URLhaus Database

You are currently viewing the URLhaus database entry for http://www.hzylqx.cn/wp-admin/gozi8uft-jmqa-956/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307636
URL: http://www.hzylqx.cn/wp-admin/gozi8uft-jmqa-956/
URL Status:Offline
Host: www.hzylqx.cn
Date added:2020-02-04 09:15:42 UTC
Last online:2020-02-21 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 09:16:02 UTC to ipas{at}cnnic[dot]cn)
Takedown time:17 days, 3 hours, 24 minutes Bad (down since 2020-02-21 12:40:59 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06invoice-TL095_734517041.docdoc cd461439b62522a7397cb8f88256619f296e48a4226bc9339ad573dbdcad680aVirustotal results 22.58% Heodo
2020-02-06Inv-KVPX04_732134.docdoc a71f70e5c9147e91776353601d4c7ddf221e1776266686d334717a70d113fe31Virustotal results 22.58% Heodo
2020-02-06INVOICE_LMU18_15736326.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06INVOICE KCYC20_1957523.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06Inv_S8093_7025557.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06INVOICE EG233_3261456.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997n/a Heodo
2020-02-06Invoice_EO9_5187061.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05INVOICE_RD3_61215556.docdoc 23bfb58c53002a4c03a4931e057316564e8ccab64975f93e2d66ceca6c73f7afn/a Heodo
2020-02-05Invoice-UDBW95_9725325.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Invoice VXX69_0477847.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05INVOICE SSE15_569085.docdoc 4152d52f1411482170163f5c1a548319cf7bf6b6e3b95a2d5dce87a21ef76708n/a 
2020-02-05INVOICE-TI42_69664989.docdoc a2de78a3a39c2c5d3d3c617de7f83a6ee2ba59eeb411de1095a208d4b21ecffeVirustotal results 26.23% Heodo
2020-02-05INVOICE 686_17861943.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcaVirustotal results 26.23% Heodo
2020-02-05Invoice-O118_63405786.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05invoice-SYKS691_589885095.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 29.51% Heodo
2020-02-05INVOICE-Y2_67721867.docdoc 5829a75fd529c15f927a9ac98d3edae92ad9b51f151e90937b549a2778cdd9bcVirustotal results 28.33% 
2020-02-05Invoice MKR79_169280.docdoc 28d1b238f050e82f7e6bcc571b0ece1a23309e7cf54fd2eb77d1d79a021fbd8fVirustotal results 27.12% 
2020-02-05INVOICE-QQVD48_924968.docdoc 25e1ccfdcb1ea888e655bf5afe9b0fb8211b0bfc8478c1b9128a6301b24109e8Virustotal results 26.67% Heodo
2020-02-05Invoice YCVM319_023827.docdoc ee932045a6cc0928256f9fd9792fb685acd23e47fc4147eb4795a6e009be1942Virustotal results 27.12% Heodo
2020-02-05Inv_MWJ7176_9024200.docdoc fa5927f2181dbeaef9cab75616169a02fe02b41df92e598cabad444619c3befcVirustotal results 26.23% Heodo
2020-02-05INVOICE-BACZ950_953829737.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05Invoice_RQJT39_280457926.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05Inv-P5_036172.docdoc 251634753472a0f5fffce161c8c997b7ff91e76ec48b414e29737b4dc5b747e8Virustotal results 32.26% 
2020-02-05Invoice_701_784202.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 41.27% Heodo
2020-02-05invoice C58_968912.docdoc 25d98e7b0341be2da85f8fbbe279863673a1b0744c9773c8f6bcaa0c0666c935Virustotal results 34.92% Heodo
2020-02-05INVOICE-I73_1795027.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04Invoice VH5012_45655963.docdoc d0787010e140c3d4c833ba70fcd573e0eb42df65c29756cf65d0239b4374f915Virustotal results 33.33% Heodo
2020-02-04invoice ORL3277_8396184.docdoc 52950a710af26f233ca1d8c57b23f9cd3d0da7046cc64f13467497b06b01b85eVirustotal results 33.33% Heodo
2020-02-04invoice_O056_95259686.docdoc b36bb787097054921d1c91c8f9e839df7b8452550425a9f7df8bad8460bf085bVirustotal results 33.87% Heodo
2020-02-04Inv-DA7142_023012.docdoc e9289bd5ee4b42bfb14ef6ea40e133e5d9aa64ccbc59e99487f875cf21186131Virustotal results 32.79% Heodo
2020-02-04Invoice AIM61_394696.docdoc defe55c9dc26d0ae8ff07ac7bfa3e4b03c672b69761fa507e15b5715ead2abc4Virustotal results 33.87% Heodo
2020-02-04invoice-GSE705_138192.docdoc b4c3990e73035881f982534ee5ccc3a30f80b58c625e28b6f68067c223589fc1Virustotal results 31.75% Heodo
2020-02-04Inv JNAQ100_55229244.docdoc 40c57139f9fe475f5e06542c48aac3476cd943f3530f73ef44a60db380bf9e04Virustotal results 38.10% Heodo
2020-02-04Invoice-F3053_60772391.docdoc 904f34e3a638e5d981f17dc0728844c41378c8b8ee1f9bb7e85b614af0478739Virustotal results 39.34% Heodo
2020-02-04INVOICE FTU10_269648.docdoc b38620f90ec6f200c3c194fb6ec3444c55f50151f4a47cd6ff0eba0bc12a03can/a Heodo
2020-02-04invoice 971_851447.docdoc 32205c6e3940af055c6164bb249b544737778db9e0ee965daf226efedfe861d7Virustotal results 37.70% Heodo
2020-02-04Invoice-BPNR3356_8823583.docdoc c6f67345d51de31d968f542885d815a518e46ae16c2629694893cceceb18ff3cn/a Heodo
2020-02-04Invoice-FEWX2496_099315.docdoc 8e66d9957e16b357616a30285cc04951088836af1778c63ca72ed2f7f0b48f41Virustotal results 33.87% Heodo
2020-02-04Inv Z9_623175.docdoc afe31791fd85a56e44bdc5261af1e3c237392614029d439e9421a09d348bc389Virustotal results 34.92% 
2020-02-04INVOICE-MPDT461_1357819.docdoc 8dabecf19c1fe768cb300b5a9c29af08b8f8f3967e8883c10b73d1f81bc26630Virustotal results 33.87% Heodo