URLhaus Database

You are currently viewing the URLhaus database entry for http://yitong888.cn/ck/swift/wokrfhm2h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434622
URL: http://yitong888.cn/ck/swift/wokrfhm2h/
URL Status:Offline
Host: yitong888.cn
Date added:2020-08-17 13:09:21 UTC
Last online:2020-09-28 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-17 13:10:03 UTC to ipas{at}cnnic[dot]cn)
Takedown time:1 month, 11 days, 13 hours, 44 minutes Bad (down since 2020-09-28 02:54:23 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19BAL_LDA_080120_ZOM_081920.docdoc 35796af9eeafddb25ff3a9497cf558acfd341dfa8bd825baaeeaf41af0069f08Virustotal results 20.69%Heodo
2020-08-19REP_MK3867X3JYYUVL0.docdoc 882600fee7e0ea4b30699f07b2c5237c9cb80b2ed0bdd471d055f7b450565272Virustotal results 46.67%Heodo
2020-08-19REP_JV0A3BCM1A.docdoc 5208e749e86ccf99bf26e6e19476798420c729533d866f386eeaea5726fad12aVirustotal results 46.67%Heodo
2020-08-18BAL_YMWWECZ9OL9.docdoc 6132d38c562ce3fd2f815bb85f961fe7be3153f058d6b86f366c69a51f65bbf8Virustotal results 42.37%Heodo
2020-08-18BAL_AADM6ZTYMQKIL170.docdoc 2db327ec6e030d7937f39cdedb6cbdbade5a89c43fbf6ff39f7c4b7299261a0dVirustotal results 40.00%Heodo
2020-08-1842349065.docdoc 58f54242a517952baf0ab77f9eba354e7f6299fc66a0a2ef3eddfbc9def3870aVirustotal results 40.00%Heodo
2020-08-181468105216861566.docdoc da237c6410295bccf15c5ae7a39cf56b4b7d46ccbeb39e9b1ae4d8c6eca20c41Virustotal results 38.98%Heodo
2020-08-18XTX_080120_QCV_081820.docdoc 0cdf898371cab59af7cc28c017f51ac0dc92223bbd9fc07325a91e964bd2fb58Virustotal results 26.67%Heodo
2020-08-18FILE_67178641696695765647.docdoc 432019576127ddaad9eb1c68d25e375d3b4d3a0982757676929e1dedbe2eba83Virustotal results 22.95%Heodo
2020-08-18BAL_PO_08182020EX.docdoc 890e6b09a956af7f75a2fddadce7b159de81fd5b13dfca677daae92a1459bd81Virustotal results 22.95%Heodo
2020-08-18BAL_PO_08182020EX.docdoc c0e32bb3934d16ab19f764e6471ad6f135e2bee38ef98451fe976f56613e0bebVirustotal results 22.03%Heodo
2020-08-18PO_08182020EX.docdoc 456510d5a40582d308f81577cbf8ae64f2b616539e4bae452df2916721b027d8Virustotal results 20.69%Heodo
2020-08-18IOZVIWFDDIW9ZMQK.docdoc bf8175beee1c42c023a5345ea192a4aa5596111fe463e747212ee6866147b1b1Virustotal results 21.67%Heodo
2020-08-18BAL_66287843.docdoc 443b1de4c1e4e8de972ff2ecf0f5dde23c3c7667e27853bd446fd5341684a15bVirustotal results 45.00%Heodo
2020-08-18INV_SOJ_080120_PMM_081820.docdoc e7e59e1fee68542ac8095f59c35cd7c88c27b60952550c64ebbc62c63a66e507n/aHeodo
2020-08-18REP_VAU_080120_UMS_081820.docdoc e3526411cd34be5871e6cf4764a353fcda9944f4ea5328a75e99090c887c4657Virustotal results 40.98%
2020-08-18REP_84000750.docdoc 5c8b923944c5816b259806159d34a3d379b2c8f347ef3b69cbc5b18f60637d93Virustotal results 41.67%Heodo
2020-08-18LD1978025521ND.docdoc 69d3f09930fcee1c934169fbf11d379163a3058c0db215c9fa09a756934ef0d2Virustotal results 42.37%Heodo
2020-08-17FILE_66106215596137520317957.docdoc 6cfd3bc71ff38c615ec9c2b54e9f7b2a878e5b34918ef26526b8d2695f04ba6eVirustotal results 42.62%Heodo
2020-08-17K_LRL_080120_ZBL_081820.docdoc 5e842e47338636cf919cf4da91f192fdee581c3e70625ca84d9ff63ab8b6a012Virustotal results 40.00%Heodo
2020-08-175239950447549950140732364.docdoc 974cee607e26fc226dc6835c3823f25a77541be94a01be3d3ffdb69afaabcdf4Virustotal results 37.29%Heodo
2020-08-17BEV_080120_KTH_081720.docdoc 2f70dfac38cad01f35e35b9af87dce14dff3cea72cbab5c9650ecb608cafa766Virustotal results 37.29% Heodo
2020-08-17BAL_PH5103223645EZ.docdoc bb8b51bb8f2d33030c1f963dd95654077beff6ce188a27f1fbf8d0fc792d03a9n/a Heodo
2020-08-17BYZY_1VV7ZNRBM.docdoc 9659bb43672c6bbb2908a60a397ec276690d9c49f02d4bab375bd933a2cab5d3n/aHeodo
2020-08-17REP_5A22O8DE6.docdoc 1f1dee1a0fde78b55c81c98efaec59d4ec92271f623428c62149cdf21af712e1Virustotal results 35.00%Heodo
2020-08-17BAL_GRN_080120_NGV_081720.docdoc 9c19784b1ba93b71935f0e3cf46fe35dd570c0a7ce4a79791351eef6946269fan/aHeodo
2020-08-17PO_08172020EX.docdoc 61ade7afc3021dfde983fdab31597cc2934ccda2012fe9ef49c985f5a52aa89dVirustotal results 25.93%Heodo
2020-08-17PO_08172020EX.docdoc 9fa1d2aba6fe973a7b0668ee385f2c1dc3a1b9db113875b9d47e46a98756ee31n/aHeodo
2020-08-17JKI6RFATZ3.docdoc fb97c4ab0046a60d20e5ae58c4fc426053c1c168d24495e1463765c194272238n/aHeodo
2020-08-17PO_08172020EX.docdoc 84ccb7dd64a2a08a9be41050698b514edd4b7b2360f42a6342f4960977bccdc5n/aHeodo
2020-08-1740035504.docdoc 82484f937d447414a0d20f7ddebadad675608fa009f2a255712cac5dcd93f39dVirustotal results 22.03%Heodo