URLhaus Database

You are currently viewing the URLhaus database entry for https://zcb.hsdgk.cn/wp-includes/5MIpqh-n2CEWVlQKS-box/close-warehouse/8jfzi57qs1o91-wts684/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307955
URL: https://zcb.hsdgk.cn/wp-includes/5MIpqh-n2CEWVlQKS-box/close-warehouse/8jfzi57qs1o91-wts684/
URL Status:Offline
Host: zcb.hsdgk.cn
Date added:2020-02-04 11:34:16 UTC
Last online:2020-04-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 11:36:02 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:2 months, 24 days, 21 hours, 5 minutes Bad (down since 2020-04-29 08:41:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05list_2020_02_05_2082.docdoc 593ef299e4bcf8e836dd1522653ec33230104646f6e8c376e9c4a9957ca5ca3bVirustotal results 24.59% 
2020-02-05DAT-PJ9133.docdoc f4dbeab20387f793a3dd0b39d717b27c6787e02951aa4ef7cfeb0d156b75697cVirustotal results 25.00% 
2020-02-05rep TL30264.rtfdoc ab556aef3f7baf74127e682541cd5bb674af38a62c4c1f89ff43f09388894af2Virustotal results 25.00% Heodo
2020-02-05Doc_2020_02_05.docdoc e017e89646b0d091bc67504f4318ea078b5a279edd898f418ff735e40c432e28Virustotal results 25.00% Heodo
2020-02-05MES 2020_02_05 UB095.rtfdoc dbbe0d7dded778f388849d7ce83487c413292de6f83d4d8286e7b13bd8f5b981Virustotal results 24.19% 
2020-02-05DAT-2020_02_05-790560.docdoc 6552a6b01beec690c8ebf79b58d1397c3e9449e2d59c4f17b1d0e24415fdc05fVirustotal results 24.19% Heodo
2020-02-05mes_20200205_4349.rtfdoc 544e09d5a19e01f91c458d3b56a2dd3aa5d6623ea0857a3a56662454bd417dedn/a 
2020-02-05Mes_AJ419.docmdoc 07fe2fb2cf6e99bc0fee819b38bda8d4c0e8f7d18f8faa9775463041c71ba5faVirustotal results 24.59% Heodo
2020-02-05mes-2020_02_05-19944.rtfdocx 3002799efe2f36491f41e0c5e350a6c6ae06bdc8fbef3c1ddf753c6c2e206736n/a 
2020-02-05MES_2020_02_05_0707306.docmdocx 87b1933c9a37e955daf97fd9640da17cde0f579c30a655b8d1af0fcf8ecfb7cfVirustotal results 36.51% Heodo
2020-02-05Arc 2020_02_05 FOA6298.docdoc e96b3b96851ad8f49fa155f44b5dad11bedded8a6c96898fa814e872822f3eecVirustotal results 35.48% Heodo
2020-02-05REP_20200205_7615.docdoc a464fbbd0fd6eb2e09bb5c04dd46379d3cf1c4f67eeb3f4e9f0b9f7896a2192fn/a Heodo
2020-02-05file_20200205_AE5699.docmdocx ab25cd8065a0df8608fcd69bd29689ae7657b263b8290a459052ff0cfcac3951Virustotal results 30.65% Heodo
2020-02-05Dat 2020_02_05 774364.docdoc 87bf983815a7bdfc6fda722fa02b1adef0c064fc60a443faed053662ba92a74fVirustotal results 32.20% Heodo
2020-02-04doc_2020_02_05_6034488.docmdocx f2d5330b5aa423a1c21c6f960154447080fb0b6a7747307519ce8d57a310d1a0Virustotal results 29.69% Heodo
2020-02-04doc_20200205_D864.rtfdocx f189891eacbacefcd510376ad44060a48962b25cfabcdd82b7845acdb512bab8n/a 
2020-02-04arc-X29443.docmdocx ec4146a69e81f690514da6199f759c184964dbe031f6ca7850b4af5d0d365150Virustotal results 36.51% 
2020-02-04File_2020_02_04_5921.docmdocx cf00a0e13bdc326ecf08bd0238ee35c3600642133c7f84f69b0434aa63bfa291Virustotal results 32.81% Heodo
2020-02-04INF-20200204-D00881.docdoc 226e3d9397801a0c20fc12e65373887d6b8e32d5d47ea818a8b891be4513e330Virustotal results 33.87% Heodo
2020-02-04dat-20200204-ICN82623.docdoc b47eba67f3bdcaadc7e9116053d4a250ae71ce6031b8ae4c30bc22459a57ba0dVirustotal results 31.75% Heodo
2020-02-04file-20200204-3960.docmdocx 597a313c1d55cc65b461fb9ff7e086dac74ae798f9e9641b03420282e54dc514Virustotal results 37.10% 
2020-02-04file-JU126.docmdocx 12edeef0065331ab3b8644b9c14a1267b266a96e33ad20e9055315c454b750a4Virustotal results 37.10% Heodo
2020-02-04rep 2020_02_04 X423.docdoc a22639097a957b8debdfb4ff182eb2b6a288368b09b8427853ed91346b687737Virustotal results 35.48% 
2020-02-04LIST 20200204.docmdocx 71504ffb2ac7323b2da494aabf013190544db3e4230b363b639d68878aaf77dcVirustotal results 36.51% Heodo
2020-02-04File-20200204-XN891075.docmdocx b71394268acf3acca757143450d5ccc9030bb60cd3e5e9e3245f81fa1b63e757n/a 
2020-02-04Arc_V660.rtfdocx 66fbfabc52fac899652f0e490be589ec3d3c5d3cf233ca24171ab6d8ff55a50dVirustotal results 34.92% Heodo
2020-02-04File-20200204-37107.docdoc 3789c941e20a1afaa8508bb9bc699447586bb117bb98732f0c932d4638cd03b2n/a