URLhaus Database

You are currently viewing the URLhaus database entry for http://www.gjhnb666.com/wp-includes/AR1Vkxb_I8YTLEagz0YOjL_sector/interior_9b6pj_dF7TXqtl/CdsJJR_odvfkLkqqyfMvz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:306690
URL: http://www.gjhnb666.com/wp-includes/AR1Vkxb_I8YTLEagz0YOjL_sector/interior_9b6pj_dF7TXqtl/CdsJJR_odvfkLkqqyfMvz/
URL Status:Offline
Host: www.gjhnb666.com
Date added:2020-02-03 11:20:37 UTC
Last online:2020-03-11 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-03 11:22:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 month, 6 days, 22 hours, 8 minutes Bad (down since 2020-03-11 09:30:24 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05Oferta 02052020.docmdoc 5e0c254fb5a3039e5963ad8d508a5f290cb14e8469b8d3ff0505511eacce9c67Virustotal results 25.42% Heodo
2020-02-05CONTRAT T34247.rtfdoc ef74202276aee43dca3327e29e3f7444583c342da59aa5f7ef01e6be1dccfeb6Virustotal results 25.00% Heodo
2020-02-05oferta O36990179 3570405699.docdoc 46529e473f1dc76c028e9d23e9b51ab7dca3b2f86cab1cf88db1fc504aca4705Virustotal results 25.86% Heodo
2020-02-05Factura_02_05_2020 C0591378.docmdoc bd69c2f2ba41eeccc2c9fb6372f3a09a5921e0adbc6eea30efca31833098f475Virustotal results 24.59% 
2020-02-05fct E482072464355.rtfdoc a9d9d090c46571aac592ac8ab969a6c1f70c729927d1c863b3ed327c286b3b5dVirustotal results 23.33% Heodo
2020-02-05FACTURA-02_05_2020-F86931.docdoc 3c0292963e5af1dfc8aa14b1b0408c3d3e0873fde4dd75962bd380b5aa67eb36Virustotal results 34.92% 
2020-02-05Factura 02_05_2020 3H2077.rtfdocx e96b3b96851ad8f49fa155f44b5dad11bedded8a6c96898fa814e872822f3eecVirustotal results 35.48% Heodo
2020-02-05factura 694n42.rtfdocx dcdcefae226e1eccadad30728bc5d5a86fcc042676c0e98078e62ccd82b564d2Virustotal results 33.87% Heodo
2020-02-05Factura 580o534non.rtfdocx ab25cd8065a0df8608fcd69bd29689ae7657b263b8290a459052ff0cfcac3951Virustotal results 30.65% Heodo
2020-02-05Factura-KC21826134.rtfdocx 0eeaeab309fee32e71f3c9e221e6583285eac868bd06ee8bd594d06621c97e16Virustotal results 30.65% Heodo
2020-02-04FCT-02_05_2020 7B568676.rtfdocx 6464ea34b63546f7d2cdcb780b772b1250731bd38c105c2feb70e0928d49b1abVirustotal results 32.20% 
2020-02-04fct_60p987mon542.docdoc 3e807f7cb48c71df4ce8ba0a0024238ec14712f1e68e7d0c959ab376f2fbd524Virustotal results 32.76% Heodo
2020-02-04fct-EE97362744643 756912370.docdoc 03657e4b0103d718978b4736846da1ebdd18f8ba892ff4709eabbae4d7f14c10Virustotal results 32.81% Heodo
2020-02-04factura 32482930815.rtfdocx 226e3d9397801a0c20fc12e65373887d6b8e32d5d47ea818a8b891be4513e330Virustotal results 33.87% Heodo
2020-02-04fct oppn9o.docdoc b652230d0ab5eba2fd05573b7ef10013f6563c1bb9f64d5f5106b15cc8a5ade7Virustotal results 31.75% Heodo
2020-02-04fct_9891361.rtfdocx 609b7ca66900e1a185fdd6dd43b220fa5bdae7fa5ac96d0c04e8b821f292cd7eVirustotal results 35.94% 
2020-02-04FACT_02042020.docdoc df93d5db4e5f605a05698932442d24a5deda32e2947b200762e8ab6572afe007Virustotal results 35.29% 
2020-02-04factura_02_04_2020-6749829841422.rtfdocx ffe59b190e1aea7c975d401c6efc7427e35dd63718af5a25cd858b1f8c4090eeVirustotal results 36.51% Heodo
2020-02-04Factura 02042020.docdoc 71504ffb2ac7323b2da494aabf013190544db3e4230b363b639d68878aaf77dcVirustotal results 36.51% Heodo
2020-02-04facturacion_63484559567_2136901.rtfdocx e0979d62d8759cb55806f491b1f2cfd2b63b1d018449f8f6c3d9e41044852152Virustotal results 35.48% Heodo
2020-02-04FACT 7310.docmdocx 3e2e9a5442d6c6826dad3dd23433234eb8d095c3ee6f0cde53e92e675e6f8822Virustotal results 36.67% Heodo
2020-02-04fct-02042020.docmdocx cf2fa78d90fcfab9100f273c1e9ffe890840d22f6a0dad51aafde1684d179222Virustotal results 34.92% 
2020-02-04FCT 8843.docdoc 14caedac45df173fa759640f3d19efcd330e4ba5c3a8f2d6751dab8556b6fa77Virustotal results 34.92% Heodo
2020-02-04facturacion_02_04_2020-C6698750771.docmdocx 12d4d22023747c7d29ac36363975fc476b7cbb77e0ee34ebca12b17e2e0109b7Virustotal results 34.92% 
2020-02-04FACT qmm29opn14q.docmdocx 28f6267574c80900ddd8dd34a0ea0526fa3b3657f789c233556b69472c75ad2fVirustotal results 31.67% Heodo
2020-02-04FACTURA 02_04_2020-5GB38059189114.docdoc 3df4c20b912377bb69db29aaf085b27d9eadd660678c6c0d113a502c36257532Virustotal results 33.33% Heodo
2020-02-04Factura 232096_56865195317.docdoc 7769ae1cce4e29c3e8bd982600d46a07804c1f66a2772bf00ea100aa24c227baVirustotal results 40.68% Heodo
2020-02-04FACTURA 1789635914.docdoc c1930d674cd5a16025ce8267497e1c2f5004cced1042af0dc4106caadb5db41aVirustotal results 38.71% Heodo
2020-02-04FACT_8551.docdoc 0c5326e304b5b23196b990d4ba1000e7a34150acbfa3b3cd8aaa35a12f124e26Virustotal results 38.10% Heodo
2020-02-04FACT 02042020.docdoc 05ead2ea8d0ec1dfd4f5b491661af731b41e275c0471f7f733cd097b544413ddVirustotal results 38.10% Heodo
2020-02-04Factura-C90097-1650.docdoc b5bdbfe46cbe25168c809c0da1cd3018bef7e7821ead2808e7b22f4a01d76a34Virustotal results 38.10% 
2020-02-04fct_02042020.docdoc 133d966b980eb291760a47d0e9344a2900a4917c5983c098292115d55f6c8bc4Virustotal results 36.51% Heodo
2020-02-04factura-02042020.docdoc aa3931cb2f3ab736b14ffab1da3e306231e5ca42842da644913c4ba7ed5730b2Virustotal results 35.48% 
2020-02-04FACT_24819.docdoc 96ca41fe85593ec2adee71cbe9ddeae3c084689d3bd049ba0b3a548895583c11Virustotal results 33.87% Heodo
2020-02-03factura_934981o.docdoc f1ca3ac8b29ff318670eb9fec48430c20bfd5c159a0e78ea322110f711f0b3caVirustotal results 32.26% Heodo
2020-02-03Factura-434046581.docdoc 1122defb13e730aa0be39b9b0e30c0e10932dead24efb3053847c47b1fe0a38bVirustotal results 32.26% Heodo
2020-02-03FCT 54402110437.docdoc 4fe0e17a6ac7d17121f601c54ee859631883631e15befadd1d1a3254b792983cVirustotal results 31.75% 
2020-02-03FACT_SB76992979.docdoc 41eb5864c5fc90cd72e8d963dbde4bdb3596211365801c454e35c43a62f99d86Virustotal results 31.75% Heodo
2020-02-03FCT_02032020.docdoc 512b2b0415df7c51ee775773ba39d89e89c37b739b4d2479db8ac4b4af3d23fdVirustotal results 31.75% Heodo
2020-02-03FACTURA-01209220.docdoc b5df0d05aec91b3e5543414a3dea4e39757c4c16a3ba96398771d33bd7484bebVirustotal results 31.75% Heodo
2020-02-03factura-79122013869.docdoc 9681ccc3cf58b12d30d0c4be40f0de86eaa804c3f72922a4e654956134e1b831Virustotal results 31.75% Heodo
2020-02-03factura 02032020.docdoc 2dcadaf9703bea2cb80e65f8c66d26d25f03055e60a4335e8d6b885ef19f1ac9Virustotal results 31.75% Heodo
2020-02-03Factura-02_03_2020_4G1070980.docdoc 51057661187625ff898c280a03f881bb18487319fa830f5cc65678a8e0092589Virustotal results 28.12% Heodo
2020-02-03facturacion_Q36359.docdoc 6f1b024e7c96da7fe1a7c676accf6389ba787000e8824827d9c8b857eb1f2d09Virustotal results 28.57% Heodo
2020-02-03FCT_4724370885.docdoc 1ed54620b27cd872b7110c4c93c0f9bc5838419fa980138fc9042bea2d2d08e0Virustotal results 30.65% Heodo
2020-02-03facturacion_6A8814.docdoc 04c71248d275d113a2bf8b63c91e522a80a9d12f0f286af5eff747ef1c11e06bVirustotal results 30.00% Heodo
2020-02-03Factura_02_03_2020-3FD932194273371.docdoc 213da00a6a527cd2f83d407699c4aff55bfac762fad3ecabbf8c519223682228n/a Heodo