URLhaus Database

You are currently viewing the URLhaus database entry for http://wqapp.50cms.com/addons/xrxUPWg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:309497
URL: http://wqapp.50cms.com/addons/xrxUPWg/
URL Status:Offline
Host: wqapp.50cms.com
Date added:2020-02-05 23:18:02 UTC
Last online:2020-02-14 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-05 23:18:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:8 days, 9 hours, 41 minutes Bad (down since 2020-02-14 08:59:24 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-12t0fe2xapc609.exeexe 4245c8c970490064e18d07a0f1f5d22588cb9676a9e31c090fccd39514053fe6n/a 
2020-02-09t0fe2xapc609.exeexe 88364e36f088d96b1b80bb321a58168b04f8817f76daf39333209e3ccde3d3edn/a 
2020-02-086i0201271.exeexe eaec0a89c28d1f441932b07d123139425a15645c3266e76818a6554f32221f38n/a 
2020-02-07adepugmjen664888.exeexe 724dd5dad3c8c253663db43557712ac030b8228f9602030ff21ec61a5f9cb198Virustotal results 26.76%
2020-02-07ee76812.exeexe 26b9a92ff0c0fee2914312f857cc34db251597bd109cec2e4e587eb3f6e27020Virustotal results 13.89% 
2020-02-07t7jiv045384420.exeexe 674536c46366891235134e45ceba7df06f23f5be990557bc9c532637746e999bVirustotal results 16.67% 
2020-02-07bhqjjd83252416.exeexe 15fdbc77e9921a59c4e57fd420e148c72f2d78d8d726b5f0b2c5c197ddd97352n/a 
2020-02-07ug62228444.exeexe 7bf3de03dbf613a602da42338a50d50cb60086ce4bd82c9fc4a21b827ab6d2ffVirustotal results 12.50% 
2020-02-07kr5.exeexe b5017e13b2f5c2312f71a4389c23d3f9a4dd8ae17685ec370b14721371370120Virustotal results 11.43% 
2020-02-0752mv2w904465301.exeexe 591cf4c1c69ceb50241d570fdf6e820aae47d8d58b9da8a53b25db3f052b9d5en/a 
2020-02-07rps53t0dua7641.exeexe b6e21823ee31c32b8ba81ef3da9cf2baaad3b9553d31959fb4bd200775ee64a5Virustotal results 12.33% 
2020-02-072x73rtyn0.exeexe d9d1eda71f2a1ed215fca587c0f9597ffa26af3e7cc27d1b93817b12a89132b2Virustotal results 6.85% 
2020-02-07xow64407.exeexe bc17e6e8b5422e6221bfb0b0d6352c8b73760124ae807d9b7de7d6e2cc051e6fn/a 
2020-02-06pfvlhzkdc3.exeexe b0a63415c08b77e913cc4d9eccdd77240683c2960808f2e65a70c1fedb244947Virustotal results 11.11% Heodo
2020-02-06xi94ocg105.exeexe dcfcc02ccc2a380aa56e71745cbbce88426d64b26b960e7dfa91f7fb343fd71cVirustotal results 9.72% Heodo
2020-02-062m8738208.exeexe 878c00d6b18f7dc5f642bb65948ab3b55f054a9a93dee6c056e1c6c5b21f3589Virustotal results 11.11% Heodo
2020-02-06h8vb971449.exeexe d86af03a77f37ecaa7f5cb4d4770cf3bbe3489d74a845b35e8196b721e77ca3cVirustotal results 8.33% 
2020-02-0641y1.exeexe 2f605b35491fa4f6fb22e5c3bc5369de6bcc16d9ca50836c0acdab5b84d82053Virustotal results 11.11% Heodo
2020-02-06mmra1u7589.exeexe a0e33c2bd20b84aa14d1aa5b6292e4646620e9a0bfe5476483c77eadb3393456Virustotal results 11.11% Heodo
2020-02-069ohnd8182531449.exeexe 66e4ba19e63ef70151972c381e007ec4668c392d9bde8bb5b4511c1a0d734239n/a Heodo
2020-02-06o7wj39864815.exeexe 137a5847b7105b09f3d4a344fde0696cd7be47dc2ab39cd2e2346fa10ce54818Virustotal results 9.72% 
2020-02-06jsp26bb4gn61.exeexe 44004a3bed5c23901575fd9b060493800a23d17377cae5d27dab73e91444debaVirustotal results 9.59% Heodo
2020-02-06arl393.exeexe e2d5bfc8607d50414fc4fda68778d634bfe9bb62c878110bea2e810510c36faaVirustotal results 22.22% 
2020-02-06e699jie059379.exeexe baaed937565265039d225c33fbb4714302d3d5a9f927728fc46a675cf2ec0116Virustotal results 18.84% 
2020-02-062v041609325928.exeexe 2ee4575f1f5c1f2803ba175a0b80134ab6c438fc90b060917220df0ca817a8c4n/a 
2020-02-06o4ina17990564.exeexe 50757656fe701e1eba32c342ee258695a9e706abbf460235ee287de90a51b969Virustotal results 43.06% Heodo
2020-02-06yc3803.exeexe 3068cb7570539eca9de9b47424c202a17aaf892414d4d3ccfca0dbcc28b20cdeVirustotal results 24.66% Heodo
2020-02-06g9j461976.exeexe 7f44c6a8f88ac6f33cefd41ebb06e63feed58c250512926cea1f39ea4f56ab3dVirustotal results 21.13% Heodo
2020-02-06l4ncker12174796.exeexe b1b0de783d33d81a97fdba5470ffc693c45ec4e86eca635628712bb0f14336c6Virustotal results 22.86% Heodo
2020-02-06roeq4sfr3j5126290.exeexe f9928335dc78b14bafd3bed551b18cda9b903a884459e13663b32b6274e26524Virustotal results 19.72% Heodo
2020-02-0683978215.exeexe 04120ac049a299f387e2a5802aa75647ae1675d15c5ebcb4df4decb771e212c0Virustotal results 20.00% Heodo
2020-02-06ds0adq69406681.exeexe 27712d3f2629d9d0280a47b72fe446b867ef228c5999ce8b11eb709e8ded1213n/a Heodo
2020-02-06y1cm85zpsp51503745.exeexe 2e8b449a0728e2307148beabaa92512e53b4e3c2b3b3770b56412f3e591c3ac2Virustotal results 11.27% Heodo
2020-02-06mdbw4167573.exeexe 9ab9ca1f328ec35ae8290df1be8f2b7b33e936e0a4dc11dfa84236649562b085Virustotal results 11.11% Heodo
2020-02-06c324894.exeexe d6c9ef9dac72d7a91b1a4c57a6fd6729a7b88b0bb09dadfbb6a89ebf265bc6e2Virustotal results 11.11% Heodo
2020-02-055xe1969738.exeexe 0bb0d410355f6396ee091db46b0d28475fe41b809748773abd1498f8277d552bVirustotal results 11.27% Heodo