URLhaus Database

You are currently viewing the URLhaus database entry for https://yuexiangw.com/yvzx/attachments/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:429651
URL: https://yuexiangw.com/yvzx/attachments/
URL Status:Offline
Host: yuexiangw.com
Date added:2020-08-11 19:43:09 UTC
Last online:2020-08-11 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-11 19:44:03 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 hours, 33 minutes Good (down since 2020-08-11 22:17:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-11RGD_ZAM_080120_BIT_081220.docdoc 6c5380e193b725ec3ea512a3146d8c0925c7c489800dad57d1b4b2f940751d22Virustotal results 52.54%Heodo
2020-08-1108399414198863863079288.docdoc ca30b2272a56997f03e6470ff7ef67a05a07abaaa5a436b29c936f7fc34e2dfaVirustotal results 50.82%Heodo
2020-08-11JG3343288672CN.docdoc cbacf0f510ec4c1a5cacd10259c0e6075f65050b602e47fc67409aefcb6af60en/aHeodo
2020-08-11BAL_KXBAQR8RH9L.docdoc 597ed34e38d2b0c2313a9d95a421d70af23bd88d60c66de8e04f4127d425c6e3Virustotal results 50.00%Heodo
2020-08-11REP_86170609.docdoc 544045a4220133bbe6fba0dc73c65a21782329649d1c4ab92cf883cc1dbae677n/aHeodo