URLhaus Database

You are currently viewing the URLhaus database entry for https://huakai.com.tw/wp-content/closed_593437422_ggMWM/security_y7y6_y0o6/8i97h0_0xs645/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415510
URL: https://huakai.com.tw/wp-content/closed_593437422_ggMWM/security_y7y6_y0o6/8i97h0_0xs645/
URL Status:Offline
Host: huakai.com.tw
Date added:2020-07-20 20:22:08 UTC
Last online:2020-07-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 20:24:02 UTC to hostmaster{at}twnic[dot]net[dot]tw)
Takedown time:6 hours, 8 minutes Good (down since 2020-07-21 02:32:45 UTC)
Tags:doc emotet link epoch1 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21REP 6746874.docdoc 1236dd4116a2c4ba4427175d0a3e88c848f70dc6219f6b22f1997ae3ba80ba14Virustotal results 31.67% 
2020-07-21REP 967.docdoc 4e34674eaa422795c92ef9cb66994e18a57553e217b4bb4de69c1369608e36e6Virustotal results 31.67% 
2020-07-21Arc 2020_07_21 5161.docmdoc 49b857e2068f710d1facd444264c6d8804ecc9e2ba9660953b24bbf213cc66baVirustotal results 29.03% Heodo
2020-07-21list 20200721 NN826.docdoc 33e64096db5340fb26c5b5d6f9b1dd89674d3a77a96a25fafcb878d9929fc9daVirustotal results 31.15% Heodo
2020-07-21mes_B80207.docmdoc 99c6c8f02c2fef792bc8a5a6406b0baa294156cb38b8df191f98cfb5a90547f5Virustotal results 30.51% 
2020-07-20list_20200721_6676.docmdoc cce8e5e706869261ede523822b673dd52e48d4351de8600f5ac209a7f0189629Virustotal results 29.03%Heodo
2020-07-20REP_20200721_180.rtfdoc e00291bcd00edfbf9f8f55a1f34576b512404c036b744d0ce846397f8a83bb1fVirustotal results 29.03% Heodo
2020-07-20Doc_20200721_FDJ4670.docdoc f83e32a15080c0f31451809377046083d52daef3354edecea6db6ccf4158a43aVirustotal results 30.00% Heodo
2020-07-20Inf-20200721-894.rtfdoc 68f85e639cf07fc84c8204cec1bd82fd8985d854aa17d02c89b58b255b98ed48Virustotal results 29.51% 
2020-07-20MES WWI447.docdoc a6ca24bb5b1de30cd63ecceac1727ca4102ed289d65fa05c550c4485e6ca372bVirustotal results 29.03% 
2020-07-20file_20200721_9457.docdoc 41d61ed5ec94c9f81d804487ad8f6132520d6ac7009a8c9a7b0c074ed0748e4eVirustotal results 29.03% Heodo
2020-07-20arc 43761.docdoc 616dde6dc6e22e28f4149e26996578dde114b40f896cee3cb36165d52ff70857Virustotal results 27.42% 
2020-07-20List-2020_07_21-N0736.docdoc 1269bdbbc40be92cc1f13918a692b34fdfeec466bd7d872863ecc405ff38f77fVirustotal results 27.42% ZLoader
2020-07-20List 2020_07_21 3743.rtfdoc c6050ddd07c6d8c4aee73c52d0e50d6056ebd5f3e82550d8c771fc4353d489feVirustotal results 28.81% 
2020-07-20list-DM8675.docmdoc c5dc7db865c477ba217342107932a67cab54659a8a870fa16a9d2f21ec3aade2Virustotal results 27.87% 
2020-07-20INF-20200721-09649.rtfdoc ec87e9999c894cdef59c964d06c6de6c7a7134d373b4e754180d90dd5fb23f64Virustotal results 27.87% 
2020-07-20ARC_A982190.rtfdoc 8d861becdf66c056d51b6b585d1d2c98ec75e77bc3af28d354edb72f3ebb65adVirustotal results 27.87% ZLoader
2020-07-20Doc 2020_07_21 250.docmdoc d6da6435e94d2fbb2a3847c934bf0b6d41c613337ac951b10fd5851eb98a9bf3Virustotal results 27.87% 
2020-07-20Dat_2020_07_21_618.docdoc 10e15c8850925b8f03210b06fdc2e0e87bd7339bf6a185992346e2063cbe1e99n/a 
2020-07-20doc 2020_07_21 YM217.rtfdoc 3aedca3992d77371154f015834399c14aab576050a53efa01fb5714e01beb841Virustotal results 27.42% Heodo
2020-07-20Inf 2020_07_20.docdoc 08f5ec28ca3c972a6d03a47225475ddf5930decbb10ca8de63dfe0544581ce14Virustotal results 27.42% ZLoader
2020-07-20mes-20200720-262221.rtfdoc 7812b414ab8098b436f22af0523a1edb14b8af7eb4df4bac66f9268cdb074e96n/a 
2020-07-20rep_J876180.docmdoc a1064f658ecf514ba982b19196bb1ea0b7f1e85661c20777b3e93093510db141n/a ZLoader
2020-07-20Doc_20200720_TCO44768.docmdoc a596ea13973162232be90c68099e1b664aadeb7150a6c7e70ece1bae29dcce39n/a