URLhaus Database

You are currently viewing the URLhaus database entry for https://gehua.com.cn/vrwmg/protected-array/verifiable-f8kpf06bnqkg-4g5q634m/u8IZWp-boGkKqoshl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415370
URL: https://gehua.com.cn/vrwmg/protected-array/verifiable-f8kpf06bnqkg-4g5q634m/u8IZWp-boGkKqoshl/
URL Status:Offline
Host: gehua.com.cn
Date added:2020-07-20 16:23:07 UTC
Last online:2020-08-17 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 16:24:02 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:27 days, 18 hours, 48 minutes Bad (down since 2020-08-17 11:12:13 UTC)
Tags:doc emotet link epoch1 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21ARC-6724.docdoc 3ef294ca4013371b69d6af647114806b71bb3dc07fd56f12c078703411d61b3dVirustotal results 25.81% 
2020-07-21Arc_20200722_AQG8781.docmdoc f03863257ba6bfc7e029c245f3dd3f892fe5a6aed79b625b2c7314f3398b723eVirustotal results 26.23% 
2020-07-21FILE_20200722_166.rtfdoc 3e24c4373b1e2ba1e3d16925cd0d4a1752452402ae4aaa8ad8ce498bbff5335cVirustotal results 26.23% Heodo
2020-07-21LIST_2020_07_22_F21741.docmdoc cbccd20b9bc23454ec01bec4a0094e77dcc43d577666259f8d97aa30a118ac35Virustotal results 26.23% 
2020-07-21File 2020_07_22.rtfdoc 97d6a51f311c9af7f316be2f4d5ed00901bc5eb08c6daffb87fcf98ba3bd851eVirustotal results 27.87% 
2020-07-21FILE 2020_07_22.docdoc 205a04626bdf6f3da605d8f8ba60126d02451085528330524d899a38520be8c3Virustotal results 26.67% 
2020-07-21FILE_2020_07_22_66589.docmdoc 6852b34db0c7a6150c1095a704236a1938b4ed46cd9d7bdfd412555ebf61890aVirustotal results 26.67% Heodo
2020-07-21mes_3300.docdoc ca4ae10db92df8cf44bacee70e7560ae411a37d1559687ad47687282ca447526Virustotal results 25.81% 
2020-07-21doc_20200722_MKF479.docmdoc 99b15b640124bbe2d317af00e7c30fd65e9b97abdb6e07947205d5bdd73c5737Virustotal results 25.81% 
2020-07-21File_20200722_ZNY456.rtfdoc 5f0b99c314488fa69352a7d73b64203da43208db1b90b18aa4032a84a0c57374Virustotal results 26.23% 
2020-07-21Arc-YH10310.docdoc 1a3131840aa881ca39803d20f5224e9339a2cc959ac92ab756f6ded8d81a1a90Virustotal results 26.23% 
2020-07-21inf-QSY047.docdoc fe0262abd2e28972585a28e0db4036c88dc6bc7858de8135e9cf58c599228037Virustotal results 26.23% 
2020-07-21INF_20200721_15988.docmdoc 9f943a83654e34af90ea126ca921eae3fb9394833e7356a9446aac1579995691Virustotal results 30.65% 
2020-07-21dat_20200721_PQ341476.rtfdoc 9e5640f95155193ba256e171fa3c82d7ee336931c3b88e12f1678197ba4d3081Virustotal results 31.15% 
2020-07-21DAT_14058.rtfdoc 50d5051a82f97571415ca2550517c6872eca80692c7d6db605082a0b9876d34dVirustotal results 31.67% 
2020-07-21FILE-20200721.rtfdoc 8d842d76f958c70be828a217a80c8398107c158a2320c0d36f3b75512b8deca9Virustotal results 29.51% 
2020-07-21mes_169.docmdoc 852dc1adf51a9d21e3750a2b47eade7430026476e56af1615175cf7234e4c7e3Virustotal results 30.65% Heodo
2020-07-21List_2020_07_21.docmdoc b94adce77ef4687f4a2308618ad9109110ccca6b7a12618f12c334a61ffa712eVirustotal results 29.51% 
2020-07-21rep_061888.docmdoc 1b3a66fa218971358919a1dc0cbfcd9fdaac7ec3278bed6109f0df2550dfe3b7Virustotal results 31.67% Heodo
2020-07-21REP-20200721.docmdoc fa34ecd729ebdf64de47192d76713cce9390f4f77b2b0640ea2ed67fa54f4d5fVirustotal results 32.20% 
2020-07-21dat F481879.docmdoc 3d808e9e116ecad94d0839d1a951f8aa24c96f6dfaaa774a889edbb38c857b56Virustotal results 31.67% 
2020-07-21rep_20200721_W56344.rtfdoc 262962b5fcfbc2fd14aa121ea6d5731ee54807c1d8f5cb14aedfa6437d1b764bVirustotal results 31.67% 
2020-07-21Arc_20200721_83789.docmdoc 2da4a10c384d2bf3468b73d621de109cab5a29179b9d6cf4102c7b46dd937261Virustotal results 31.15% Heodo
2020-07-21Arc-20200721-4257966.rtfdoc 4de321a8533808438637e1c145e5ddfef9f24da81cb5129fed75c13218abecbfVirustotal results 32.20% 
2020-07-21Doc-687452.docdoc 519ac8bbe23cc0506580ac08c5bc589d9d5382e00ea81898846715cef7502d8dVirustotal results 29.03% 
2020-07-21list 2020_07_21 K978.rtfdoc a9e912c0733016338d181ec06475e1f30f28fc2159ee482787e913fc65085cf5Virustotal results 30.00% Heodo
2020-07-21arc_2020_07_21_EMX72199.docmdoc 608a39d31a2ab34bf79ebd042bf10028b9bc7ed087dbb810306956dd1ba45567Virustotal results 28.81% 
2020-07-21arc 20200721 567.docdoc 703809d3dea2ef37b518110d3f0bdbd25798dafcd9ebfd2c4094ecf9a2e91267Virustotal results 30.51%Heodo
2020-07-21file-2020_07_21-15602.docmdoc e03def51cc78a91e3c97945ebbf083bea9efa86f55fde07a8c4bae905c1b8671Virustotal results 27.87% Heodo
2020-07-21Doc_2020_07_21_412.docmdoc d1f13cff50c5950b6842f81fb632405df63e1d6a953d4d912b3f5ecfb1afa55dVirustotal results 26.67% Heodo
2020-07-21DAT 2020_07_21 966.docdoc 15617b37ed587c9af7ec3de8d4aabd3de95ded6604f652abea14822da2c94ce0Virustotal results 28.33% 
2020-07-21Rep 20200721 217.docdoc 3b2f5f46ff691d1339cd98d00d79cfc31b0a7c7820a17c45c7be9197a392f2f6Virustotal results 26.67% Heodo
2020-07-21Dat 20200721 FCJ72738.docmdoc 75cb0d33fbd33b08aede2930d9ac79f7086ef7db06803c493d9214d84a4391e3Virustotal results 24.59% 
2020-07-21arc_20200721.docdoc a82dd2141315d36a0f9ba74bb443a40e0495cd089323254c35d0c4686249de7aVirustotal results 24.59% Heodo
2020-07-21inf 2020_07_21 FGU652.rtfdoc 55a103c16b3c4d8958091e55cfb62091fd2d209e07ffba0a5c88252946b8ae39Virustotal results 25.42% 
2020-07-21List_2020_07_21_A80492.docmdoc bde282cb96f5986ecffac2e217f661fa0f00c92f1e4b2a788aad9cbd53a2eb51Virustotal results 25.00%Heodo
2020-07-21INF-20200721-SYY3314.rtfdoc ad614712ee0ad71a7408a527a3a2051489b0ff4f08038b7a676ad967ea160fb7Virustotal results 25.42% 
2020-07-21mes_2020_07_21_905086.docdoc 23bf0066e26b5b6e2403af2810c57d5ee5c0e04cfb175df6c134826cdb68bce9Virustotal results 25.00% 
2020-07-21mes 967.docmdoc 38a052e49569227f531849f52c6e801e5abb2c68a7dd2c5a9fca8e92ec6b0211Virustotal results 24.19% 
2020-07-21arc 2020_07_21 77436.rtfdoc deb29a892e444cde34fe7642bacbee1bf74d35fcff478966636eec77c5e28646Virustotal results 25.00% 
2020-07-21Arc 20200721 69233.rtfdoc ecdaf78dab236699d9244160f6b4865a5cdc8481ff2e8d798df9a342d10f1654Virustotal results 25.00% 
2020-07-21REP-20200721-TB904033.docdoc 44d93b12f57a0d476e774d58da761e56ddd20f6d299acc2390a9111082e448deVirustotal results 23.33% 
2020-07-21dat 2020_07_21.rtfdoc 477bc137f269ae86b7049d592f7588c5f063e569db20bd09ff2bea3a04aeba06n/a 
2020-07-21REP 2020_07_21 JMK686168.docdoc 77381e8fde74067c151274bc344395ef59df227e209ec80c0d7879aacbd5d654n/a 
2020-07-21ARC-276902.rtfdoc eec0262941bfb2dcb8d29f6ef1ccc699726ac66beb04d7d34e8da3281cf19c38Virustotal results 25.00% Heodo
2020-07-21Dat-EQD89827.docdoc 2e716647297132c94bca63747c48379889273658b12366fbe0e689a2b9966470Virustotal results 24.59% Heodo
2020-07-21DAT 2020_07_21 IOQ05386.rtfdoc 14f298945ba541ac7f6cf64b12d67423fffd432bbf2e598d25cd50f0e8cfd86fn/a Heodo
2020-07-21LIST-20200721-XS123.docmdoc 38ee970b2c3b2902e43212926ed41ad27fae79b76938baad0b96743897def42bVirustotal results 24.59% Heodo
2020-07-21rep 2020_07_21 W784491.docdoc a8d9eceee2cd3735b96abf3528e7ec3e8e2d8ceb8991c00c7ff479e9034655f5Virustotal results 34.43% Heodo
2020-07-21FILE 20200721 TAQ4597.rtfdoc cd7e26bbcc41d0820e6e2e0e42e56bef410264d6bcf74033fd1fe26d52b389eaVirustotal results 33.87%Heodo
2020-07-21rep 219.rtfdoc f78e874b4d5c5dedede72b85b571f2b04d8edba617b6634d95c2af181e6e4dd7Virustotal results 34.43% Heodo
2020-07-21List-UG584169.docmdoc bac082845ee6dfbda9489e3c6f1c90611ad4ba2546da7e855578225a51197ebaVirustotal results 34.43% Heodo
2020-07-21arc-2020_07_21-624548.docdoc 276568f9c3bb230aabe183dbfd02ad1c36b7aa141d382d34a839a611a422c07fVirustotal results 33.87% Heodo
2020-07-21doc_6173526.docmdoc 754a0bebe018b079d9d9260256ea2106b4b5ad9a654c8b8a1989bf6e3f4568f7Virustotal results 34.43% 
2020-07-21REP_EAC663.docmdoc 5816bc271d88617e627d64210b8ac9df417f8072b362af861ade766137eb1564Virustotal results 34.43% Heodo
2020-07-21List_2020_07_21_DJ90966.docmdoc ace014e43d78870f28d2a732d72b60fe0c602b71dcc8771989e5cfc0bb1e0befVirustotal results 33.87% 
2020-07-21INF 9744.docmdoc cace589fbea03e0098cd73ad40875dfbe1af727e4b82a5944b6e2111009af7a4Virustotal results 32.79% Heodo
2020-07-21file 20200721 X0407.docdoc 86615d32b685ca8d74d59c1c848216fac1eb779d126a183795f316a6ff0014b6Virustotal results 33.33% Heodo
2020-07-21REP_0890612.docdoc 32a11fccc02f1372c54ca027f00c35e33268d3819191a348b9096fd3853ab6fdVirustotal results 32.79% Heodo
2020-07-21Rep-20200721-ZU1072.docdoc 41718a7885dc57496b953e118a0e425ba2af1e37a2a3a868cf05ac83e3db792fVirustotal results 32.79% Heodo
2020-07-21dat 20200721 E9158.docmdoc 276dfa20b9cffd3ac104aeafed599b2f70a9fd0e8d4faf1d86ffd46e8354a416Virustotal results 32.79% Heodo
2020-07-21dat-688463.rtfdoc 176237b901fd642cfb1c3a9fd8c50cdbf0d5ec30df6c98142d3a0e48839f9d51n/a Heodo
2020-07-21mes_2020_07_21_0984804.docmdoc 6c7da386cdaa6398c065aafedeb01b31ec959ecf615e9601a81a2c86488c4c86Virustotal results 32.26% 
2020-07-21FILE 20200721 594.docmdoc 1236dd4116a2c4ba4427175d0a3e88c848f70dc6219f6b22f1997ae3ba80ba14Virustotal results 31.67% 
2020-07-21arc_NG256939.rtfdoc 4e34674eaa422795c92ef9cb66994e18a57553e217b4bb4de69c1369608e36e6Virustotal results 31.67% 
2020-07-21Dat-UUV28141.docmdoc 49b857e2068f710d1facd444264c6d8804ecc9e2ba9660953b24bbf213cc66baVirustotal results 29.03% Heodo
2020-07-21rep-6704.rtfdoc 33e64096db5340fb26c5b5d6f9b1dd89674d3a77a96a25fafcb878d9929fc9daVirustotal results 31.15% Heodo
2020-07-21REP_RZ11548.docdoc 99c6c8f02c2fef792bc8a5a6406b0baa294156cb38b8df191f98cfb5a90547f5n/a 
2020-07-20File_2020_07_21_PJG225.docmdoc cce8e5e706869261ede523822b673dd52e48d4351de8600f5ac209a7f0189629Virustotal results 29.03%Heodo
2020-07-20Arc-20200721.rtfdoc 0d657d365282571dcf58adbb3a758c81fa3df50bc081a60d01f14c5431b9492eVirustotal results 29.03% 
2020-07-20Doc-V676.docdoc f83e32a15080c0f31451809377046083d52daef3354edecea6db6ccf4158a43aVirustotal results 30.00% Heodo
2020-07-20Doc 2020_07_21 SQ8755.rtfdoc 107cf68ace70917126432b415c7a9b4a18e3f87c304c1ea780b1fe0950167c29Virustotal results 29.51% 
2020-07-20Rep 20200721 NWY81685.docdoc a6ca24bb5b1de30cd63ecceac1727ca4102ed289d65fa05c550c4485e6ca372bVirustotal results 29.03% 
2020-07-20FILE-F982039.rtfdoc 41d61ed5ec94c9f81d804487ad8f6132520d6ac7009a8c9a7b0c074ed0748e4eVirustotal results 29.03% Heodo
2020-07-20Arc 854428.docmdoc 1269bdbbc40be92cc1f13918a692b34fdfeec466bd7d872863ecc405ff38f77fn/a ZLoader
2020-07-20REP-2020_07_21-5181.rtfdoc 9d397f040fb1768faae4189e4e3e0aa60604b2b86617d979e1f61d90a8798fbbVirustotal results 27.87%Heodo
2020-07-20ARC_20200721_2339314.docdoc c6050ddd07c6d8c4aee73c52d0e50d6056ebd5f3e82550d8c771fc4353d489feVirustotal results 28.81% 
2020-07-20Arc G5953.rtfdoc 3b93eda94becc07130cb0b7b3bd4f351444c2a0810a9bd983913a4a5d833b3a5Virustotal results 27.87% Heodo
2020-07-20Dat.rtfdoc 00593b1d3ba64e5ca39e6c503ab0f33dcade0d3afb65c2a73f2d4696cf8a7bb0Virustotal results 27.42% ZLoader
2020-07-20ARC_2020_07_21_722.docmdoc 8d861becdf66c056d51b6b585d1d2c98ec75e77bc3af28d354edb72f3ebb65adVirustotal results 27.87% ZLoader
2020-07-20FILE-2020_07_21.rtfdoc 10e15c8850925b8f03210b06fdc2e0e87bd7339bf6a185992346e2063cbe1e99Virustotal results 27.87% 
2020-07-20rep 20200721 7282.docmdoc 6f644a06ca787f32149885c5a6c522c5cb5f0b40cd112d8a306d239b316f4d55Virustotal results 27.87% Heodo
2020-07-20list 2020_07_21 XAD432689.rtfdoc eb1f1cf5bb142fb70ac9421ceb472dad3f583fcc852ae768c1ae347506cbcc04Virustotal results 27.42% 
2020-07-20dat_20200720_368180.docdoc dc9d3da24212096b6029163166558cefcd8b37aae588dd461d9b5c02700700afVirustotal results 27.42% 
2020-07-20list 2020_07_20 ZDX4623.docdoc 8f282a424b1167ed2e71b2355a7c4e6797a75d031969749e3ba21050292414e6Virustotal results 27.42% Heodo
2020-07-20Dat_2020_07_20_SXP75222.docdoc 97e66ad16955f21f83dae53917dbdefba08fc07108392a96327eeef55698a04cVirustotal results 27.42% 
2020-07-20Arc 20200720 XC569.docdoc dc83903be08352444bfd3116d33bda30da619c60371f037e0bd56f82a2a768fbn/a Heodo
2020-07-20Doc-2020_07_20-5452.rtfdoc ed29b479d20901bb285c8146d9a69a73a34eadaa4f6c86aca69aeefe96f4fe0fVirustotal results 27.42% 
2020-07-20dat 20200720 02839.rtfdoc 3bcf67ec54f94ea28c8c35560ef2f6b2ef8090951c1ce2d0a94aebfd04a4786eVirustotal results 27.42% 
2020-07-20Dat.docmdoc d2592f81840c6459ba7e0d05e58f48c703e29b3a97134a5bec16e60e85e72098Virustotal results 25.81% 
2020-07-20dat_2020_07_20_696.docmdoc c8b4b7e686954bc7ebd4115f98ec29527b1b0d47d1a817adebc3c6b44c26d787Virustotal results 25.81% 
2020-07-20doc-880.docdoc 0cd73a229418caf24e599b0db39e5ff3ae2903ffb83340c026c0ffa0f7e9f86bVirustotal results 25.81% Heodo
2020-07-20Rep 20200720.docdoc 2ed0a17884d80b91110cc117b3963361ae603c91ce2cd60de6131972d6a047b1n/a Heodo
2020-07-20Mes-2020_07_20-8463576.rtfdoc 4fe945b83567f1855dbc8ea4f8e0e0e2258117238ca2184dd10ba6cf797377a7Virustotal results 25.81% 
2020-07-20arc 2020_07_20 89254.docmdoc 31adf970450cb8a76809bff658f19a6e62c31894dee3957e3374752544f042d3Virustotal results 25.81% ZLoader
2020-07-20mes 20200720 8321.docmdoc 130a66f245904ca4051c2eeb37eaa7b9157fb02b881164bef6a47aed0adbf12eVirustotal results 25.81% Heodo
2020-07-20Mes-692019.docdoc 65177717b6fd8b0a589c64a14c0f03064f055d5855247580c6926b0b2966e44aVirustotal results 25.42%