URLhaus Database

You are currently viewing the URLhaus database entry for https://zcb.hsdgk.cn/wp-includes/protected-disk/verified-profile/1868782867-Kl7ZEm4bBTXZycw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299680
URL: https://zcb.hsdgk.cn/wp-includes/protected-disk/verified-profile/1868782867-Kl7ZEm4bBTXZycw/
URL Status:Offline
Host: zcb.hsdgk.cn
Date added:2020-01-28 08:31:14 UTC
Last online:2020-04-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 08:32:02 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:3 months, 2 days, 0 hours, 9 minutes Bad (down since 2020-04-29 08:41:59 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-30mes-2020_01_30-525588.docdoc 8de125da28c8e4b9808d8e4555a2879d781a5301dd49a50795ec8d9714ea0b3aVirustotal results 25.40% Heodo
2020-01-30Rep-20200130-MLG0947.docdoc 4932fd4b350016a8ffd5945209efaabc177ab4bb83e310f2896d29c02e0a612fVirustotal results 25.40% Heodo
2020-01-29arc_2020_01_30_8512196.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29INF_2020_01_30_S63501.docdoc 4e2697404537ce6a8ec19caeb51f6ab87704a57dde37bc9814ed69ace7328995Virustotal results 41.27% 
2020-01-29Dat-2020_01_29-SK162754.docdoc e49d66744b97eaa47dae870c0fdd5f6b3a52e1b2245e8567ffa6b8a344663fe8Virustotal results 34.92% Heodo
2020-01-29LIST-20200129-2648030.docdoc 7e8c0e91d30b485bed7963d9d3169c243edb3f5f2ce5e8049df4731007ea4d61Virustotal results 32.26% Heodo
2020-01-29DAT_H34727.docdoc 49725f6641477d5fcdc1933e66eb652922a1e1264277a6aef8069967eb0084f0Virustotal results 30.16% Heodo
2020-01-29LIST-2020_01_29-716339.docdoc b09c8d39fe17d600ac2beffd9540076f55d944b41ae3c11b26600252a272b3ecVirustotal results 26.98% Heodo
2020-01-29DAT-OV9581.docdoc 7caba02f08e117aabc3a0f109c1e5d565c3fdf3aec3ae0c90d0d78a16b6c2a8eVirustotal results 26.98% Heodo
2020-01-29MES-2020_01_29.docdoc 41f2df35fe03375e39b939c95142a9c04e1613e60bcdeb4f50ea339349d04243Virustotal results 26.98% Heodo
2020-01-29rep.docdoc 0b0243567f8017cba7be007b4d797731af10a9c7e9971cb09881d0a646bf88a2Virustotal results 30.00% Heodo
2020-01-29Dat 449.docdoc 6765421b973c2bc3603b0f52f3ed514310bb83b678823614f845b6d4b1cbedc9Virustotal results 26.56% Heodo
2020-01-29ARC_20200129_678116.docdoc f8a5336b371ee216fc6fb0d0b23eca343a30c1d0ff719e61a847bffaaaf64a21Virustotal results 25.40% Heodo
2020-01-29DAT_53523.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29LIST QU24830.docdoc ab46f8f9b1905e64a35d9db9e9ff84df5eb21679b53d1291553d1b6a936554a5Virustotal results 23.81% Heodo
2020-01-29MES_20200129_351.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29ARC LP557.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29mes 20200129.docdoc b40831be7daa247208f2f37c223101e825eca3eaedbae7a72de040e21852ae00Virustotal results 42.86% Heodo
2020-01-29Dat 20200129 OQ8851.docdoc 8c05cb88caacbc8eb0e4a1e79a0d1a707959b45fb39f5e694923b6b069ebce75Virustotal results 43.55% 
2020-01-29Doc HBB8365.docdoc 6a23106b558df36e6d88bb5b5dd187430087eff0c8a2ca1586f8538e8259e01dn/a Heodo
2020-01-29LIST 2020_01_29 133.docdoc 5ed01ecc76724ef8dff654d4ef2b359c600c6dd3da2481677304b851d0c752b7Virustotal results 43.75% Heodo
2020-01-29list-2020_01_29-10807.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29MES-2020_01_29-P495339.docdoc 99f4cbe6a9549c0dd8d99cdbee3c8ffe2c85d61f8a3cc94d1e57a962e4497be1Virustotal results 41.94% Heodo
2020-01-28ARC 20200129.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28Mes-2020_01_29-8324421.docdoc 4b4867516d0fd10fb9b46f9474a7db95edf90a09b41086aaa1eef12ed73664baVirustotal results 41.94% Heodo
2020-01-28rep-20200128.docdoc 9a1962dfceb1a62ff349d932160c03ec9304954e3a0fb69e25b672fbef7b90b4Virustotal results 36.51% Heodo
2020-01-28File-VF587.docdoc 4f0657b4834de2757799949da41f3ed5391b919f6539122e9dd06523c75df20bVirustotal results 36.51% Heodo
2020-01-28Dat_HT129939.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1Virustotal results 31.75% Heodo
2020-01-28Inf 20200128 179.docdoc c1cab8e632a4cf554ec0a4d36e228aae0333fbf9f2bbf06bd23dfe0197bf885cVirustotal results 25.40% Heodo
2020-01-28rep_2020_01_28_965286.docdoc 7d66af4b1a956e0ddf0d0eb592a01b7506541b769b54272d7882c872b2019922Virustotal results 25.40% 
2020-01-28Rep-2020_01_28.docdoc 17de704a282307408b556e2328dec5c5715d0cd7136dcdc1d6fe54f841dc2bc4Virustotal results 23.81% Heodo
2020-01-28dat_20200128.docdoc c50c6dc106e4d46b561eb4f45f329818ee1c5077cf4d4b4010ce38d01e437756Virustotal results 22.58% Heodo
2020-01-28Inf 2020_01_28 9230527.docdoc ff3030128824873fe504c15ecf0cd7b700b36b02bee75fad21ac9d45ea20fa58Virustotal results 30.65% Heodo
2020-01-28dat_20200128_81766.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28Mes_20200128_325443.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo
2020-01-28inf_498074.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28ARC 2020_01_28 SBT9535.docdoc de17002f75f0fb919b4201123c082332243cc6a0bef524c6d5a82a15d906d396Virustotal results 22.22% Heodo