URLhaus Database

You are currently viewing the URLhaus database entry for https://yuanmaj.com/wp-content/seky5z8l-04/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434747
URL: https://yuanmaj.com/wp-content/seky5z8l-04/
URL Status:Offline
Host: yuanmaj.com
Date added:2020-08-17 16:36:41 UTC
Last online:2020-08-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 16:38:04 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:3 days, 9 hours, 53 minutes Bad (down since 2020-08-21 02:31:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20INVOICE_CA004_668794628.docdoc 8c71ec9eedbf482ef0eb2ca7c191b16287ca2aad60d0a18d0b8dcc08eeb17a74Virustotal results 60.00%Heodo
2020-08-18invoice-EI0002-643635508.docdoc bb70bfcfda9d3e9df53c9e41b6625cc0896142d27a9d21b566adb5bbec1bf2c4Virustotal results 41.67%Heodo
2020-08-18INVOICE-BUNI0746-689081113.docdoc 40f7770f2b4cf7b9278695e6fcea916099ecedae08d4f4b3070f3fb47feb413bVirustotal results 40.98%Heodo
2020-08-18Inv MKO091 25361861.docdoc e2531260a88716bc42cfedc37b67576c03c26a31b38478d1a5ba6507a290e01eVirustotal results 41.67%Heodo
2020-08-18Invoice-TP00005-457479.docdoc 744b4fa289d8558331dbf2749ff648489860000fa1e98f7c2961d549b9e1bdceVirustotal results 41.67%Heodo
2020-08-18invoice-TCJ0002779-05051551.docdoc 78592ac8692e506cbf84de53eb9e18f8758944a5bd60a40fdc7a5b11218af2c5Virustotal results 40.00%Heodo
2020-08-18Inv-FDC0005603-41673289.docdoc 34f6f3dfbf731cc3d87253cdb7a6cbf7cbbf8a47369e0ff4b5a2c966e8f2335bVirustotal results 42.37%Heodo
2020-08-18invoice_NE00092_4889873.docdoc 77b91e171886421bc7a87ccccd572453071795281331490c3984b3601ca941a6Virustotal results 41.67%Heodo
2020-08-18invoiceEP0421787498.docdoc 92be4a79167b433e9a255723e3b6e3e3b01bc350cdaa6bc01a1cb46653bdc086Virustotal results 43.10%Heodo
2020-08-17Invoice LGT576 13107987.docdoc 4cfd1a4d130209a42e6f1463451b36e01d0290a5b62df9a4b6a802eaa6580dc3Virustotal results 41.67%Heodo
2020-08-17invoiceQXH01539791550.docdoc fb6aad846cb69bf2d5287dddf2b0f0899e5338ece7621d4d6553aea13fa9a285n/aHeodo
2020-08-17invoiceDKH0006515541950.docdoc a6843ba695ff6d9b98c1710de18540fb64fbd14e5600bdcaf2bb08c8d5d4e879Virustotal results 41.67%Heodo
2020-08-17invoice_JS0035_749207084.docdoc cca592a85f2072100fee32efe4da3a5838a4fede975df3a1892da6bd297595f2Virustotal results 41.67%Heodo
2020-08-17InvGYX0005770060804.docdoc 3ba7e5c969ebc04a05763c55083111c62b6bc12fa1b845f71bd0a2eb94501d1dVirustotal results 40.68%Heodo
2020-08-17INVOICE SE0311 77259713.docdoc 5a46b7453ab371c28e2d0579740f747b1eb714014cd186bb2ca3ea43715a9902Virustotal results 40.68%Heodo
2020-08-17INVOICE-FJDE03-659859615.docdoc c173dc0610840f39487d42dac104a6b6226faabda18baf6e22ea305b405191e1Virustotal results 40.00%Heodo
2020-08-17Invoice-XI0099-033067.docdoc 69aad8b30bf71211ae9950bb6ba0f258d420597413f988aa094e5e6f15dae70bVirustotal results 36.21%Heodo
2020-08-17INVOICE-FYZD00399-077089887.docdoc 32b182b7d1765f38210411e917f24c9927d053507c5ca2ba097387de33210ca7Virustotal results 35.09%Heodo
2020-08-17Invoice_OS7325_542096.docdoc 4fa07d2b92390ce810b09723ccf48c59d24051c791428e3daed60edd9bbe8248Virustotal results 36.21%Heodo
2020-08-17InvoiceYX00039009802.docdoc eb5662fa54e863a467aa8e7244ae292e56df5ce7e263521d7879fff32a5cbbb7Virustotal results 35.59%Heodo
2020-08-17Inv-JJ01432-8983033.docdoc 36411b6b9a12fd7750db9128fbd093a70fe359b50c54898c61446c3af1940993n/aHeodo
2020-08-17INVOICE-WJC0004166-82313535.docdoc 002fc17ef46f5a786a26f8463cd5ec94ae73ee28100e60d364eb8ac85e70a10an/aHeodo
2020-08-17invoice-ED0332-4427044.docdoc 25d674d0133fd5d5436990578240da96820b71e96aee7f75f3cc491a43259182Virustotal results 32.79%Heodo
2020-08-17INVOICE 0009354 7367267.docdoc 0858225435ef18d51362fbdf7228a8db3ed5b107ff8de17591a83a7366b936cfVirustotal results 28.81%Heodo
2020-08-17InvBTMZ01078963.docdoc ebeb93b496cad01ac3da5ccb47d1695200f0245e76275845d610b13434475fa0Virustotal results 28.81%Heodo
2020-08-17INVOICE-YS000244-341009.docdoc 60f7f2e65193c7c4219cf0246c38f7eeda8449dc52648a62f8549258973629c5Virustotal results 27.12%Heodo
2020-08-17invoice VWJB01 405260205.docdoc e882dad5b84a41853fdb21f8229c8bf081505ddb9334dba42ab48f07edcebc86Virustotal results 24.49%Heodo
2020-08-17Inv_HIRK000_640827983.docdoc ad7b95cd42cc634f74b82730c63941006b341cff953ab44fe3eb63fda9123fedn/aHeodo
2020-08-17INVOICE-000648-5982689.docdoc 8b03dc5fe55fec0064b3e0886526d6645dd239585dbd1aac5ccaa79d68bf51e4Virustotal results 22.03%Heodo
2020-08-17INVOICE000163087016.docdoc d33440881126800ecb592f63bc2e3d128adde303eee29a80c02aa5e76eae5ec9Virustotal results 21.67%Heodo
2020-08-17INVOICE_LNBN000_88633619.docdoc c84ea22db06ef0d80eb9dd2151b40060ded6ba947466b1f863e3b480a8875137Virustotal results 22.03%Heodo
2020-08-17Inv N0580 85325145.docdoc c11b318052c38b2912124109f0b4047a5ee9391adb9e3e0e5f88d772739a3b09Virustotal results 22.41%Heodo
2020-08-17invoice-119-15246159.docdoc c44ddcbb54399b54e123f47cf9753dd6376799ce5b101f6a809e957d0b087a3fVirustotal results 22.03%Heodo
2020-08-17INVOICE-00617-052824907.docdoc 0a7eaba5e79244be71d93f72b5bb4d0927a6b42b0a9963579c385c599e4ccb96n/aHeodo
2020-08-17Invoice-GPI3-927688.docdoc a69b1528038510c4ebecdf7f717d7f9d34694721fe045a86ec14fcbfe0bc59e2Virustotal results 22.03%Heodo