URLhaus Database

You are currently viewing the URLhaus database entry for https://hftk.ccc.edu.hk/wp-content/kxwHhWN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430536
URL: https://hftk.ccc.edu.hk/wp-content/kxwHhWN/
URL Status:Offline
Host: hftk.ccc.edu.hk
Date added:2020-08-12 15:09:49 UTC
Last online:2020-08-15 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 15:10:11 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:2 days, 17 hours, 22 minutes Poor (down since 2020-08-15 08:33:00 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14invoiceT080801498.docdoc 275360394b82d7c9bcc73920c9b0182be30090a6506c970fd3c7fed11cf75764Virustotal results 28.33%Heodo
2020-08-14Inv-WNDV692-034082.docdoc 4935ab1182453885ea821cc714b1679ae7eeb54bb744fe13f52ad6e954a7f785Virustotal results 25.00%Heodo
2020-08-14Inv233144742.docdoc 946ce7bab4b96c0fd40f3bb134b7d616880bc04dc8eacdf9d4cf10f4c0287cb5Virustotal results 26.23%Heodo
2020-08-14INVOICE-7-23786075.docdoc 6969c9659df92d53fbfae853c8c208cb0e09fc6acf7dce23773cb66cd060294dVirustotal results 26.67%Heodo
2020-08-14Inv-TFG543-060036993.docdoc 7dc64cdcabade0fe1b2cccc83c3a256efb0de22bbc1e8b17a072104e393b3b26Virustotal results 25.00%Heodo
2020-08-14invoiceYATO278567842.docdoc 31fd17ea13411b2b4c8a726012b7e3390527519bfcb805d9d895877a627c8f7eVirustotal results 26.23%Heodo
2020-08-14Invoice BP4 395012227.docdoc 293c5df488141cb4aaa3c1d4e450c5f3fce9c1b3ff26d587b42c17d6a05758b2Virustotal results 26.23%Heodo
2020-08-14Inv-VLUQ0956-0334007.docdoc 0bd1c09908f6c09ae5217b631f5041669b722d5961f9471365b074d51d9a7a36Virustotal results 23.73%Heodo
2020-08-14invoice LGQ912 331793.docdoc 0aeb7a7ccd5f0a664f6955eaf500b29020c82c40acd8b9d14cff49c6a9377f72Virustotal results 25.00%Heodo
2020-08-14Invoice-PQ6-6658283.docdoc 2a7342691538ac359f25d6ccd05e6b81f64ea3dfb5fe8af5f23eb3f3425a056aVirustotal results 23.73%Heodo
2020-08-14InvN67071186.docdoc 825617f8a3ad347433be07250c2c043f504c413cfbc31739029208f4af30fc57Virustotal results 25.00%Heodo
2020-08-14invoice-MFX8-234033955.docdoc 8aa7b26f53f2ebc1a1678bb6f61704527478b875e9c4947c3193d966f0664efbVirustotal results 23.33%Heodo
2020-08-14invoice 41 873492.docdoc 0c8f2829aa051a5e6c46de5538877492af65802d40d49435dccb05882ec52308Virustotal results 40.00%Heodo
2020-08-14invoiceZLE948125530.docdoc e64e43f9549144dcb8e091b5d2140499702e699e14f019192575a50ce08d323eVirustotal results 41.07%Heodo
2020-08-14Invoice_AF5_592649062.docdoc 99dac5a117859eb23edb38d2da4b792d02b4a4d1fab2249bc171faf6bf1dfda9Virustotal results 40.00% Heodo
2020-08-14Invoice-D7-173761156.docdoc 854fcd9b34f74cfd7956a1bfd5de137afaa0c79aa3e1e80ccc4f87410e0e6159Virustotal results 40.00%Heodo
2020-08-14InvoiceZN344288513360.docdoc d77766273a903661def8286676499fd3cf8f2a337cd8fa867e5788e5509db0e6Virustotal results 40.00%Heodo
2020-08-14Invoice-KK0-191541.docdoc c257cd4e52104d35aad4c65319a54abf3cbea3929e1fd295bff5fe422409618eVirustotal results 38.98%Heodo
2020-08-14Inv_H9495_510963718.docdoc 167459762dfa748a07ae8e4d2479e9733ad4d66e0d833453daa2038e833efa29Virustotal results 38.33%Heodo
2020-08-14Invoice V8818 829366163.docdoc 0b134d91d537beab9f4e700b126eb1b43b69c80126818592cef4697fce08263bVirustotal results 38.33%Heodo
2020-08-14invoicePVLS3594076466.docdoc 2879a9d705300779c0269f3a6847fb725a3564c7ae27f44226fe17f422474ca3Virustotal results 36.67%Heodo
2020-08-14Invoice-TFC055-2133438.docdoc e8516c23d1aec8faadd52ae68fd240339940d05f4a1db7c56afdbec1eb5de0f6Virustotal results 37.70%Heodo
2020-08-13Invoice-EEVX58-5663591.docdoc 3c2103ec1e6af0ce039524d58d70a4ced5e2845549def894d03f836978afa09dVirustotal results 38.98%Heodo
2020-08-13invoice VABH351 65464332.docdoc 5f082300c48965f84f8c991027f6081c4397825021b74021b253c7fc7e9dd5b3Virustotal results 35.00%Heodo
2020-08-13invoice_TV0069_4469019.docdoc 2700c5a0f48e93d064b77b0179fc337d59ed7d100dcdfa5f29c2f1d035e03204Virustotal results 36.07%Heodo
2020-08-13invoiceJ78458583431.docdoc 345ad176e1abe5bab4a7665cb4b35fda3bac70a3cb1207f3b663d77550e197f6Virustotal results 35.59%Heodo
2020-08-13Inv-QVD017-7855135.docdoc 9790de78c7614b7690b8f35d421b7704eb89e5eb5cabfe24dcf83485d90e2949Virustotal results 36.21%Heodo
2020-08-13INVOICE 85 6415833.docdoc 5afd28f4c27929a5271720ade77b26422b7596600473f76d9aca778869203bacVirustotal results 36.21%Heodo
2020-08-13INVOICEWC797763565118.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13Inv-M3-81601572.docdoc 294443b3b8e68154544b8f501310b598b2925bc108c42f5a30bccfa9598b6782Virustotal results 35.00%Heodo
2020-08-13INVOICE 20 891268537.docdoc a0174ce27bcb676191641c4b06722c67732d37458580fcda2aca969593f838d9Virustotal results 35.00%Heodo
2020-08-13Inv_Q8_891240.docdoc 7f84ffec8d67c90cf874b1c63419a909e57b6e610d050a800bccfef7de037607Virustotal results 37.29%Heodo
2020-08-13Inv PY6214 793178607.docdoc a430b79aa886bc228b8aedcfd295bfdd9f860f814ddfefd8839d8c2159e24049Virustotal results 33.33%Heodo
2020-08-13InvZ4978181364.docdoc 82b0468b8277859b0d4bff3af6eff0d446bbba4daa11cb4d96b62160bb22e3cfVirustotal results 33.33%Heodo
2020-08-13Invoice-PRK14-268011835.docdoc 1344d4ea858a94b81b25c9c85ca54dabf55f7ac242bd4e4a9eaeb991ba75fc4dVirustotal results 31.67%Heodo
2020-08-13invoiceNAVN925479271972.docdoc fca1b080bd37f31310426e23e3d06dff66c14e54fdc049af8896fd4970ea29c5Virustotal results 31.67%Heodo
2020-08-13Invoice WXO07 5437618.docdoc 7d4ee38f224a7af8f2988087cb32ba596f3e914f876a03f7b51b3d68c0832e43Virustotal results 30.00%Heodo
2020-08-13INVOICE-WLYW7705-240444.docdoc e2b52ca08d4008fa9685112c5dfd20fcc5fb9d70c23426f9a30404ece51ca0d1Virustotal results 28.33%Heodo
2020-08-13invoice_01_52010379.docdoc 4bd0be911a687ec4b5a5cbb2e2fefd2756af0764a5360ecdb90bbde1dbd3dfd2Virustotal results 29.51%Heodo
2020-08-13INVOICE-2-812190449.docdoc f029a391648b1fe61978c79aa2a2c7783ff27cdded15c30ce648421693898e2cVirustotal results 26.67%Heodo
2020-08-13Invoice_GHBG50_0727783.docdoc 1891c9a4d06b02d38d12e504d36af168594a2c9a5dad8ee47996b3fd99f15eebVirustotal results 26.67%Heodo
2020-08-13invoice-BSK57-3011767.docdoc 7689a27b894cae744cbcc6233ee883c95f92853ce314becca2b0eb1428689c49Virustotal results 27.12%Heodo
2020-08-13invoice K1 045057.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13INVOICE_SU93_06551877.docdoc ff88b58cda20861bb4defc057fd5c5b094705648918b08fcb53f7433a53ff7e2Virustotal results 24.59%Heodo
2020-08-13Invoice SD56 207398934.docdoc 906423a8a219d85fee1c58feac18a6bc8689504a672ec96d5df2e61079f60672Virustotal results 25.42%Heodo
2020-08-13invoice-2734-5935626.docdoc 225e48d5a2210f48804a4463a7c970cb9d79f88b8ca085b379ec5bf95f671b01Virustotal results 25.00%Heodo
2020-08-13Invoice-X2531-7375006.docdoc e9fe379c503723a5883c5b4b3e4227a3a35c0fd4cec4716f859a2f981f6eb732Virustotal results 26.23%Heodo
2020-08-13Invoice-X2531-7375006.docdoc e9fe379c503723a5883c5b4b3e4227a3a35c0fd4cec4716f859a2f981f6eb732Virustotal results 26.23%Heodo
2020-08-13INVOICE PHIC69 026378127.docdoc d72f36fa492b648c515c4246b7072da043def4709a7e99d87d3a2aa447fb6f2bVirustotal results 26.67%Heodo
2020-08-13INVOICE_FKN944_702593.docdoc 620d84fae4b584f528eb0044177ac950380d8c41d764dc1615871a80ecdc4ae7Virustotal results 25.00%Heodo
2020-08-13invoice_893_40057254.docdoc 27d0c48e8224b8b6607cefeec92b1672e7d61628e58bf2574cb30f1fc9518d2fn/aHeodo
2020-08-13Inv QEDE82 40158393.docdoc 5478e4974b64a8471ba220eb079a7dec82a9ceba893c8d56e165235a8df47f25Virustotal results 25.42%Heodo
2020-08-13Invoice-64-5746920.docdoc e1b7a11726c385bcad71dfe791b165802cc625ceaf2f1550a5a10f5f222ea90dVirustotal results 51.67%Heodo
2020-08-13INVOICE-YLU0-675619742.docdoc 10531f315432369a9c0706bc00ac1405445316044a9ec07b03de6606a6a9f9fbVirustotal results 55.00%Heodo
2020-08-13INVOICE628641351.docdoc de63eeb9f1015ea52b0e1a4d4698d706634a985366000085cfc06c5295b0d165n/aHeodo
2020-08-13Invoice-R2-4875256.docdoc 17b6049e45eaf5263f576de1799a8b8ccd0164f7e1241cf72738d56e8793458aVirustotal results 53.33%Heodo
2020-08-13InvoiceLI76332634646.docdoc bd379f0e0dcc9c8c75d70a99df9f95dc56d70fd92cbf446a21dcb7b22ded59f9Virustotal results 53.33%Heodo
2020-08-13INVOICE SBWS5548 909566.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13Inv 33 945401.docdoc e26bbe184e43c8251aee307aa6d392971f7facdda4ce50f9733a966dc7905ff2n/aHeodo
2020-08-12Invoice_5327_622408.docdoc f0c882d52064e9965202bcad61de9663457c9564ab432b3a009de74238d21346Virustotal results 50.00%Heodo
2020-08-12invoice FN3 728867.docdoc 9b5d7e0c6ce7b00011f1c9fa7157bded3963629b18e4b79469bb62c84e80a312Virustotal results 51.67%Heodo
2020-08-12Inv-T313-690002386.docdoc 92dfce0e83a09bacf5d1ce00c4ef5c7bd7c35bbb27742bc01060cb96511f8156Virustotal results 49.15%Heodo
2020-08-12Invoice 52 1420429.docdoc 5d53ea1eda34e3d47f8a388a248005f39d237681eea6f3155e21220b373429f9Virustotal results 50.00%Heodo
2020-08-12invoice-OPSL0-51886012.docdoc 24b41c6091602c0f9df9cc64905ce9dac977a04f700ae0607de467c101a093dcVirustotal results 49.15%Heodo
2020-08-12Invoice 36 670125576.docdoc dcf6cf67d57ff33b739c350fbd55c6b1ff49cb1143ce9da5a6b91bed3c9acdc5n/aHeodo
2020-08-12InvNYQF11411398.docdoc 1258569a650076330f8482febf678459beb6690d24b1e9e65d10389f6d641e8bVirustotal results 49.15%Heodo
2020-08-12invoiceQC0400646052.docdoc d1ce5170f24fdb09f187ca0e3e0f6e689fa2c73fc6953ff18ecc123bb8eed49cVirustotal results 50.00%Heodo
2020-08-12INVOICE-867-148947.docdoc 95fe4603a20fce976fa2b80fe19e89a3a8f0df85029a1cfbc4a05990aaa78a3en/aHeodo
2020-08-12Inv UMK9858 442747380.docdoc 7cb03d988c912a877410fe03d55bdc4a5379a95e91ff6497875a139105f2cfdan/aHeodo
2020-08-12Inv_F157_33311306.docdoc 83c31b7444f936473f6993e44e8cee3c26b1a4c6c691d33f85e9a0b0389c8a7fn/aHeodo
2020-08-12Inv-FZDG43-2093699.docdoc 37a1c85950d3e91662ed4137488030ffcec13adad6f9b2f3eea1de01a756b260Virustotal results 41.67%Heodo
2020-08-12INVOICE_TQ393_983958552.docdoc 73dbd3589e2d0ca8f9f663da4f527cb110e5e29ce81026ff99cb0a24048fabc5n/aHeodo
2020-08-12invoice-3150-912352.docdoc 3f5261f4d28c39abec2986a50be9436202150bee5188fda8a1d52e186a7423caVirustotal results 32.79%Heodo
2020-08-12Invoice_YUA463_432062.docdoc 742ca255c3695ab5ede04269aa36aa0ae82b7279c2c85fe147da3f90815dba3cn/aHeodo