 29.31% Heodo
2020-01-27arc-393519.docdoc da8d6f1ef41c9971964374e26d7ad166a13139e59754cd50509ebc535699161dVirustotal results 23.44% 
2020-01-27dat_LF67745.docdoc 9881e14e8f9d151382c8cce8f4b84a968db7537c4b66ecf46bcd02d35b2bcfc4Virustotal results 22.58% Heodo