URLhaus Database

You are currently viewing the URLhaus database entry for http://www.xiegushi.cn/error/protected-disk/446129-ln4HLDhYvKUixa-9958640825-M4wphS2Ozn/cj9bqfcaVa-keKtJNL8u/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299793
URL: http://www.xiegushi.cn/error/protected-disk/446129-ln4HLDhYvKUixa-9958640825-M4wphS2Ozn/cj9bqfcaVa-keKtJNL8u/
URL Status:Offline
Host: www.xiegushi.cn
Date added:2020-01-28 10:42:22 UTC
Last online:2020-05-06 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-28 10:44:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:3 months, 9 days, 2 hours, 57 minutes Bad (down since 2020-05-06 13:41:35 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-03-05inf RNX69431.docunknown 47035316252b86bf77d19915157e9288409e61467cab92e491b07e88464ba64cn/a 
2020-03-04inf RNX69431.docdoc 033e7ed13627fba7eb400661fab64f35da2f6bf07fc654dc0063adc9fc0c21a6n/a 
2020-01-29inf RNX69431.docdoc e26c4466ac96339cf441036fb05d86cba2f624e2c7481c1ca86209c19122cbc6Virustotal results 40.32%Heodo
2020-01-28List_9618.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28ARC_20200129_WQN099413.docdoc 20f6d17240c7bfbee9f9691efd1bef583201bfdddc09ab886887cf5d4993773dVirustotal results 41.94% Heodo
2020-01-28inf-KG22791.docdoc 700e61463a60f3fae72d32f45e0d8ddd9da4432d8dfd98d50153f7a04e476146n/a Heodo
2020-01-28arc_20200128_Z60589.docdoc e6384df1ef6040795e8d6521f54723cd118a6b6cd4a007f0ca96e3558f55b81bVirustotal results 35.48% Heodo
2020-01-28FILE-W30223.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1Virustotal results 31.75% Heodo
2020-01-28list 887.docdoc e973fec4c3e5b5f599c5defe0c00df33eae0e9b00f1f8a1d8f9479d4e343e446Virustotal results 25.00% 
2020-01-28FILE_422433.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28dat-20200128.docdoc 17de704a282307408b556e2328dec5c5715d0cd7136dcdc1d6fe54f841dc2bc4Virustotal results 23.81% Heodo
2020-01-28file_UV837254.docdoc c50c6dc106e4d46b561eb4f45f329818ee1c5077cf4d4b4010ce38d01e437756Virustotal results 22.58% Heodo
2020-01-28ARC 0397374.docdoc 267aa23c9031b06e6dc7fac45daca30a65d4f08843fe0976c2ad7201d9646dafVirustotal results 28.57% Heodo
2020-01-28DAT-20200128-753.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo