URLhaus Database

You are currently viewing the URLhaus database entry for https://lgjmcaz.cn/wp-includes/attachments/bw2554921933816769anjytysnh7krtq3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429452
URL: https://lgjmcaz.cn/wp-includes/attachments/bw2554921933816769anjytysnh7krtq3/
URL Status:Offline
Host: lgjmcaz.cn
Date added:2020-08-11 15:01:33 UTC
Last online:2020-08-19 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 15:24:05 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:7 days, 13 hours, 26 minutes Bad (down since 2020-08-19 04:51:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13GW_76160687.docdoc 53779912a3ae5ef479fed79b214c947ce24d8295c680654ced405639448dddc7Virustotal results 28.81%Heodo
2020-08-13PO_08132020EX.docdoc 6a26521c4629bdf9f7cbb4b978fbf7f365e57683a6f13c93cd7147bfd6b61473Virustotal results 28.33%Heodo
2020-08-13SH_KL1305961401YZ.docdoc b51738d4d37c472d3b1b69c1f7cab2d120fd9f2e53a524e772a263e65a892c94Virustotal results 28.81%Heodo
2020-08-13Z_RR27TKK28D32Z.docdoc 22c4bc8c9ad10df54d22ae6a89c1b937d49982a7b9f6ed54798394dc9033c0cbVirustotal results 28.33%Heodo
2020-08-13INV_PO_08132020EX.docdoc 44a4e9297c1d0191631e49532aa755b5a7928836c63b7a9f37deb77293cf2ec7Virustotal results 28.33%Heodo
2020-08-13INV_56682835.docdoc 79b609ddf074406de181d656544923255389ac44a068ddaeb858e6546d2787f4Virustotal results 27.87%Heodo
2020-08-13REP_TJQ_080120_OKU_081320.docdoc 384640f8d0029dc11aa8cfd8514d0f4113fee6cf0e3c9db685bfbb282214c49aVirustotal results 30.36%Heodo
2020-08-13BAL_RBG_080120_CSV_081320.docdoc e163803cb71c55b28fbfe8435c5aed2616a006e425556ee9b4f3670db2115d98Virustotal results 30.00%Heodo
2020-08-13INV_PO_08132020EX.docdoc 0c4fc99638ce35263569e89011b336bddac6074ea768e3f77d4d6acfda9e3ddeVirustotal results 28.33%Heodo
2020-08-13E_AK8503118991UE.docdoc c62e7473580736e9ec7372d05bfebc80d995dde8be351119f101ba366ef172b8Virustotal results 26.67%Heodo
2020-08-13DOC_GX5360589424WS.docdoc 3b4424256068b5207279adbfc554cfaeffef0536777d0762c54c1f23211fbd2aVirustotal results 26.67%Heodo
2020-08-13FILE_8IRMHYSH395PI6XB.docdoc 0652c184cccfd772644a2b72467b93f57ee93b1095894cc08ab3a9d9470fbac9Virustotal results 26.67%Heodo
2020-08-13DOC_AWS_080120_WQY_081320.docdoc e303bd587f94e0cc2bee4cd31594d807f186aa22f04da0615deaa6c27863e72aVirustotal results 28.81%Heodo
2020-08-13FILE_30863744.docdoc 1ac4188f22c717e76b493881ab12ef60e719cb86d2e5289f743b42b338cb5b96Virustotal results 27.12%Heodo
2020-08-13INV_PO_08132020EX.docdoc fdd5654b78c6c5c23b4f6c6502eb69701c87c65ad4bd2d121046db883154d863Virustotal results 27.12%Heodo
2020-08-13QCZF_4390088177.docdoc ba510b5a0f97430a09efbd12acbb4c1be869e71e678adf5fa0b5498fb477068eVirustotal results 28.33%Heodo
2020-08-13REP_78413414.docdoc f3288815441008b2291c6b17d597d58fe606f7475c4641bacba49ad56c1b1142Virustotal results 51.72%Heodo
2020-08-13PO_08132020EX.docdoc 0938a3eb8d86fa634cbaa1f643bd2c6cafcdacba202e4683cf7245705bd11fb3Virustotal results 52.46%Heodo
2020-08-13PO_08132020EX.docdoc c2bb5e128810c06abd15ad3ef0bc95622c20da154ca500892972305c94feabedVirustotal results 52.54%Heodo
2020-08-13DOC_CG9403639087VQ.docdoc 2ec1025c3a44b35de74853b22998ea439d6eb5f0d92d9065256692f0deadcbd9Virustotal results 51.67%Heodo
2020-08-13DOC_UW4GXKAWFCBTO48.docdoc 5ec2a412f6729dbbd84453b84c85ac56f93e865a1900eb514efedefedc56467fVirustotal results 50.82%Heodo
2020-08-1229660655.docdoc a9af06ae735677ec282b4a66f7bc85a343dc7c71491658673fed6150e05ef3c5Virustotal results 50.85%Heodo
2020-08-12YA4141936118KN.docdoc e9bbc3d987e57144a6554ea1c30a527af2db5a40b2c12e9fa6b28a79ea2afb3aVirustotal results 49.15%Heodo
2020-08-12YW0936442813TI.docdoc 77b30bd340e5190b08a7d94df99aa81a4aed0b89711a543fa9f87bb83fe3a72fVirustotal results 50.00%Heodo
2020-08-12REP_PL9151094573OZ.docdoc f3a601950fbbbb99855528eac98d43109bf3ab8aa35e4de00ae14321f1d6ea2aVirustotal results 48.33%Heodo
2020-08-12BAL_OSD_080120_NNP_081220.docdoc cfec1c4aeca2bf10496b8ae3be0b77a9dfade44f1503c09398114731db0e92b5n/aHeodo
2020-08-12FILE_GTA_080120_LUH_081220.docdoc 04f8c0a6881a2159e13398f7072a461705b4ccc8517a28cb9565506f9b9ba8b0Virustotal results 50.00%Heodo
2020-08-12H_H23XBYWOL5KT1E7.docdoc 448b77551e8ab272663dac5ccf4cad4be8b7dcfc1759a2859785754aa44d285an/aHeodo
2020-08-12KU_9A2Q19I24PICMMV.docdoc c75a7753aba5fdf5703e46cfe6e6a53ceb7df3394f932fc521343b25ab0b2388n/aHeodo
2020-08-12FILE_PO_08122020EX.docdoc 86a7080b18d0d16fd7b1505799c006382ff034fb5dbb65b0e933ab56cee84215n/aHeodo
2020-08-12T_KBM_080120_BMO_081220.docdoc 42784e0de01af05a046c1361a8e58eeb1d7eb88b72badd646658090e49a54939Virustotal results 49.15%Heodo
2020-08-12L_568770367968895974.docdoc 9560b2aab2f8964f9d311f48c38bfb28b97ac4de7f71ec667e4ea68e921a2c62Virustotal results 45.90%Heodo
2020-08-12REP_QMFBRV0P.docdoc 97feccf3c91f6d0275ecafdf2bb2d3a869dbd30f1ed7e87db533ac6a63678fb5Virustotal results 45.90%Heodo
2020-08-12DOC_PO_08122020EX.docdoc f3852c9ccc8a88f0f18abfd98b52f67f59980f1ddd97da7743a4bf6c7fe900f9Virustotal results 40.00%Heodo
2020-08-12DOC_PRW_080120_VYJ_081220.docdoc 1b43dacaa3825888c4583607901a5fad687f60840690fa8dfb7b5ab72e28c27aVirustotal results 38.98%Heodo
2020-08-12FILE_3757677952118743500.docdoc 25263694227734da43c741c2d09b0f0aceb8cb2d9488378a2ea765c6c19be594n/aHeodo
2020-08-12KGI_080120_FTD_081220.docdoc 2c99381fa134d8121f52b07a62cf94574cd977c2662a4087f18b2f5960370005Virustotal results 30.00%Heodo
2020-08-12WX_PO_08122020EX.docdoc e6aff4596a71a4b0c501dd7850553e31385190366a94fd6dc636e0664665e131Virustotal results 27.87%Heodo
2020-08-12FILE_J04XLWU.docdoc e9b11c739e5d0a771cb4efdc41e3d084460fa975e42a309294ab185eb2836728n/aHeodo
2020-08-12DOC_938415365564845873.docdoc dbbcb02ce1775cef0bf8d1ccdcbf4789d5936dc08b63afaa7ca81e20aa03a597n/aHeodo
2020-08-12NT6014693346AP.docdoc 7eba5b17df94761ce65d93039d81735e0a1525f6b3244704a023df60dd04c17en/aHeodo
2020-08-12DOC_SJ1316279513CA.docdoc 975bbf11f28dfc7c66c6cf49572657178c8ee4acb9d48d403c01bac687b1eedaVirustotal results 28.33%Heodo
2020-08-12EUM_PA0192058724UV.docdoc 16d2a267cba033c59963d01757e9800048ac1fbcf7cb53595dad21ee5bb027c6Virustotal results 27.12%Heodo
2020-08-12FILE_3073169946300435811150384.docdoc 9f355154b3f108769ec0855431cb69c5172916d78b07a8d79ff6da2f49371b6aVirustotal results 28.33%Heodo
2020-08-12INV_7374308946903.docdoc 0d6aca5233bf958211fc44e3eaf4a6c88b1bbc68c716758cb805d62b93306b0cVirustotal results 27.12%Heodo
2020-08-12JC1647726464HN.docdoc de169cf40f36b18f3d015ce68ae4472c46aad34f8d9e71f76e658fbbdc74a6d4Virustotal results 29.82%Heodo
2020-08-12REP_EZ8106619231RF.docdoc fe14ae5d76ac1ccafc67f474efe315000dadae344444a44c9200e04e94ebbdadVirustotal results 28.81%Heodo
2020-08-12INV_46676299534419531973.docdoc 05fb55b118852bdde2c76754d2d2b2700accc08481280cc2309ab985aeb86c06Virustotal results 51.72%Heodo
2020-08-12FILE_03395304.docdoc af51abb1270f34af770a98599b8023a55d05885a976e2c898299e78ffe91c943Virustotal results 51.67%Heodo
2020-08-12INV_U1RCKVP2WY66.docdoc c978e204a4343d19a9b1df57379618a391455fe0f0fd17e49fcb670670c4241cn/aHeodo
2020-08-12JHSP_IY0JLSCL.docdoc 6f973501cc2dece992aa2f959f8e352e424e96f06abb300b4bed8bcf2ab4bf34Virustotal results 51.67%Heodo
2020-08-12INV_PO_08122020EX.docdoc 1d2096f4adcba717670858b98912615f7bc86bd95ef6b3117901aa4ae6383d4dVirustotal results 53.33%Heodo
2020-08-12B_865157964860951439651163.docdoc f9f228e552c3971983d4b5909776c052df083b9b41f65f764ceba0dc9d6219e7Virustotal results 52.54%Heodo
2020-08-12C_35224875.docdoc e95c19b3173d0c69d60efb950859b2ffd3020235efd6c47ffebddf950a0edf52n/aHeodo
2020-08-12INV_WL7913786475JS.docdoc 29a8f854081e5f20b6709851863472cd33a1863fbed4867153edf6fcc5e86dc8n/aHeodo
2020-08-12PO_08122020EX.docdoc cbb96bc7d3aebe42ae0bf197554d7224fd693a6e864fdc3bc2f7b5e466986485Virustotal results 53.33%Heodo
2020-08-12INV_PO_08122020EX.docdoc 4c3eddd6a41f348b80609e91f83e3a9e22818758105ce3db1de70777baeae682Virustotal results 50.85%Heodo
2020-08-12INV_UK7YW3UY37VH7B.docdoc 358176ae69d49cbdc29ce5f8965efe9952253949970d9de4e8f09f46c488e6ecVirustotal results 50.85%Heodo
2020-08-12DOC_97754455.docdoc b06fa4a03274712b0d1bea0d2a5d1afc2c71541acb80b1054d31b661b67514ean/aHeodo
2020-08-12Z_UVEMJU1.docdoc e4d1deaefa7f905c5ce7490867ae09ff2d50fdf4162f102e276653c1c46eeab6Virustotal results 51.61%Heodo
2020-08-11FILE_74587021.docdoc 5a95e436c4df9dfb41496c96489d1bddf6db2c7d54ccf0761eb61ef1af9c83a0Virustotal results 50.88%Heodo
2020-08-11DOC_PO_08122020EX.docdoc 896db11ae3dd47bbbdaef6de2e44964142461c89f1fd377015b96affcc75cf60Virustotal results 50.85%Heodo
2020-08-11REP_9PKLXTIMFHPKO4Z.docdoc 6ef92d63f441bea978f148ae6b93fd26d8feb4716042101e28ebacd3101f6eb1Virustotal results 51.67%Heodo
2020-08-11XARX_RU4776311851UX.docdoc 1aac25866333e7f77dc237137353a0a65ce189972d87658229eae96e3037bc68Virustotal results 51.72%Heodo
2020-08-11WPD_080120_FNP_081220.docdoc 1d09b28a4d454266d52d7d2e5b9aeab2bbf43839ec33c9a7221eafae3c28c067Virustotal results 51.67%Heodo
2020-08-11DOC_CA7438053675UD.docdoc 2adc586ea7a59715aa3226b8b211a8d39fdc6b40691c30e3a96962d2c041688dVirustotal results 52.54%Heodo
2020-08-11ONWGGHYIC1D7I.docdoc bb6e3d0f0394c94254fd90afa543277a215c6834d045f0c20aabd990cb68856dn/aHeodo
2020-08-11BAL_60251772.docdoc b9be58269c46d1dba55d08e51cf5186e5c6669171b0b96d6bf2ca5b7558af124n/aHeodo
2020-08-11LS5958312943NM.docdoc 597ed34e38d2b0c2313a9d95a421d70af23bd88d60c66de8e04f4127d425c6e3Virustotal results 50.00%Heodo
2020-08-11BAL_KU6325922346LZ.docdoc 0dc77319f898db1037b996e421c171d0ddbd13166a8b589ab1da97b8bcfc99cdVirustotal results 50.85%Heodo
2020-08-11INV_WDBV6HD0.docdoc 8ba6e22d298dc4a7b8722b5e15bfb9f8b4128d0fba504cff7fd4acd55999eba5Virustotal results 40.68%Heodo
2020-08-11G_34538904.docdoc 8e5f3490181127db4ae19a0c19a2aab3233016bcc64272ec836a68426ed0ae89n/aHeodo
2020-08-11Z_PO_08112020EX.docdoc a78bb11106ec3dc28544e1a0117cb8aeffa81a5f0f24b3bc4dd1a1f155e0feaeVirustotal results 39.34%Heodo
2020-08-11D_SO5730666049BE.docdoc 8979a7dda1fa732d2164c2ef2e8bb59471cbed0bf320309720b8c18ce4a5f673n/aHeodo
2020-08-11PO_08112020EX.docdoc f288fc67d607003c58bc277bf9c779e8d206ae43259b9cea64be737d4df22a7dVirustotal results 36.07%Heodo
2020-08-11REP_PO_08112020EX.docdoc 34d67996b2581cdd647857f3e3e696b014b5439d13108d5cbc713db42e9089cfn/aHeodo
2020-08-11D_PO_08112020EX.docdoc 91ea8ace7b370d468a6318d2ab0847a1d03897afb3a2d887794d4f35c781f34fn/aHeodo
2020-08-11REP_69563819.docdoc 5ca1aedbc7b3e63e13e3b3263321e12f1d49d668c331db20a1f996b3fd362894Virustotal results 32.20%Heodo
2020-08-11BAL_PO_08112020EX.docdoc 3cbbd9298f3b6d77456b687dba10ecf5f45614573ed3be647167c5e96ef16552n/aHeodo