URLhaus Database

You are currently viewing the URLhaus database entry for http://www.zhinengbao.wang/wp-content/common_array/ir5na94zc_df6ozr6m_space/zw1r26j8vkb3z17_u37x7471x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303501
URL: http://www.zhinengbao.wang/wp-content/common_array/ir5na94zc_df6ozr6m_space/zw1r26j8vkb3z17_u37x7471x/
URL Status:Offline
Host: www.zhinengbao.wang
Date added:2020-01-31 00:57:07 UTC
Last online:2020-02-16 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-31 00:58:02 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:16 days, 0 hours, 8 minutes Bad (down since 2020-02-16 01:06:20 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01file-2020_02_01-MW9862.docdoc 27689a930fd81d023602e707ea9431d24fd92189df1a2acf8f8cf481f60180ean/a Heodo
2020-02-01doc_20200201_3721885.docdoc 0868d596c8affa141c596d7bfb80521df4e2147cacf37ce374b0cc357cfdfc2fVirustotal results 35.94% Heodo
2020-01-31REP_20200201_1276474.docdoc 16dc2ea6966445ff4b382ab180a5983bbe8513068550a030d7581fd6c0e46bd7Virustotal results 38.10% Heodo
2020-01-31mes-2020_02_01.docdoc 4baf8e9392bf622ac92d0f6c9160608a3dff028c5adac479c599cef9f4b81272n/a Heodo
2020-01-31doc-20200201-9107.docdoc aebb8ef053c29de1aab7da94fc9873aee20eadcb51be762f73f08a2aa0cea7baVirustotal results 31.75% Heodo
2020-01-31Doc_2020_02_01_Q491925.docdoc 7df4b1ba365168795d999be611b28e076068dc3a6a2fed14e065dd689a2d841fVirustotal results 28.81% Heodo
2020-01-31list 2020_01_31 JWV556252.docdoc b21358d6c77db859428adedf4f2f657357cc13d818befc72583e6cc9590cd135n/a Heodo
2020-01-31mes_20200131_R1470.docdoc 1bbba6556de9b7552cfe85621ad8905c44d0a59782a9db60bec73e07847e7767Virustotal results 31.25% Heodo
2020-01-31rep DCZ959.docdoc 31ad07da3bccaaebc18676212e40fcd30a280ae55fd101eb55e89302c9532580Virustotal results 26.98% Heodo
2020-01-31Dat 20200131 FU42224.docdoc 84d8eb2ec1e042ad4d13a86cf929126e01b6a0fc5aec0160b7f79dd5151ec355n/a Heodo
2020-01-31Dat 2020_01_31 N405.docdoc bdfaaab845be88d3e21927df912e9260f3ed52b69998a0355ae34afb005a10c7Virustotal results 20.63% Heodo
2020-01-31Rep-VS424332.docdoc 91275159f80eeb0eff909660f56290704daffd027e4b5725ef33573c925488a4Virustotal results 20.31% Heodo
2020-01-31Arc_319.docdoc 2c1c2bc7043d0a9e19f8082f74edb7fe6701df464a66a408969bd9825c11d16aVirustotal results 21.31% 
2020-01-31arc_2020_01_31.docdoc 9fb0a6fe332aeb878af094ebb838b45e25773204f45c299a2c31fa1070c7d80bn/a Heodo
2020-01-31List-2020_01_31-IRO241134.docdoc 9ab30abebfdb3619b5253d44a3e4b928ad5d7ae3a1af4c5634f3b1faa7e675a2Virustotal results 20.31% Heodo
2020-01-31Mes_20200131_69944.docdoc 1927c895365ce9eb0b850ccab2180fd7d46e42b647113981b953bd353c6edad6Virustotal results 20.31% Heodo
2020-01-31list-2020_01_31-2698298.docdoc 5e1a30103fd40640c8a5b91d5dadf5564896d808711410002020fa9f136b080eVirustotal results 20.63% Heodo
2020-01-31File_2020_01_31_VKE5943.docdoc 479acd550fee84ce07d46ca359554323d14b0874e9402267f9f6cedc7ea64065Virustotal results 20.31% Heodo
2020-01-31dat-2020_01_31-493378.docdoc a5a1cad504ed2881f3206bcc602f7e379d15cd59082cac926f2fd286257ca9can/a Heodo
2020-01-31List 2020_01_31.docdoc db5ec50aa0307b01efda63c0c839ca56003ecb0cf9e97153c79a15f8c7954de7n/a Heodo
2020-01-31INF-2020_01_31-3550935.docdoc 867bbb07e9038e3e82a5213c489f70005c917c0e459e7f6f4f2ccefe80a53701Virustotal results 38.10% 
2020-01-31inf-2020_01_31-HQ985854.docdoc 8cf8b5bd984c809a86c9c425d500393b50115233149a953678de79dca4bdc223Virustotal results 35.94% Heodo
2020-01-31doc_482101.docdoc 02d4150ccb8c0569ecd99cc1a860f5c711f1cd2ba567aa5728b830b9f1789f46Virustotal results 33.33% Heodo
2020-01-31Doc 20200131.docdoc 8c92d4ec69c3abb56aa2bbf048e479ef4129aeaf93c5425063415797f78f151an/a