URLhaus Database

You are currently viewing the URLhaus database entry for http://swork.com.hk/wp-content/uploads/2019/closed-zone/individual-area/EKmrCeQmSPMa-vtztt0lN8szj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300670
URL: http://swork.com.hk/wp-content/uploads/2019/closed-zone/individual-area/EKmrCeQmSPMa-vtztt0lN8szj/
URL Status:Offline
Host: swork.com.hk
Date added:2020-01-29 02:16:06 UTC
Last online:2020-01-31 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 02:18:02 UTC to abuse{at}amazonaws[dot]com)
Takedown time:2 days, 3 hours, 38 minutes Poor (down since 2020-01-31 05:56:56 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Inf_20200131_117616.docdoc c4cf9b5d45af4db61b8876038eab0b75807bf7d0637e1f0c6d3cc7df79275477Virustotal results 36.51% Heodo
2020-01-31rep_2020_01_31_15455.docdoc 02d4150ccb8c0569ecd99cc1a860f5c711f1cd2ba567aa5728b830b9f1789f46Virustotal results 33.33% Heodo
2020-01-31Dat-20200131-533.docdoc 8ac6cda8c7b4094b736c508bc231f782f410a72cecec097edb943014ce610585Virustotal results 33.87% 
2020-01-30INF 2020_01_31 19858.docdoc 38ed0185799cc1cb1e2fcfea1f554229ad2ddee7695a8eee704426cf83a6b7e6Virustotal results 33.33% Heodo
2020-01-30FILE_738701.docdoc 7e928307f956ba7153481f9c5ff422807d3b210a51be147e9fe988fa41d392c4Virustotal results 34.38% Heodo
2020-01-30list_2020_01_31_783.docdoc f49ee5e7c4bc2384d6506dbbec88af0952dd50e37bc2f61df774c6e8a47a3218Virustotal results 34.92%Heodo
2020-01-30REP_20200130_W5555.docdoc df43728a90f505ab871cacfc9dda0c255c46428970911584e7ff00a42c796c41Virustotal results 35.48% 
2020-01-30List-2020_01_30-6904.docdoc 915478aabf43d394dd3ef4f1cb6de4976b0415b9eea56cd6e50780c10b8da5f2Virustotal results 38.10% Heodo
2020-01-30DAT-5074.docdoc 6edd33f15c012fa0a5a49cc0ffa73234c8c178849d41a7b60cececefd9c852dcVirustotal results 38.10% 
2020-01-30mes 20200130 460.docdoc 4545be8ef7e08c3b47cf52ddd7db73179dc78b170f65f3ea2a8f0fd09325b8beVirustotal results 38.71% Heodo
2020-01-30Mes-2020_01_30-CSH80915.docdoc 11078ef33eb1bccdd13fee326af0b5a51e5d9bfb1335c25004cf281c01ccfdc3Virustotal results 37.93% Heodo
2020-01-30DAT_2020_01_30_LDY83555.docdoc 3a7b81bb27f1ab16420d1f91c2e9169a125499962a663c704918e216d5a7aa46Virustotal results 31.75% Heodo
2020-01-30FILE_20200130_VNG70618.docdoc e6d5e96c13f2b7b829475906025dfeee28fc96d040dff47ec11a3df708572563Virustotal results 30.65% 
2020-01-30arc 2020_01_30.docdoc 767b17c9708aa05e3d52db97aa2842a873f2cf8e9d75f19e3e8c84fd32442e32Virustotal results 25.00% Heodo
2020-01-30File 071287.docdoc 7099bcda5f0b4caadc077f6bc794a4dc8933e66863535f49c23c8b19ec793b7fVirustotal results 28.57% Heodo
2020-01-30REP_2020_01_30_2049.docdoc 6686a87ce4ec03815de4f384705a2a876aee4195ecaabf95d727a6d63030d4e8Virustotal results 29.03% 
2020-01-30mes 2020_01_30 GX191.docdoc 093fe06865cc5cd449e9684d621efaf181505881f5e0e818b0ec9c4459ef1ba9Virustotal results 22.95% Heodo
2020-01-30LIST-2020_01_30-9606846.docdoc 23b0933587b2ce021d44e764dcdfb9961d967b9e9490d154457df7e420cf9fa4Virustotal results 25.00% Heodo
2020-01-30MES.docdoc cbfd00a796bdd447134f7dc1f38823e8e2eefb7075068cc197ec67c044ecfc24Virustotal results 24.19% Heodo
2020-01-29doc-YP7418.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 22.58%Heodo
2020-01-29dat-CR4552.docdoc f3e0ea1e9f70b58a16ab7b737be16e81a1868a88fcdd4de0c1fb6c4a3aa6b3b9Virustotal results 40.32% Heodo
2020-01-29REP_PZ3039.docdoc de39c0b0ba341eb6a6c1cc3bff5a3dede93907976a77563396df5165f422ac7fVirustotal results 33.33% Heodo
2020-01-29REP 2020_01_29 TL084755.docdoc 49e28f382793143c68d57be83f8e7252dea8674a30f06b9063dd9ccfc4f25e85Virustotal results 33.33% Heodo
2020-01-29mes.docdoc 93e6b158ccceb81017a551ff0ede39622381a6ee79e572a206f2756b342a47fbVirustotal results 28.57% Heodo
2020-01-29DAT GV92893.docdoc c0ebbfa695c1e2d054d32b340956dfffb4c155a4e420caaf593b0f1bbccbbd18Virustotal results 27.87% 
2020-01-29list_2020_01_29.docdoc a6f8d6e5f80b47b55146e82c61a78c5ed8c451bcb68d157dee574d02c768ba30Virustotal results 26.56% Heodo
2020-01-29doc 2020_01_29 020853.docdoc 717b785246dc9287f784e18696ce1abfbcf2289df5d5fbd124092943be92e779Virustotal results 26.98% Heodo
2020-01-29mes 20200129 944100.docdoc 41f2df35fe03375e39b939c95142a9c04e1613e60bcdeb4f50ea339349d04243Virustotal results 26.98% Heodo
2020-01-29INF.docdoc a570252bf1c2fa10675c88c55f9ef2362c2c7d3ac6e6bc1400102a49f2aac861n/a Heodo
2020-01-29REP_2020_01_29_W329.docdoc aad9025b37d955a0929dc76185e7b87d374e735e3a30a258bd549dcfc7a1bf27Virustotal results 26.98% Heodo
2020-01-29LIST.docdoc f8a5336b371ee216fc6fb0d0b23eca343a30c1d0ff719e61a847bffaaaf64a21Virustotal results 25.40% Heodo
2020-01-29mes_20200129_BG745745.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29Inf-WV048.docdoc a1245dc00abc837e5b912c2aab2cc8eb34eb70db4bad71991edb4854fccadfb9Virustotal results 24.19% Heodo
2020-01-29mes_2020_01_29.docdoc 7c22eab322ac6b786498c54df9abb223c3466203f681028b1023147f081fd6can/a Heodo
2020-01-29Dat_20200129_6792.docdoc d6548725e281a6fac0ace4af505c15a21b8e1582ab951ad62e29dc42cae45885n/a Heodo
2020-01-29ARC_2020_01_29_9095.docdoc b7cb7ac3c2e6b877b9893ed5651e3dfe2937135d7a2bc612ee70c3abf4a8d654n/a Heodo
2020-01-29rep 2020_01_29 5940011.docdoc f5c5c5efd56a06272577f6aa8fde6fe22660095ec9332d7449f3e0769fa11b8eVirustotal results 42.86% Heodo
2020-01-29Mes 2020_01_29 364.docdoc 6a23106b558df36e6d88bb5b5dd187430087eff0c8a2ca1586f8538e8259e01dn/a Heodo
2020-01-29INF_054548.docdoc 403843da9f9fec9121c607bf92725387ae2715864e259d81fb897458613cee01Virustotal results 42.19% Heodo