URLhaus Database

You are currently viewing the URLhaus database entry for https://xcx.zhuang123.cn/wp-includes/dzRruAikJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303596
URL: https://xcx.zhuang123.cn/wp-includes/dzRruAikJ/
URL Status:Offline
Host: xcx.zhuang123.cn
Date added:2020-01-31 03:03:15 UTC
Last online:2020-04-25 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-31 03:04:02 UTC to abuse-noc{at}west[dot]cn)
Takedown time:2 months, 25 days, 11 hours, 18 minutes Bad (down since 2020-04-25 14:22:25 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01INVOICE-OHU854_830074017.docdoc 970df6100d8375af169bb259df2c7bb1ad641294e34ed57dc3ad02a38371b4c7Virustotal results 36.51%Heodo
2020-02-01invoice-OCBN51_51561419.docdoc c7f8a534675b643449abfdf573e7b23803ecce479e90653ba295ae4d5f82995eVirustotal results 36.51% Heodo
2020-02-01invoice_JLZU4_5223423.docdoc 068c0fa7ec2b72cc8c87bf99a725b7e44c8a49a5b8461358acd77d6186504229Virustotal results 35.94% Heodo
2020-02-01INVOICE_IDHK3_562210.docdoc 596840343814720213f9ad50272e76d5436f72a30674e560ba88543b854b2fabVirustotal results 37.50% Heodo
2020-01-31Inv-284_5633935.docdoc 66cf6a1cda9e240560d3dd09a638f88527ba60dc15d9d5716e63c8ad1df5e954Virustotal results 32.81% Heodo
2020-01-31Invoice 5_57694096.docdoc 3c898038b0729e908f29fc28f0b7b4032f71c1bc46d890ded09e2b435bb75256n/a 
2020-01-31Inv VOYK4_793529879.docdoc 93f30df7007372c3e96246ac6e4f6aada7422dabc2cca1dce79322aa17715aa4Virustotal results 31.75% Heodo
2020-01-31INVOICE-YEAZ69_976427627.docdoc 6f5b5a3741af81754e65b88c920cfdbfae7c14bd6b8e0200d260b0a71dbb3affVirustotal results 34.92% 
2020-01-31Invoice QWYQ83_779409426.docdoc 48aece09b58178b17b2a09cebbb26f2da0bc3e6140b65d86b642060ec00689e5Virustotal results 33.33% Heodo
2020-01-31INVOICE-CW47_415133.docdoc 2041559b24b2289ef8263b1c8335bd87424dc62061a72b4bfdd5525b98da6b54Virustotal results 28.57% Heodo
2020-01-31Inv_549_373216305.docdoc b777b2c1bf49b5a05bd8241ae61fbcfa3c3c96cd899ef9ff4215bc6121945da2Virustotal results 22.22% Heodo
2020-01-31Invoice-ZJS6_779858.docdoc 39749a5fa62f593521a2251acfa4e36b1fbd1e36cb9dc73834157fa917c51698Virustotal results 27.12% 
2020-01-31INVOICE 5_559192155.docdoc 8e0afd2fa4abbe847f9ff21eb7ac55c920eb69a98ebf7d214cd28aa32d5a5eccVirustotal results 20.31% Heodo
2020-01-31Inv UTG8809_6075851.docdoc 02d0fca16499272621f28342b9c41dfc3c6133eb9cc3d485b8334de09bc9825fVirustotal results 22.03% Heodo
2020-01-31Inv-U6549_700888172.docdoc 322bc97effba52663f35f592be159313057162f0b75287845c440a3971648cb7Virustotal results 20.31% Heodo
2020-01-31Invoice-SU41_8025891.docdoc e1fe6aa5e952e7f904ab79438277216f1af38d9073fa0f7656c8bbfec0ba6639Virustotal results 20.31% Heodo
2020-01-31Invoice-Q3_71351469.docdoc 21b6e7719a2afa773453d60937aa333af8e41f515ecf2f2f50301c235971e447n/a Heodo
2020-01-31invoice-72_89107170.docdoc 1d0e564ea6985e92ea399f37d2410b18fe208c71c35c4bca9bcfd196d44017b9Virustotal results 20.31% 
2020-01-31INVOICE_EIG7333_868252.docdoc 3787564ed34e427bb2a2d38b16eb007660f36dffcbb6a32b4f38768073b582feVirustotal results 20.31% 
2020-01-31invoice AXXK0646_409177.docdoc 605d7a3139166d8f5ef7e7c7acea745d2c208df433a07e161d991fd71275e763Virustotal results 34.92% 
2020-01-31Invoice CU85_163913.docdoc 9241cb1293c8d90d2fd0137b70ce74ba6e7d5835122b0c9a6215cfb1ce1b54c5Virustotal results 34.38% Heodo
2020-01-31Invoice-HNTQ75_3083080.docdoc 9931f06412385e83080f75415b9fba75bafafe36cb481e478b635d4dca29d0f3Virustotal results 33.33% 
2020-01-31Invoice K769_618566.docdoc 5cc9b80f9de781a2bc9717ed8ae9323422aeedca1df3e663869ed6a168f1986dVirustotal results 33.87% Heodo