URLhaus Database

You are currently viewing the URLhaus database entry for http://jkshaonv.com/wp-admin/cg1-70urc-761/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:430532
URL: http://jkshaonv.com/wp-admin/cg1-70urc-761/
URL Status:flame Online (spreading malware for 5 years, 4 months, 4 days, 17 hours, 5 minutes)
Host: jkshaonv.com
Date added:2020-08-12 15:09:09 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2025-04-30 01:41:09 UTC to abusepoc{at}afrinic[dot]net)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-08-1124c1788b89f1eb6e216edfea0e93836c4a6f69adfd6a402b0cb9271280987d0c.jsjs 24c1788b89f1eb6e216edfea0e93836c4a6f69adfd6a402b0cb9271280987d0cn/a 
2025-04-30c448ad4f02d8dff98b400a50b43237c890d2aa6e40c71def98ea2f9ae352fb7c.jsjs c448ad4f02d8dff98b400a50b43237c890d2aa6e40c71def98ea2f9ae352fb7cn/a 
2020-08-14Invoice IKVF873 249512.docdoc c6f5ca51538e073cc5ede1d36d9778a58042583bbe61be6a26a0cc4367b56a4dVirustotal results 23.33%Heodo
2020-08-14invoice ZWOL96 8425454.docdoc b873855abe6ecb687a4df753ed5f4882475ca551c53ffc20ef18b3c896115a91Virustotal results 23.33%Heodo
2020-08-14INVOICE-REJ393-839412.docdoc 27db24afe51c643a809e559c190b96146022ef6d3394b8e990c6eee4bb9846acVirustotal results 40.68%Heodo
2020-08-14Inv-PJB804-8520062.docdoc 538aec1c87a88d78a75a417c253579be5fa18cefce592109122505cf70f2eea9Virustotal results 40.68%Heodo
2020-08-14Invoice_OITH0_803778977.docdoc fb17807621969c33d345882ad5ae95cd5294c32509e13a6fe8ce1d317a5c3f4dVirustotal results 38.60% Heodo
2020-08-14Inv_X8_7873449.docdoc c32ebf07a4f2324cc33cf6e7c975c375621c519fa654fc27303c9a812293fd7fVirustotal results 39.66%Heodo
2020-08-14INVOICETOOY806838090.docdoc 382eeb05e0b37509916697e88d5f58e00cfd17db07cf9b27240fd84aa4bcd26eVirustotal results 40.00%Heodo
2020-08-14invoice-WZ180-2842626.docdoc d77766273a903661def8286676499fd3cf8f2a337cd8fa867e5788e5509db0e6Virustotal results 40.00%Heodo
2020-08-14invoice LJE72 166168.docdoc c257cd4e52104d35aad4c65319a54abf3cbea3929e1fd295bff5fe422409618eVirustotal results 38.98%Heodo
2020-08-14INVOICE-Q7665-6471712.docdoc 2da551517d3d24f3485bb7c1edd4dc79031582d5cc3f4066169ecdbe26b4df18Virustotal results 36.67%Heodo
2020-08-14Inv-LQA3504-886452388.docdoc 5b5e18fb115c6b3ac31082a0b3d864e051d30cac7f5a27ce29d97c3deed87a5en/aHeodo
2020-08-14Invoice-ZB75-711232.docdoc b912946f86e61acf37130b179be53f6dfa2fdd31fa0e158dd2fd19f557aaf059Virustotal results 36.67%Heodo
2020-08-14Invoice VZH0602 704346620.docdoc 4398bc31070f761b318b30f297d363b006ed9e84c6af0aa45ad140f57e7c1529Virustotal results 37.29%Heodo
2020-08-14invoice-CVTB028-5003818.docdoc e8516c23d1aec8faadd52ae68fd240339940d05f4a1db7c56afdbec1eb5de0f6Virustotal results 37.70%Heodo
2020-08-13Inv-TOP4-96472093.docdoc f9d386ef77ac7b75fa5d24fedcf07b054c6e35682826e1a38a6e908dc8c77e10Virustotal results 38.33%Heodo
2020-08-13INVOICE_75_290662944.docdoc 2741a0a45d8bb8b7e1fa15f9f05492ec1235fcf882792971e1668640ae40fbb9Virustotal results 36.67%Heodo
2020-08-13invoice 1388 373149471.docdoc 02002790f4d5801feba9f00836aa82e8762db15f9dbe6f7aa8b7ab84b661c284Virustotal results 35.59%Heodo
2020-08-13INVOICECJ62210570844.docdoc ff68f4adbb2d5f421b94ec8c2ca343c8dc807544237928a2617bb4c1dd32b7b8Virustotal results 36.67%Heodo
2020-08-13INVOICE_ZPBY75_8117014.docdoc ab444b6b4e01751a504bcbe5bfafccb6c73c5a8f0a83102badfdfa7f0d061be7Virustotal results 35.00%Heodo
2020-08-13invoice R7014 2513350.docdoc 49d66f1859784a289e46f5690a521c15cb397cb29ad8db6882806c03628a4b97Virustotal results 35.59%Heodo
2020-08-13Inv-8836-52719744.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13Invoice-AMA85-248383.docdoc 294443b3b8e68154544b8f501310b598b2925bc108c42f5a30bccfa9598b6782Virustotal results 35.00%Heodo
2020-08-13INVOICE_YWWJ751_50473265.docdoc 1f57bfffafbbddf246e071774ef4975de31cc8a7e0fc15192cf360c0fe218174Virustotal results 36.67%Heodo
2020-08-13INVOICE 5809 986226.docdoc 775c7f80738784b0ea5e971bb618159e93970f0eeef8b80612dde5e1d76c953fVirustotal results 35.00%Heodo
2020-08-13invoiceHXH28388603.docdoc da66414b758cec9e59a4d246d1a01e3339644d5be305c6447ddaf0f65900db71Virustotal results 30.51%Heodo
2020-08-13Invoice_RDE6_893631.docdoc 7e058242f7a064bad48c7b7a1e45ebabdb59903cabf069d79e145c9edd2408fcVirustotal results 31.67%Heodo
2020-08-13INVOICE_PXE62_75179011.docdoc 196a89c54cda70af31877740ead0a738ead3533d3ef89e87e31b193044fb42f7Virustotal results 31.67%Heodo
2020-08-13INVOICE-QSTH79-369602.docdoc fca1b080bd37f31310426e23e3d06dff66c14e54fdc049af8896fd4970ea29c5Virustotal results 31.67%Heodo
2020-08-13INVOICE_108_971478.docdoc a9daa1f1f97ea5d02fc81e34cbab89ca25f94540d2fb3506f7339f3398470d67Virustotal results 29.51%Heodo
2020-08-13invoiceK4774290610.docdoc b8a573213c36923b03e13902ca78fa55cd62d801d34fc7f5ecaf692f7b68482cVirustotal results 28.33%Heodo
2020-08-13INVOICE OA80 821026848.docdoc fee712637002c8475f30aa70617736faec255bed242c89f24aaba602691101a5Virustotal results 29.51%Heodo
2020-08-13invoice-Q9199-793747761.docdoc 52c981dcee0a9c0bc80ec192b453e8af6b01ced6cb3187645687ad0fd1b13221Virustotal results 27.87%Heodo
2020-08-13Inv-8807-584980027.docdoc 06166b3489e6b1ba8b3b7abbedf9fa72a55fc82e560c856df36cc781c2470e4bVirustotal results 26.67%Heodo
2020-08-13invoice_2_0038347.docdoc bf2332d7bb2fe3a48644b9436beaccf7cc4015b5954d8d012f2b095e21023629Virustotal results 26.67%Heodo
2020-08-13invoice-1-2082000.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13invoice-DH546-18846023.docdoc d2cc4f61f498dbddde048bbb918416d73f063a0bb46c960ab7fd6fe671ed9bd1Virustotal results 25.42%Heodo
2020-08-13Invoice5567611688.docdoc 780339401d94d888dd79a9d81b94ead083dc9070649cdf2e72eb3a6a78eb45d8Virustotal results 26.67%Heodo
2020-08-13Invoice-YW3917-736795.docdoc c6448d3ae149d4be02cc47863725d1c6422455e424cc378cc755ada5109d76c7Virustotal results 26.67%Heodo
2020-08-13INVOICE-FEYJ2-56408517.docdoc 8d3707b8799040b4d0ae3452f01c096d3658cb6636834e49f602c9f745ccd6edVirustotal results 26.92%Heodo
2020-08-13INVOICE-FEYJ2-56408517.docdoc 8d3707b8799040b4d0ae3452f01c096d3658cb6636834e49f602c9f745ccd6edVirustotal results 26.92%Heodo
2020-08-13Invoice_H9_7793937.docdoc 24fe0e4704e8906e4819aaf88915317509beef8a6bd0abc3c4933cd0d75b7084Virustotal results 26.67%Heodo
2020-08-13Inv299744063883.docdoc 642f6238f4c26f7e8829b4739309809c5b2ec80f58e0beb4df4cbfdfd8ebe42aVirustotal results 25.42%Heodo
2020-08-13INVOICE-FK5043-7277640.docdoc cdb381f78364b3a519d51aa70490c2a66f26062664a172c82b15f14a70297bb2Virustotal results 25.86%Heodo
2020-08-13Inv_NHTS1_365037494.docdoc 5478e4974b64a8471ba220eb079a7dec82a9ceba893c8d56e165235a8df47f25Virustotal results 25.42%Heodo
2020-08-13INVOICE X5966 723773.docdoc e1b7a11726c385bcad71dfe791b165802cc625ceaf2f1550a5a10f5f222ea90dVirustotal results 51.67%Heodo
2020-08-13Invoice ON2 49214650.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13invoice CSJS2881 656325560.docdoc 3d1521d09be3ee5bbbc9968469250a27e97da18cb8dc7ec8bd9d211bdb683830Virustotal results 53.33%Heodo
2020-08-13invoice-HNJ026-676306763.docdoc 17b6049e45eaf5263f576de1799a8b8ccd0164f7e1241cf72738d56e8793458aVirustotal results 53.33%Heodo
2020-08-13Invoice V2733 2257380.docdoc 015990746f332cc1ad898d46ef3de53f4ffc95d723ccd19bea5fc12b95f86b47n/aHeodo
2020-08-13INVOICE-7554-137607.docdoc fb04bcaffc6328a8a16308df4ecbcf2ab1099b8c1dd14c443590f8bbad856fb7Virustotal results 53.33%Heodo
2020-08-13invoice_LU3_291392686.docdoc ee1f5c8ab512406824b28cd257477afae1af144286ddd585d142664b10b2ec77Virustotal results 50.85%Heodo
2020-08-12Inv-LXTZ897-428164.docdoc 5fd1794cc1e685dfa2a1e2594b10d690a59a070a9b8bc9c6c12743efb989137bn/aHeodo
2020-08-12Invoice H7 519554.docdoc e412c6a1097b6fdf1492ad40805d0bbb1df005f870085f3fcb57d30552974cdbVirustotal results 48.33%Heodo
2020-08-12invoice-V02-69531122.docdoc 92dfce0e83a09bacf5d1ce00c4ef5c7bd7c35bbb27742bc01060cb96511f8156Virustotal results 49.15%Heodo
2020-08-12Invoice_RAPW8988_7770921.docdoc 5d53ea1eda34e3d47f8a388a248005f39d237681eea6f3155e21220b373429f9Virustotal results 50.00%Heodo
2020-08-12Invoice-DOM1967-587197.docdoc da25968d18d6c8ddfd6ffa940b4e0bc6809a5b1a224602f196ce7eb107578f88n/aHeodo
2020-08-12INVOICE-6-336947367.docdoc d9ec148861bca868b82455ef1a50c34c46fd0e3ad7f337803a67c5eb67fd8469Virustotal results 49.18%Heodo
2020-08-12Invoice-RTXV54-032143441.docdoc ff563f0125c05e1a24c111ca5306fc7394a4a705167d272704bb0c2067a96b4fn/aHeodo
2020-08-12invoice SPG967 239384.docdoc 87a59fdf7ab0abb1c6263fc0c53650659aa5c3d50d09d38c6696819017787e38n/aHeodo
2020-08-12INVOICE D03 7891737.docdoc bbf084bcd83d08a6693798f851e3af34cc7c303afb235c8c25fe237ec00315cbVirustotal results 48.33%Heodo
2020-08-12INVOICE-HKIK0401-6057086.docdoc 45a8de935419a54875afce7f3862e01a00c5bdce06bf494ccb53a16a022f6bc1Virustotal results 46.67%Heodo
2020-08-12Inv-YNB9450-17777054.docdoc 79ada6c652264a8bf701b99a922fae42a4965fa95c5117d73c9d6942028cf07aVirustotal results 43.10%Heodo
2020-08-12INVOICE YPW025 93060621.docdoc 37a1c85950d3e91662ed4137488030ffcec13adad6f9b2f3eea1de01a756b260Virustotal results 41.67%Heodo
2020-08-12Inv-TL14-1106106.docdoc 73dbd3589e2d0ca8f9f663da4f527cb110e5e29ce81026ff99cb0a24048fabc5n/aHeodo
2020-08-12Inv_QX7605_416496237.docdoc b2699f3cd54b6953a3eb9e1812890cf40563699a96776cfacd8f81288e962e11Virustotal results 31.67%Heodo
2020-08-12INVOICE-C6084-9554920.docdoc 55eaa0f085e7e905c6ab2b43f308133901f482713c0cecbaf1f66c34c0bc060cVirustotal results 30.00%Heodo