URLhaus Database

You are currently viewing the URLhaus database entry for http://www.jsygxc.cn/wp-admin/SSna/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308614
URL: http://www.jsygxc.cn/wp-admin/SSna/
URL Status:Offline
Host: www.jsygxc.cn
Date added:2020-02-05 02:08:14 UTC
Last online:2020-05-01 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 02:10:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:2 months, 26 days, 20 hours, 12 minutes Bad (down since 2020-05-01 22:22:39 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07Inv-QWGG2399_6743028.docdoc da55d54edd3021ebaf41530e1ec8dd18fb5541bb09c3cc9d10c88e9da0351409Virustotal results 32.79% 
2020-02-07INVOICE_WSXJ2_42565167.docdoc 0c9034b1b23f6270ae3e19fa9bc1afa09f315b19b27878de0eecbdf6e2cc934bn/a Heodo
2020-02-06Invoice-093_175771.docdoc 128b70bdb5fbda8c46a35ba4de65203340df324bb4340fae2109dd5815acea06n/a Heodo
2020-02-06invoice-RUC11_380170439.docdoc fbccd622c1dd3d84621bbdc63975f6a57fd06bb79c310e15b469beed436acb64n/a Heodo
2020-02-06Inv_XPL0_97371932.docdoc cf97fc92739f7d431c0d391d38dfe6096c9fb8689a40a8754a5bdcfba6f97fbbn/a 
2020-02-06INVOICE_U85_316316862.docdoc 6c06954cbc088900ecf406f49cd3620cb6152c02121a754986fb65f7935bd043n/a Heodo
2020-02-06INVOICE-3874_830731215.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06Inv-N07_5624818.docdoc a22067b37f97aa4ed866b27ae8891c6af526a3b0ef093d55e638577cf66567cbn/a 
2020-02-06invoice_ULFI404_37689254.docdoc fa8b5aaa0d8bcfe54d4c7f45381fd38d18dc6a9372417b4d086e5321483353f0n/a Heodo
2020-02-06invoice-ACG4963_245227.docdoc c6a19d8526d12dc6f0c7c0510b8bb00a575ca52dad8d3aef5f4d90284a2d9877Virustotal results 25.00% Heodo
2020-02-06Invoice-HLH5_869073913.docdoc e10f7b95c27f399f5a1a28c5e94c61bc47ffb9f8bd9ab3bb562cf27be6460e88Virustotal results 26.23% Heodo
2020-02-06invoice FQ0035_83989144.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06invoice B6_7122126.docdoc 970952a0f98fcf246d5cca3fd65cc02327bf35fcd3235630b195749f0f92619dVirustotal results 22.95% Heodo
2020-02-06Invoice-5079_1452278.docdoc b0568d9ff726c394e4b6a7b7a59c6dcccfff57c4d618bb531c30dc3ffa5aaeedn/a Heodo
2020-02-06Inv M3899_068256160.docdoc dfdc0cdf13e57057b4f865048a2ae7a01a553397aa6faa455e773fa0637ca68fVirustotal results 23.73% 
2020-02-06Invoice-CB5_175545230.docdoc a71f70e5c9147e91776353601d4c7ddf221e1776266686d334717a70d113fe31Virustotal results 22.58% Heodo
2020-02-06invoice_D7990_2554949.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06Invoice UZC68_624349289.docdoc 4a620a4453c5b138b1c90c5bb3db067135faef7ad7106666379edaa77f38ae06n/a Heodo
2020-02-06invoice-KUNY10_35442194.docdoc 90250acf44f763164182f91d1d9e734ea442e491965e1c3883ed40fea09f0d2fVirustotal results 32.79% Heodo
2020-02-06INVOICE-ZC5_8350761.docdoc c7b6f46f5a55f557c829d3a1e6d171b7fc2577517bd72b3219b805304f56a2fdVirustotal results 33.33% 
2020-02-06invoice_VZ5_190338.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05Inv W0_26424263.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05invoice_NC439_824096813.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05invoice_RYD3979_760440.docdoc 9a6d2baf1a6f63a692b3584aecb501ab9d2c4cf6cc5e97ed5390454ec60bc466Virustotal results 26.23% Heodo
2020-02-05invoice_HK4_0104219.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05INVOICE-P97_8260638.docdoc 63d4871b55ab3111a178e22deccd794a6586ae79a9ca7144c7097773b2121730Virustotal results 26.23% Heodo
2020-02-05Invoice ULKP5_234732.docdoc 80ff1f7758139fb61d82afe12894afc778068701ba7fc6acc78f1e05b8e6d90bVirustotal results 26.23% Heodo
2020-02-05INVOICE-9016_992679.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05INVOICE-TVR510_789782.docdoc 28d1b238f050e82f7e6bcc571b0ece1a23309e7cf54fd2eb77d1d79a021fbd8fVirustotal results 27.12% 
2020-02-05invoice-NBU098_3431026.docdoc a2193d72f5be38cd1689028f15e885dafd9baef0923a1c1e761c88b8fd3e5ed3Virustotal results 26.67% Heodo
2020-02-05invoice-PPT6402_061958.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05invoice_04_298206823.docdoc 9c0d8eb2c0e899f1f31e9de7017aaff6d70980005e812ac41b19aca4a6bd6514Virustotal results 26.23% Heodo
2020-02-05Inv_WG6772_2256035.docdoc 52950a710af26f233ca1d8c57b23f9cd3d0da7046cc64f13467497b06b01b85eVirustotal results 33.33% Heodo
2020-02-05INVOICE-HDPP55_88093971.docdoc d753eaf7b22aea01dd44dfba5b9fc26ebb5677f4a713b4afa69d8c34efe836f0Virustotal results 33.33% Heodo
2020-02-05Invoice-VKHZ7_957111053.docdoc 471942cfd9aa93923bc0f054e64201217913ae24a3e192919207202918c628fcVirustotal results 32.26% Heodo
2020-02-05invoice FZGJ2652_521265.docdoc 7f66dc4cd5e6ca9fcf2c97fa1fae7983116a973390e5140205bb26e8d60136e2Virustotal results 34.38%