URLhaus Database

You are currently viewing the URLhaus database entry for http://yihe.fcglobal.com.cn/phpsso_server/ej9ni-qb-014/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414144
URL: http://yihe.fcglobal.com.cn/phpsso_server/ej9ni-qb-014/
URL Status:Offline
Host: yihe.fcglobal.com.cn
Date added:2020-07-17 17:34:08 UTC
Last online:2020-07-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-17 17:36:02 UTC to qcloud_net_duty{at}tencent[dot]com)
Takedown time:2 days, 0 hours, 6 minutes Poor (down since 2020-07-19 17:42:11 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-18Invoice GZ1_198815209.docdoc 169f03cee2b674a04eb777235895e2e6d94f82785fac8764ebb330df2bf2448dVirustotal results 40.32%Heodo
2020-07-18INVOICE KD20_022978.docdoc 81cd5ce6123449ba648b0d4e9e5b254c223fbec0959ca04f739d278bb49e0761Virustotal results 40.32% 
2020-07-18invoice_TG4_977541.docdoc 80e277e15058cc1c440200dfe3163744b701225ecedf6888dc08e9f77df37601Virustotal results 40.32% Heodo
2020-07-18INVOICE-V090_765166053.docdoc ad8ec7c667bb0c0c8f29d5da291048d0a7ec8f118a640c6e97788abc0ecad0ebVirustotal results 37.10% Heodo
2020-07-18Invoice FUTO58_86461774.docdoc 1930614813330328ea07ab82811cdce5464d3cbde53b3f4efc556b6d710ea453n/a Heodo
2020-07-18Inv-BVU130_266493570.docdoc 7160087ac3e5c4d46b6584cbcbddcc6ec96376290a7361df015284b62cb3c2acVirustotal results 37.70% 
2020-07-18invoice B5029_112399530.docdoc af0485ffa7cb3464b0918c518490268e427e3a768d194cedf1187eefec333104n/a Heodo
2020-07-17Inv-KPN66_98596819.docdoc 409ffe4576bacde509efa8e950c78e278332d37992587aa8699d6856cf62b119Virustotal results 35.48% 
2020-07-17Invoice-639_5320861.docdoc ab19da6f740056f36197abf8845d9ccaefbce0a420ecc8c0c4576eb74a108ca9Virustotal results 36.07% 
2020-07-17INVOICE-OU23_13988529.docdoc 61a437bbed8e3ac3a4641ce788de7880516f124ad0a3223f107e92fb0cf969eaVirustotal results 36.07% Heodo
2020-07-17Invoice RLF2_855890.docdoc 656404db090356761eafa7b73c9528cc277067a7e77743bf9eaa8d17e7b3b522Virustotal results 36.67% Heodo
2020-07-17INVOICE BZFZ6100_998747.docdoc 83f66d992e12fef5ce5f9bd4d34b909c05733fbc574d98eb9524003fd005d738Virustotal results 32.26% Heodo
2020-07-17invoice_FYG6301_655235359.docdoc 1e1fb8134d9ede5ca2e5b740ff81ef5e76206eed5933c5c2786ecbfa2dccf624Virustotal results 30.65% 
2020-07-17Inv MZHJ0_244101.docdoc 211a160cb4b1f9b0166c5701cffe1b3f47ebd10d59d0899a1ad0dac6dac1e855Virustotal results 29.03% 
2020-07-17invoice_BWO319_69911558.docdoc 69fda7852e8bb1536d60567e061a42139a071a604855852101bb0d4d3ffdaff8Virustotal results 27.42%Heodo
2020-07-17Invoice-MD6_658666697.docdoc 7208ea29213bf6b0393523cdeb9b9234f8b52596ad3e2f595012344bf5de5fb8Virustotal results 25.81% 
2020-07-17Invoice_P593_1763439.docdoc bb6b248bbf5fa806a85edd4cd5580e6d0f24bcda6e0271b88c236cd653601ee9Virustotal results 25.81% Heodo
2020-07-17INVOICE-BG9_451930062.docdoc 0c6fdbb83539fe76c8db143e036c4eca7464535d8b900318b5c0870b3b8024a7Virustotal results 25.81% Heodo
2020-07-17Inv_V39_746527028.docdoc 82c401148abefde60b6f557d36ae313e40d65cb3902f6d0d4e94a14308a7e410Virustotal results 29.03% Heodo
2020-07-17invoice_RY27_40040048.docdoc e37ed35ad92d7f72dd82ba694d4ff1b2811ed68857e2402e20f46bbeebbf8b7aVirustotal results 25.81% 
2020-07-17invoice-NE5710_176688785.docdoc ea488cfef075f8314cbc01390816578b77f0f03778254e6a802d18e5e764daacn/a Heodo
2020-07-17INVOICE_T9088_314643525.docdoc 9fb23aa6a9fd7292e6020c5830bc67721c605a132a2a406fe2c7e4d948fd0377Virustotal results 27.87% Heodo
2020-07-17Inv-FE153_4109401.docdoc f83e196ddacc66388f92a4e8aec132445b3cf724beb962528c9b860e82bae6b6Virustotal results 25.81% Heodo
2020-07-17invoice P672_31488621.docdoc d92cb1bdecd2ac46696a43f0a13682eddfdab906ae7430887a5dfbe33174b9d4Virustotal results 26.67% 
2020-07-17INVOICE VP963_780230.docdoc d0fd2d71c1267d3ad20bbc348b043e49ea7eda9acbfbc30e64dafb296a1a9011Virustotal results 26.23% 
2020-07-17Inv-FCL054_3033303.docdoc 8b8ccd4f24be195ddf2b59efcacfe6486785230cc152b5a31a5f5e217050a8aeVirustotal results 26.23% Heodo
2020-07-17Invoice_J608_8164826.docdoc 8ad7d04c2ce1495acb9334fa32262fde03ff9062dea6f41ac1753e56431a2defVirustotal results 26.23% 
2020-07-17Inv-OUF5707_341800.docdoc 7e5ba709b5531916b926d6d12030425682e84ba3a9913be003f9ba1776ef1efbVirustotal results 25.81% Heodo
2020-07-17Inv N63_506482.docdoc 99eaa2c123dba9eef4f3ed871cab31b24c0f2ee401252c7fcb6b78a33f5354b2n/a Heodo
2020-07-17Invoice-W44_279617668.docdoc 606100910cf09b07bf7bcfbd832340267c887fa8dd37f5db6aa05b41460b0a30n/a Heodo
2020-07-17invoice_NLY91_099759460.docdoc 9816f91c8817dcae7564fdd7ab9883355c523c01af140c53b7595e5ad133912dn/a 
2020-07-17Invoice-CB86_143015571.docdoc 00e7eac4214d505bdb07f3f161a911b70fd63d15371ed900126c174fc4220c4en/a 
2020-07-17invoice MMRD9_943992446.docdoc 6024b61c5cdefaf718ca5c5ad0870b779babd90c85ae569db58a0602360c43f5n/a 
2020-07-17Invoice-DD01_222665957.docdoc 46a1bc126658ca3de121d07c778420ffd99ddd9ce2271922902e888d8a038f99Virustotal results 25.81% 
2020-07-17Invoice KSB7_919049642.docdoc 23750f655e0a44d03e6b7598858e354f1c4e3dcfe784c3f6e1175b831ebc1badn/a 
2020-07-17invoice-VQU8_811594322.docdoc 478a7e22d2f0fd9f4fe8ca2241692afb2fcf175279a0117bfb8c0cae469fc195Virustotal results 25.81% 
2020-07-17Invoice-ZC6207_401589491.docdoc 33d9a2c9378ab460b1224ec190291fcac259178596a1e285383dff0697376115Virustotal results 25.81% 
2020-07-17INVOICE_G1022_48448677.docdoc d8c01ed6fe71e39201aa7d34dd3ff21706ffe6b3217489501aaf659889115eb1n/a