URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ztbearing68.com/wp-includes/ktC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299399
URL: http://www.ztbearing68.com/wp-includes/ktC/
URL Status:Offline
Host: www.ztbearing68.com
Date added:2020-01-28 02:36:13 UTC
Last online:2020-03-12 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-28 02:38:06 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 month, 14 days, 7 hours, 16 minutes Bad (down since 2020-03-12 09:55:01 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29invoice_DYV39_02194578.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29invoice-UU92_66776178.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29INVOICE-KMX1705_197109819.docdoc bd1eac417a2f82f5ed9f7dc86783678343738758322a16a7d21d77cd587a4f55Virustotal results 30.91% Heodo
2020-01-29Invoice_4656_2715597.docdoc 3bdbcccc69e55ca69203cb80868675eb9aed4e2e9f880d181e51bb341905b8b7Virustotal results 28.57% Heodo
2020-01-29invoice D251_031887.docdoc 72135c6d015b299b10f9a4f9810b8e217b43a66581dbc869d2562cbec3de54d0Virustotal results 29.69% 
2020-01-29Invoice CBLC416_81478245.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Inv-ZR58_633648024.docdoc 603a04c67b941a3ff9345c94e890896e5570dd544e8ca3998f5197f45ab28f00Virustotal results 26.56% 
2020-01-29Invoice-K2_104500.docdoc 6eb3be35a52b1bbd297eec41d1d5871bb1f27a225f381a75a1040eea80a20ae4n/a Heodo
2020-01-29Inv-09_4794040.docdoc 93071be8d8601593e3f0dcc01e70f4ed2a3b90c67285382701f817ef6db23b8eVirustotal results 32.73% Heodo
2020-01-29invoice_HX908_695559955.docdoc b9b47debd4d9fb932401d580847e8c3f82b770c5163dbc7d405aefb5cc704a1bVirustotal results 31.75% 
2020-01-29INVOICE-D962_0853072.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Inv NDLZ6_9758735.docdoc 3a7a8518b41dd6c05289a08974c95a0038be4e5d1b0588edfd0589fcf22b0c8fVirustotal results 49.18% Heodo
2020-01-29invoice-ORQ705_98782948.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29Invoice_RTC299_69499527.docdoc 722a60dfd59a595daa487f2fb759ef6f9ccaabcdf20605d5ae9450cba4a9b9b2Virustotal results 46.03% Heodo
2020-01-29invoice 9_9674288.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29INVOICE PA3880_035685216.docdoc ea3a0a223474592635d1fb7a0731dd28a96381ad2562e3e064f70e2d4830c39dVirustotal results 49.18% Heodo
2020-01-29Invoice R36_4354622.docdoc 849aedf219a4f6ab15e2c5c653a8bbd6fce909c51d2e95984bf6241f6b939e89Virustotal results 48.39% Heodo
2020-01-29Inv 5_4541873.docdoc c25db0a6d33ba3de2ea0ea992b98117d92ef8cc0a1dc6d9ff79788db6ce7e06eVirustotal results 47.54% Heodo
2020-01-29Inv GFBJ64_556139185.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42n/a Heodo
2020-01-28invoice-HQZ8141_8951293.docdoc 1dd0d4d09771b53f50226d140b1a05702fbafbd0a98ed27d9a1ab68634c15365Virustotal results 43.55% Heodo
2020-01-28invoice EYIP274_203495422.docdoc 0617b35ff84886cd395bbf20745f3b82a830d97b07b0085b0f4aa056bcd57cd9Virustotal results 42.19% Heodo
2020-01-28Inv_538_503989.docdoc 9dbf7690bf328942e99f61b0eae8db502e74c272b7499da4342e6ee7d915bda2Virustotal results 40.32% Heodo
2020-01-28Inv-46_4400073.docdoc 85e978955f2d5b46e50d3a259f837643be8e5b3e0c643465881342f1cc7f3d31Virustotal results 35.48% Heodo
2020-01-28Inv-UP766_113919.docdoc e8c780bbb1f9fd071b00776b138b3cf27c3815c7203593068e78774d4dbdb36aVirustotal results 30.16% Heodo
2020-01-28INVOICE 1_8799687.docdoc b351412551b1d480fe50603de72c1d23a0afa22991461d2b812edbf5ad7d6021Virustotal results 25.81% Heodo
2020-01-28Invoice UIXT5_8413588.docdoc c17c75821c89a7ad0099092a5b55fcc514e74124e43e60fcf669de6436453b82Virustotal results 23.44% 
2020-01-28Invoice RN441_44733639.docdoc a7cd0e0d4371256091f7a81ff6100974822424c0c06e2dd5e07956b1ab62c19eVirustotal results 24.19% Heodo
2020-01-28INVOICE-H25_327721.docdoc 6f22c0d4f43bc7fac554939e9cd9d7e36caddda37a31e3a6acfb54c6033a2074Virustotal results 24.19% Heodo
2020-01-28Invoice-IG9_192604691.docdoc 58cd4f0ffbd2cfb01f153efd0e8560a2475bc3f98abaf8ed787f8fe17166524bn/a 
2020-01-28invoice_NJ2_572809.docdoc 32a27468a4355d462e5de6e29290189f023ad6b51836d3134dcb19a74f615f51Virustotal results 25.81% Heodo
2020-01-28INVOICE 628_714218.docdoc fcdf9154d769d5e1f3935355b39b57010d978fd2dc9ad24a1df12131f7d34155Virustotal results 26.56% Heodo
2020-01-28INVOICE YBG5264_150787739.docdoc 10110ba02728cd33f942639ed9af5ef77659f31b95631ef77803c3e8b97d72efn/a 
2020-01-28INVOICE KQ2840_35883631.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28INVOICE-22_10247387.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo