URLhaus Database

You are currently viewing the URLhaus database entry for http://zgtaiji.com/uc_client/open_49852151641_Fo83xvaF9XFufCn/guarded_cloud/PT2O9_Kr3t6Iwahb7r53/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434746
URL: http://zgtaiji.com/uc_client/open_49852151641_Fo83xvaF9XFufCn/guarded_cloud/PT2O9_Kr3t6Iwahb7r53/
URL Status:Offline
Host: zgtaiji.com
Date added:2020-08-17 16:36:27 UTC
Last online:2020-09-19 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-17 16:38:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 month, 2 days, 21 hours, 45 minutes Bad (down since 2020-09-19 14:23:06 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19mes_20200819_EOV233.docdoc 50599ec6a36b32abe685c7917ae4c5eaeab50db0b59311a50f24d9b2b7366c4aVirustotal results 20.00%Heodo
2020-08-19Doc ZJ941.docdoc f089aaa465591c3bda52688c4f998d141107fcbd15cb723c4f961386e2c8bb58Virustotal results 20.00%Heodo
2020-08-19ARC.docdoc f3aa1b3aa9d42328b931f89bf0ead8cf73a1549f9352f8ec840283be88e758f0Virustotal results 21.43%Heodo
2020-08-19Inf 20200819.docdoc 1e1bd9b8516ba6602eafeeb65a0fd430014d63b18bb637cc352f7f55ccd80332n/aHeodo
2020-08-19File-40310.docdoc 124ae2447478f4b71404f5f07ea89abe4b985e402955ebcd02fb67b27939de31Virustotal results 19.30%Heodo
2020-08-19DAT-20200819-KE024487.docdoc 8b3f4fadba7e503156606666e368e036a99962c1a2a7e3929067e86d385df235Virustotal results 20.00%Heodo
2020-08-19Dat_2020_08_19_6064.docdoc 5ea25ae96dc619098cb941050217ceafa7413f64b4e57fbe6839c8a4a56f27e9Virustotal results 18.64%Heodo
2020-08-19Arc_77276.docdoc a834eee056511d26145abd3184681bc4afaf44e4d370bf83d950e66751704ea5Virustotal results 17.54%Heodo
2020-08-19Inf 5259848.docdoc 4f1f186c9993f7a0816cf46d8aaafd5057718ca9b9102e98fb12fe2c2ea1bb24Virustotal results 18.33%Heodo
2020-08-19List-P319.docdoc 2ba9e7e84b705ed936a7ef2b3e1b098055150c0c512adf5630f5a43b364c0cfaVirustotal results 18.33%Heodo
2020-08-19inf 698250.docdoc efefb13f4f10cbe61192d1e07a8c0a3b8c510b0775b4f5d73a522ea8a19fa1dfVirustotal results 18.33%Heodo
2020-08-19List-77570.docdoc 87a90ac40158e53a2309863a8bebfe1218f13262f87b93db76e5fc79ed1c388eVirustotal results 18.33%Heodo
2020-08-19REP_2020_08_19_3094301.docdoc ec8c0018d55b35c18e17e06c15691612b7f16387e0d4550e9be8dacc3c150d24Virustotal results 18.33%Heodo
2020-08-19INF 20200819 06106.docdoc 923e30675c7bd675c77d1dfdfc58295984d6cf5e3e06a0eb1cf175c3839804ccVirustotal results 18.33%Heodo
2020-08-19REP-2020_08_19-E047.docdoc d854741ed5301c0c1c91902f29edc9e823fe1f656c5f9c1610fdc19ae1c29059Virustotal results 18.33%Heodo
2020-08-19inf-2020_08_19-0260.docdoc 7bf519b79d25cfda553295f5249aec90f7d5faa6374eca5930118e0bc0a59666Virustotal results 18.33%Heodo
2020-08-19INF 2020_08_19 0827419.docdoc e539186195154e173115f68e790dac9a32909a8c4344a387ce25fba6fbf55d27Virustotal results 18.33%Heodo
2020-08-19file-45364.docdoc 81513b7cda31deaee14e3b4fea67a185c9bdeeb1528445479e77f675d96f314fVirustotal results 18.64%Heodo
2020-08-19Doc XBP66671.docdoc 568b22f1a6fb077fd3828a09858b4bcd8401325c01f2aed85b3a39e12777cb35Virustotal results 18.64%Heodo
2020-08-19INF_2020_08_19_U7253.docdoc 82b2463c462ac62073f95ada6f8aa70c265d0d7ca216a36322994f2d464bda58Virustotal results 20.00%Heodo
2020-08-19Inf 159843.docdoc 73c25deb64cab8ea8dca4171b122f978e179caf6cceb19884892f21668bd7695Virustotal results 20.00%Heodo
2020-08-19Rep_2020_08_19_7372573.docdoc da820b108be2808d9d5d1909a3d8683f33f902abe5ae4e5e319d6aa766aba61dVirustotal results 47.46%Heodo
2020-08-19Mes_7222.docdoc a09fb497ce5738081489fafa343ed354128eba16cc5f8f6bfbb26ff79e19ceebVirustotal results 47.46%Heodo
2020-08-19dat_KK732298.docdoc 1c98753feb43790bf0b2979ae0d73c4760638ab1d9c5d6b6336ce2241ba31aa4Virustotal results 45.76%Heodo
2020-08-19Arc 2020_08_19 X781103.docdoc 06cad41d0787e562a96ad8958e26b1f207b90cdf231201faa801225a7a259256Virustotal results 47.46%Heodo
2020-08-19list_2020_08_19_SFD3269.docdoc 4d3b86d9dc87fa84b6283d3c9ef68a508bd41eb8f2930650cecf08f2ae86c2b3Virustotal results 47.46%Heodo
2020-08-19arc-2020_08_19-320561.docdoc cc8e1c8be741f1f4185f8e0c64663644af9b6364554ada9ed521f37659373c22Virustotal results 47.46%Heodo
2020-08-19LIST_20200819_118.docdoc af3f70492545cd6391ad67cedb9347c9e78980d2462b1b1a6b656113d246e010Virustotal results 46.67%Heodo
2020-08-19Mes-20200819-ZXK94737.docdoc 8ecfd0e0dbd4257b0b0f97f99517f9d1d825e32d7862b1ceb1b6bfdc67b205a0Virustotal results 45.76%Heodo
2020-08-19file 20200819.docdoc 18f11f7da4047a7e2c9542c22edd449478756a5225bd21a18d0bd1720369ab6fVirustotal results 47.46%Heodo
2020-08-19Rep 2020_08_19 G7001.docdoc 5194005835c1f487f14f03ea67a9300ad9821c5d0922e5549321d2629448f630Virustotal results 46.67%Heodo
2020-08-19mes_20200819_070139.docdoc bed0745c35c33e15125967c2bd9523522638c0a7e10d38d2d100097a5767941bVirustotal results 45.00%Heodo
2020-08-19LIST I793542.docdoc e94bbfc806ca8e6182447d1f10e43d213e234887abec37e993057a77a51e3132Virustotal results 45.00%Heodo
2020-08-19Inf_2020_08_19_4418.docdoc 563a3c798199fa7da950162b8e2321eaef397d5b33260ab029cc3e537d43e0a7Virustotal results 47.46%Heodo
2020-08-19Dat_2020_08_19_NO319779.docdoc 04f5fb6798ce3949fb5191ed7c89dfc725231489c34bf2369d98e5228a6efcdeVirustotal results 46.67%Heodo
2020-08-19MES_5262.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19arc_9533.docdoc 5df568ab274842e91a3f5717af61fdbe6827249fc71e135fdc493f5177ccac7aVirustotal results 46.67%Heodo
2020-08-18inf 20200819.docdoc 5644494f53e0f58e39e8c623b06d33e093d920e7728632366beaa74ce3ce75a2Virustotal results 43.33%Heodo
2020-08-18INF_20200819.docdoc 85d051184c78737bf858c74a6fe5cbf9d30ed82b3ace8cad4b7555c5132cb11eVirustotal results 44.07%Heodo
2020-08-18MES 2020_08_19 9785.docdoc f382710578f3df562db77ea613a75d9485ab315f7f8b7e5aa86e8120a0f0bf6dVirustotal results 43.33%Heodo
2020-08-18doc_20200819_400821.docdoc 91abaab1b3daa4a4dfe3d6c8adf5c5c8f0ec0551c271417fffd61444cbf47346Virustotal results 44.26%Heodo
2020-08-18dat 20200819 QUK8074.docdoc 1a586ed406130c0ed7d070f24ccb79ee1b6f0b4a3f47373cfa6285ed1ee322b9Virustotal results 43.33%Heodo
2020-08-18mes_20200818_VK51283.docdoc f4b06b5878e6216de2fd744371e3da706006cd0eaab9952e028ed23bdb5b89d6Virustotal results 43.10%Heodo
2020-08-18dat_2020_08_18_HE42139.docdoc 38a85f6b82ce5d88a70ee0bc98517b5d3d4f82516e1532a0085c7c843310e350Virustotal results 45.00%Heodo
2020-08-18File_83716.docdoc 8eff0446f444542435bf1ea66d34ac5b2339a87d7702ba744f403dc5ec5d4795Virustotal results 44.07%Heodo
2020-08-18FILE_OM50921.docdoc bdd85a761fef4dd714c4096940648eef52aebea82be3d8c91c0fb5842405f6cfVirustotal results 45.00%Heodo
2020-08-18Mes_2020_08_18_G57635.docdoc 119e31c97f1254759e57ac901452c408e74c094919190ae94625b5e5a40312e3Virustotal results 43.33%Heodo
2020-08-18File 20200818 M532.docdoc 0b363d06eef3483aa25d2de2db90bbc7f005cdff8f14bcbd6f44f29676696a5bVirustotal results 38.33%Heodo
2020-08-18dat-2020_08_18-O34762.docdoc 2af8e0d9f601133746f53366680ef4bd22872cabc196bea282f11858e3e8b246Virustotal results 38.98%Heodo
2020-08-18REP 2020_08_18 242950.docdoc cae4e9249f1219782d6c234dc44eab63930830f75ab90f4d533f0ddd3bacb745n/aHeodo
2020-08-18dat_2020_08_18_40246.docdoc 93114977eaae46aa265bdd2918d70cdbaf292177875098c8e3f52bb992f719a1Virustotal results 37.29%Heodo
2020-08-18arc-20200818-RUF662192.docdoc b8ceb76e216625929c1a81fd2260e8b3ed97b6dda3a18f3054ef2fd575f7b15fn/aHeodo
2020-08-18File-20200818-X06625.docdoc c2ddfddccb101d4e986562ca370e4c29e0ec7f510f7a657f32d61ae37a173c8dVirustotal results 31.15%Heodo
2020-08-18Arc-20200818-UR58369.docdoc 4bc5422214e1f0a9c4aefa327deb893f6cbe5259343b9d42d02b42ea7204d53cVirustotal results 28.33%Heodo
2020-08-18ARC-2020_08_18-ES585954.docdoc 5761b96d033bca0977cc67ee0a51123d3986e1ea0e0f7dad51925b7a2a141555n/aHeodo
2020-08-18Arc 20200818 092495.docdoc a3d686e64806412716e762358904ec4b07f8d3ba5c22f42fd6463288f544658en/aHeodo
2020-08-18INF-87601.docdoc d85ffc795b5a9281a364b18d12c87bdb69c6351082d974bdb58839e9058b1503Virustotal results 22.03%Heodo
2020-08-18Mes-2020_08_18-GKZ7716.docdoc 2d9c3ad3458a6371d8d940be9e5379d3334396576ac0a4cf794f13309056ce6fVirustotal results 21.67%Heodo
2020-08-18List-BD0875.docdoc 6f0f54737b574488c42223ae81bd83ea0da431f0732413951fe4572ca19e6442n/aHeodo
2020-08-18arc 2020_08_18 8761452.docdoc 35b18dbdea7ae1b3d982973c26626ba8af054713d0479a8c1ad278abc7e8bcf0Virustotal results 21.67%Heodo
2020-08-18list-4134910.docdoc 2f5b958965764d27ae4953b29377a0adb36a5afc27dfc550e8ad464822719de6Virustotal results 21.67%Heodo
2020-08-18dat 20200818 4091236.docdoc f9c427a4bfa737b6f93b8d1271eb7c351a78fa1296db93634de337be0479d319Virustotal results 21.67%Heodo
2020-08-18FILE-2020_08_18-L75528.docdoc 9f1df99d205063984fcebb467c9a0f5e788e1fc90b2e9438d7837423c46faf0eVirustotal results 22.95%Heodo
2020-08-18inf_2020_08_18_274775.docdoc 19cfea28402702cfb0d89103c64300038ab9eccb6d18cd02d27e234e6f1e1cden/aHeodo
2020-08-18ARC_D331256.docdoc c05713068f1705d81e3bcdac768839b40dafb7f82ac746d7b3933d60a22b29a8Virustotal results 23.73%Heodo
2020-08-18FILE 20200818 209.docdoc 6f5f480e18ce00a7072df338b34f7d1140a5829ac041ae1483a6430a8211f81cVirustotal results 22.03%Heodo
2020-08-18LIST.docdoc ef65c9f4858045271c7a6baf6f96364dd76acc60c1c3da6ac156bdb6322c43bcVirustotal results 21.67%Heodo
2020-08-18INF 20200818 L72197.docdoc 07295ca2a5d3946d2553fc0a3e140872311843c9f6d20130ed5cd7d0f073826an/aHeodo
2020-08-18arc 2020_08_18 62078.docdoc 5ae3d951b12ec0a8e07ef73bbe0705ecdaf4d85546556d65d9cb6d6e02bd0138Virustotal results 22.95%Heodo
2020-08-18Inf-2020_08_18-3014.docdoc 9b12143b085ad044f054f5080820ffcb76f9c92df51d76173e60c0559001f16bVirustotal results 45.00%Heodo
2020-08-18INF_2020_08_18_B538441.docdoc 26919d2560f6e6e4b5c44add2fdda04f676163a1085799bfcacaec874289f126Virustotal results 45.90%Heodo
2020-08-18Doc.docdoc a7c86fe81531f07b7120be70ff6f16519758654ccc7ae3c901cea8d36e3a21c9Virustotal results 45.76%Heodo
2020-08-18Mes 20200818 NZ4065.docdoc a792d36a5d86adccbd0b2ccbb0fd67191beecb5e7230040f8d4626c8d47fd717Virustotal results 44.83%Heodo
2020-08-18FILE-992042.docdoc 25ee4f3c43b72dc8241940ae6f5418b60bf58dca63bd4a9d08d45bc566b1cef3Virustotal results 45.90%Heodo
2020-08-18REP_20200818_328872.docdoc 81ec297e1363823b4a4170387a248d68e35aaefafcd998d0f30c090fdb0a7ee8Virustotal results 44.07%Heodo
2020-08-18ARC-6267.docdoc 4a49fe6ff5e8731a7aa0536b8f0c0dbc5673dae67c35f0141efb3807cb21daddVirustotal results 45.90%Heodo
2020-08-18Mes-C0933.docdoc 85d29d1d7b0defac3d595525d663889a12f7d5388d8bb0a993665335f72bac30n/aHeodo
2020-08-18inf PC4530.docdoc 3f6f39740bdd518fc2428fa3aa082d73291be1fafe720a4a86d251a9ad92afe2Virustotal results 44.07%Heodo
2020-08-18File-20200818-Q436789.docdoc 5b2f315f6910580a86de6995dc3bb3af0bba726b0292875fbeeb557d17759d57Virustotal results 45.00%Heodo
2020-08-18inf_20200818_F9369.docdoc 8c8aa4e03dde0b4f833c19e6fe8d3ea663d6dfaf860287b2cb8d230fda6bd8b6Virustotal results 45.76%Heodo
2020-08-18Arc_20200818_387014.docdoc 1a92578592df96f6bc3c58861c8719f37bd57d2386789d07d319c613fcf2f79bVirustotal results 45.00%Heodo
2020-08-18Dat 2020_08_18 6316631.docdoc 77893a46e331faf345a8134849c0182109a90c65f156f288b95f054bc8bf667dn/aHeodo
2020-08-18Doc-20200818.docdoc 503c77f99b0c8271cb80a1101e69d6c9060647f7a4a8451c23aae49bd344b634n/aHeodo
2020-08-18doc.docdoc 78159b47ee6e43a81e5f727e9f01d56700fb22cca0c9f6cde333e91c0130dee3n/aHeodo
2020-08-18ARC_2020_08_18_UNL990770.docdoc cbae984f113307015e9a42c646507cd4fecbc37c1ce7ed2fa9d731fdfff7e00fVirustotal results 42.62%Heodo
2020-08-18doc-449753.docdoc 872c0c3578f24be338bcaa8a29f2b157d80a2d3d5e5ecbd33b028bced714c077Virustotal results 41.67%Heodo
2020-08-18DAT_20200818.docdoc c84240ca9f8d00a5e32e190c4fc4a4728fe5ca1e12603cf78a77ce78b9f69d72Virustotal results 41.67%Heodo
2020-08-18Rep-20200818.docdoc 4426143a003042fcf53c32a42cb6e2dfa30ff4dfdf7e2248eb6533df67ac8723Virustotal results 41.67%Heodo
2020-08-18File-6367.docdoc 92bd87c0eed15bf75f7c61b1879280e25a7997a4afe7c804c82a3902f51d46c1Virustotal results 41.67%Heodo
2020-08-18DAT-XBI8621.docdoc 8bbfe9b6aae9ae8cd42ef61b046d0c690f0637f216d5a22d4a5f7911b59469f7Virustotal results 41.67%Heodo
2020-08-18Dat_20200818_SM81244.docdoc e976f7e4de4c0bedc4e4bbc27752994f9110c050508b106611f035260551a8e0n/aHeodo
2020-08-17Doc-M460.docdoc e997b17d809b4d63590d7b7cca81318d3ecd18b59a46a4e83d88af6dfaeba54bVirustotal results 41.67% Heodo
2020-08-17FILE-2020_08_18-X4760.docdoc 2e363ae514de57da55513b7e9b5499e658bb254447ad4bac734032c94faed259n/aHeodo
2020-08-17arc 20200818 APR959.docdoc 32cb1657bab6cea4734f694fefe16389dca17cad7673cc0be676c77e070ae735Virustotal results 41.67% Heodo
2020-08-17ARC_2020_08_18_ZL838307.docdoc c5e15f4b4f97c4a8ab87e6bd09bf057455834577a7180163ca978fb734c66961n/aHeodo
2020-08-17list-2020_08_18.docdoc 6535313a52f000bc92afec62f22968677544878c5cf2109e862e72f7c441dda0Virustotal results 37.29% Heodo
2020-08-17arc-20200818-SA366378.docdoc 818e631aced6291b95a641f2eace827a0b9f2ee202b364a3a09378bc52401e03Virustotal results 40.00%Heodo
2020-08-17Dat SZ327.docdoc 1c00d01cd184a0d2a13e0b10fc17fe857ee0c55fe6894a8a538685b2c7a9150fVirustotal results 38.98%Heodo
2020-08-17doc LS60588.docdoc fcdb070abfffb0c9f0e4f52377b257f711f6d42380533d0e0230a6afedf0c489n/a Heodo
2020-08-17ARC XH81716.docdoc b5ba2a25b6b78baed8f427232afed8841e367725d1fb05bb47b5ec863dcfcf7aVirustotal results 35.00%Heodo
2020-08-17Arc_2020_08_17_20335.docdoc 332fb15e827574730b238731c1d69515d2110a2a48ecf3742552854097bbc5a1Virustotal results 37.29%Heodo
2020-08-17rep-2020_08_17-TL2131.docdoc 348368dc3b9ba59325226c159fd0b695e4256ad96894a3f58d3b97297a87a1b0Virustotal results 33.33%Heodo
2020-08-17List 6592836.docdoc 3d22fec6c122302f98c08a308d62a7f52a75ee6d24311103ae0af25bb246d480Virustotal results 30.51%Heodo
2020-08-17List-2020_08_17-BB57775.docdoc 7cd1f3000d36360b621ea98864af514cd8aae81afbb6f64b8010bc249173c610Virustotal results 35.00%Heodo
2020-08-17doc-51279.docdoc da10e987e0f17cdbf08a4c765e272d4feb929d329ba74d4fb5d1d27c36c1ed38n/aHeodo
2020-08-17Doc 20200817 04132.docdoc b5084e440fafd228cc3ff0eef418b654a434ed1288735ebe57084253b903a3caVirustotal results 31.03%Heodo
2020-08-17REP 20200817 8327362.docdoc 71cf52e83c16ce9dfad8a074f4c768efc94e262d70f9115f97decbccbf717981Virustotal results 27.12%Heodo
2020-08-17INF_20200817_N2498.docdoc 37fa3d3cd6ac66a6c2dac81cdbfa47a07af9cc5d6103546473c07d0dec853636Virustotal results 30.00%Heodo
2020-08-17inf.docdoc 008b4cfbe6c65f8eff107a4e75b2fdf0a04e8ccc576aa651971083412c256477Virustotal results 28.33%Heodo
2020-08-17REP.docdoc be3ec3f71ce797fc82f6e2c0d4544dde3c5ab20ff6df9ed778b0ba1199a980e2Virustotal results 28.33%Heodo
2020-08-17FILE-20200817-151.docdoc f270338465d313eb61ba96fff7969d855bdbd8f547a9eb71f5519e789d8ddcefVirustotal results 25.00%Heodo
2020-08-17REP 20200817 54777.docdoc 414a3261de7975d33e98be8efd2d34d23f9b0f3f51146b5d771026f5eb0a27d1Virustotal results 25.42%Heodo
2020-08-17INF 20200817.docdoc 955c1f638a523a970bd12d1759116d5779837c871c77d308a1275129f7d3a53dn/aHeodo
2020-08-17Mes_20200817_308.docdoc 285cbe4cd306ae4c3557c91c2fd38e3a562f79d21643a6295b53aae718aae367Virustotal results 26.67%Heodo
2020-08-17DAT_20200817_579372.docdoc e484e9b8614dff68bd63e103a395b4e03576c2f72fdcba1ff45344012e0f51b6n/aHeodo
2020-08-17rep 2020_08_17 U100167.docdoc df8740ae590def15c4443a1e068954d92bdf4035d39b8250481c07c02ae7c373n/aHeodo
2020-08-17DAT_LWF57172.docdoc 683251a1d571223428ec926ef741b19a2274b13d904fc8154915ace942c29e8cVirustotal results 23.73%Heodo
2020-08-17Rep-IP83184.docdoc 42afda4075829553353b7968af7696ea87be00a39e71dcf57b92783224da062eVirustotal results 23.73%Heodo