URLhaus Database

You are currently viewing the URLhaus database entry for http://www.huahuahui.top/wp-admin/3b0x-ya-794868/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308445
URL: http://www.huahuahui.top/wp-admin/3b0x-ya-794868/
URL Status:Offline
Host: www.huahuahui.top
Date added:2020-02-04 22:08:06 UTC
Last online:2020-02-15 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 22:10:04 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:10 days, 11 hours, 13 minutes Bad (down since 2020-02-15 09:23:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06Invoice_R55_2394821.docdoc ab391e8e835eadc53be340b46e52114f74b09bc3c9a6aab4dbb25e4cebd4256aVirustotal results 29.03% 
2020-02-06Invoice-Q1347_45602074.docdoc cf97fc92739f7d431c0d391d38dfe6096c9fb8689a40a8754a5bdcfba6f97fbbn/a 
2020-02-06INVOICE_ZDIA324_245845208.docdoc 6c06954cbc088900ecf406f49cd3620cb6152c02121a754986fb65f7935bd043n/a Heodo
2020-02-06Invoice-QK73_903120905.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06Invoice-SGE3_9769568.docdoc 72cf0e1c89a577b94531a7723c3d176dfd37839c0b19bc7878c49945f7dd7339n/a Heodo
2020-02-06Invoice WJXB9_9899625.docdoc 81fae48623d822ab3081546ad2888a2ecb9c1c93e996888dd154be91b9d8ff74n/a 
2020-02-06Inv-BW9_33476717.docdoc f529e7394604d172959df3fb126f30946377ffcbed5a186bee86ce1ae13a2902Virustotal results 24.59% Heodo
2020-02-06INVOICE-K1_784738421.docdoc e10f7b95c27f399f5a1a28c5e94c61bc47ffb9f8bd9ab3bb562cf27be6460e88Virustotal results 26.23% Heodo
2020-02-06INVOICE-YS475_442380650.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06invoice MMX1_62146393.docdoc 1ffc37048962c0a22202bc9de2da7dc6a958458986126b58248ab622cd695f7dVirustotal results 21.67% Heodo
2020-02-06invoice_Z707_76594739.docdoc b0568d9ff726c394e4b6a7b7a59c6dcccfff57c4d618bb531c30dc3ffa5aaeedn/a Heodo
2020-02-06Inv-EG7657_703784.docdoc c137f96ad20933f15cbd33dd13a59de4aa1b0e84ba2d9ffeca8835eb21d271e8n/a Heodo
2020-02-06invoice-QLC25_48089123.docdoc fd7c8c6cf457d1d127ee24d40ea990ccae1f8f8e8c648e61c760124a04dd4941Virustotal results 22.95% Heodo
2020-02-06INVOICE FH7_380221.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06INVOICE-VVVS50_01788773.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06Invoice-0_315641.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06INVOICE_UZK5118_865937.docdoc f64c7b18189347af96b402b6f3cb3294d4dbbc7cad63748805727ac4d2a83997Virustotal results 32.79% Heodo
2020-02-06Invoice YUPR10_767226020.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05INVOICE-Q2995_348863.docdoc 23bfb58c53002a4c03a4931e057316564e8ccab64975f93e2d66ceca6c73f7afn/a Heodo
2020-02-05Invoice ZL06_993466339.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Inv_ZL50_03946637.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05Inv_T1808_817465848.docdoc 9a6d2baf1a6f63a692b3584aecb501ab9d2c4cf6cc5e97ed5390454ec60bc466n/a Heodo
2020-02-05Invoice-I8598_0392688.docdoc a2de78a3a39c2c5d3d3c617de7f83a6ee2ba59eeb411de1095a208d4b21ecffen/a Heodo
2020-02-05Invoice GBAC534_0900607.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05Invoice_TF6_7772912.docdoc edf908e69ca6bddb96275159691eac00670176efad33829eff4a051b643da24aVirustotal results 27.12% Heodo
2020-02-05Inv M6435_1620777.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05Inv-YBEX267_2855991.docdoc 28d1b238f050e82f7e6bcc571b0ece1a23309e7cf54fd2eb77d1d79a021fbd8fVirustotal results 27.12% 
2020-02-05Inv DH6640_2632135.docdoc 25e1ccfdcb1ea888e655bf5afe9b0fb8211b0bfc8478c1b9128a6301b24109e8Virustotal results 26.67% Heodo
2020-02-05invoice-H994_038876.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05INVOICE-XCCU0_726726.docdoc 6e4f1e55d03c7f87e1640ee1dba3bbbf7f3d01655098885ef1db6e84a5947292Virustotal results 27.12% Heodo
2020-02-05INVOICE_847_090638.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05Inv_21_660360.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05invoice-QL75_49201255.docdoc b376816250d05683e509c36b70c10c82f78198b2daef4ff81ff5ff8515932429Virustotal results 33.33% Heodo
2020-02-05invoice HD6988_18080948.docdoc 50ed2de7492f944d8a34c9d454c3757a58d26078f91dd5de90ac595eb6279dc7Virustotal results 42.86% Heodo
2020-02-05Invoice TB5_791233867.docdoc 4887e700c4997ddaab9733c0dc0696a27e93eb2c02e2839119c077c2b92fd2d6Virustotal results 34.92% 
2020-02-05invoice-E539_766118010.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04Inv-918_219356476.docdoc d0787010e140c3d4c833ba70fcd573e0eb42df65c29756cf65d0239b4374f915Virustotal results 33.33% Heodo
2020-02-04Inv_VUKC0_2110054.docdoc a1c9943f671edf2b128462f1b6bb5d823356d2fca0b7ced2fdf61b1fe049d69aVirustotal results 33.33% Heodo