URLhaus Database

You are currently viewing the URLhaus database entry for http://blog.50cms.com/wp-admin/azf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308788
URL: http://blog.50cms.com/wp-admin/azf/
URL Status:Offline
Host: blog.50cms.com
Date added:2020-02-05 07:57:26 UTC
Last online:2020-02-14 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 07:58:02 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:9 days, 1 hours, 0 minutes Bad (down since 2020-02-14 08:58:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-12invoice_5739_450363.docdoc 7b096880244002e5c21c2579727f2138ef00d9c7c4188f688d2ad8fe7d36efb8n/a 
2020-02-07invoice_5739_450363.docdoc 8cb9e079003dfdc43da6213114104827f41c17617a82671f6f03d2896772ba9fVirustotal results 22.95% Heodo
2020-02-07Inv_83_89144283.docdoc 87cddb2b6d7ac63adb0e2d442b7cf006247f8eb8f7e7f7518c9f7524a9ec5fdcn/a 
2020-02-07Invoice-3616_009542.docdoc da55d54edd3021ebaf41530e1ec8dd18fb5541bb09c3cc9d10c88e9da0351409Virustotal results 32.79% 
2020-02-07invoice 26_121474.docdoc fabe5daadc59a858e5152921d00a9134c5f3202570daf8fa151f214455e84879Virustotal results 30.65% Heodo
2020-02-06Inv_JZ130_4317420.docdoc b45f99f3efe5bf82ee6cdee7f80ba7bbfa39f80c0973746b43efa2779a69b8d6Virustotal results 27.87% 
2020-02-06Inv_72_24834618.docdoc 0d52884323396c99de2994a867ebe7ccb325a7a33a6ae3317f4290517232a3edVirustotal results 29.03% Heodo
2020-02-06Invoice-4_006120.docdoc 4a24444820e9cbd0c73e0d97f291e4679d283f5c6fd44db547c58a37d62b4b83Virustotal results 29.03% Heodo
2020-02-06invoice_J8_14929622.docdoc cf97fc92739f7d431c0d391d38dfe6096c9fb8689a40a8754a5bdcfba6f97fbbn/a 
2020-02-06invoice-CAF5_8065734.docdoc 6c06954cbc088900ecf406f49cd3620cb6152c02121a754986fb65f7935bd043n/a Heodo
2020-02-06Inv_TIN147_552373781.docdoc 08a17a2ca774e5d63d00d6347ab8569354e6fc33b9e65cd55db64f088125e77fn/a Heodo
2020-02-06INVOICE-KF02_563635.docdoc a6f83c36cfcb51c3f166faff124cada228ef05461001847944061e18a897c01bVirustotal results 27.42% 
2020-02-06Invoice-26_29605014.docdoc 81fae48623d822ab3081546ad2888a2ecb9c1c93e996888dd154be91b9d8ff74n/a 
2020-02-06Inv_KG6695_11911992.docdoc 515c3515f3728002f957e469f6d30be479f3db347968856134e1f0287ad0438eVirustotal results 24.19% Heodo
2020-02-06invoice-RWS4128_09311352.docdoc d8a98e712d6775091bbcdbe1e2b1ed30135d7fcb59a9ec4ce71bd80823438c5aVirustotal results 23.33% 
2020-02-06invoice_BIC78_49096405.docdoc b0568d9ff726c394e4b6a7b7a59c6dcccfff57c4d618bb531c30dc3ffa5aaeedn/a Heodo
2020-02-06Invoice_6_4412824.docdoc 67617db60beb8c4cce54db289e3d3a8406049516de95ccc8940b0d1735caa144Virustotal results 20.97% Heodo
2020-02-06invoice_NT9_728012.docdoc fd7c8c6cf457d1d127ee24d40ea990ccae1f8f8e8c648e61c760124a04dd4941Virustotal results 22.95% Heodo
2020-02-06INVOICE-LXZ4_924068637.docdoc 5f1d9dff136888c71d8b157e91821d73a94faa92af1bdc04912d223b7b1de32dVirustotal results 31.67% Heodo
2020-02-06Invoice_NH5_57188785.docdoc a5fc11e008c844121e447116ba31e7430ab4bc38350cfd1b6bd52fd322c059f0Virustotal results 32.79% 
2020-02-06Inv_PE07_919636988.docdoc 9eca08bea00fec73f8bdc769abf28f857d39de7d922c4d0dfd4017dc5981d2b0Virustotal results 33.33% Heodo
2020-02-06INVOICE-4_4050010.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05Invoice QHGK41_503779769.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05Invoice_N6789_660903.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05Inv_8245_89390912.docdoc 4152d52f1411482170163f5c1a548319cf7bf6b6e3b95a2d5dce87a21ef76708Virustotal results 26.23% 
2020-02-05invoice S63_325088.docdoc a2de78a3a39c2c5d3d3c617de7f83a6ee2ba59eeb411de1095a208d4b21ecffeVirustotal results 26.23% Heodo
2020-02-05invoice_C49_806759.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05invoice_T055_21816833.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05invoice-L4495_8375619.docdoc 28d1b238f050e82f7e6bcc571b0ece1a23309e7cf54fd2eb77d1d79a021fbd8fVirustotal results 27.12% 
2020-02-05Invoice-9601_6852498.docdoc a2193d72f5be38cd1689028f15e885dafd9baef0923a1c1e761c88b8fd3e5ed3Virustotal results 26.67% Heodo
2020-02-05Inv-XS1_095708.docdoc dc0402b2e8b444ac6695dd0686b697822b5c339fb556f63aaf4cb4dce9354572Virustotal results 27.12% Heodo
2020-02-05invoice-GW748_25567907.docdoc e30921665ac8c14a0f81843c3e4268bc7a75a6add0e902ff63be178a989e342cn/a Heodo