URLhaus Database

You are currently viewing the URLhaus database entry for http://elongking.com/core/syewgb7t6fax-049228/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434758
URL: http://elongking.com/core/syewgb7t6fax-049228/
URL Status:Offline
Host: elongking.com
Date added:2020-08-17 16:49:19 UTC
Last online:2020-08-27 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 16:50:04 UTC to abuse{at}cloudie[dot]hk)
Takedown time:9 days, 7 hours, 44 minutes Bad (down since 2020-08-27 00:34:42 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19form.docdoc 924d061e9517d286d362d29b437f2c8f6145e83053b16cc364e4d6d7f0d40676Virustotal results 20.00%Heodo
2020-08-19GA3331914965HK.docdoc 2080e7550c951ac8fb488247f9ea953e73c9095393885e0d3a9e1a82077dac92Virustotal results 20.00%Heodo
2020-08-19VK74 invoicing.docdoc 73e94740e88d19f7015e1a7025eb77e524e4b23b72f576a8e5d3abdcb6c73849Virustotal results 20.00%Heodo
2020-08-19Electronic form.docdoc 3cb5213513d2ad38249b287a2e5672384c4ce47f95c23d9d1107cb59f037a245Virustotal results 20.34%Heodo
2020-08-19Copy invoice #99252.docdoc 69eb339c87a2847b96f8e1c697e0b016e8d2fc43fcc1b4febde910ac670906aeVirustotal results 20.00%Heodo
2020-08-19Form.docdoc 0b6b89fad86785304d3f98bfa09cf5b12107f3e93db1fb3cc10e5ce6def4727dn/aHeodo
2020-08-194627978265TQ.docdoc 93024c5de06bffb75e2a40baa9b9fe6ef9bcb1fc3dca10125891dc3180700608Virustotal results 18.33%Heodo
2020-08-19Payment status.docdoc 9067d745bde9ddd9c461f7d2ea60a1a1c078350952971d5e4eb93d7385b33bbfVirustotal results 18.33%Heodo
2020-08-19Electronic form.docdoc f6d93f3c605694a9c9d821b028925da61739649e5137a176f827296552532c36Virustotal results 18.64%Heodo
2020-08-19invoice.docdoc 3b5e90ebc7744849c2ad1d39c5d48cbf713dce662efe95239953614698400c99Virustotal results 18.33%Heodo
2020-08-19P5 invoicing.docdoc ba611c93ffcd43fa84efb485a52bfe8f9438e21aca26ed903a5c8e431fdc3258Virustotal results 18.64%Heodo
2020-08-19InvoiceQG000390376325.docdoc 1bf76babfa090e2a05e565fe3057f730dd19cf329997ed8e80d96b50e271e6deVirustotal results 18.33%Heodo
2020-08-19INVOICE YOSE0265 62589029.docdoc 37b23f85ba3329d2d0380f25eaf29fe5afe4cc7da0b21b01d6be794fdc22e26fVirustotal results 18.33%Heodo
2020-08-19Invoice-LBAD014-0871227.docdoc 3f83aa36b1218325b7ef35494e577c47446fadcf3baf112f522b9788671adb63Virustotal results 18.33%Heodo
2020-08-19invoiceOIJH0008485945977.docdoc 477ab71dee71ae8ff815f4d53611f096e2cb76e31d85974a37e3bd35172a8473Virustotal results 18.33%Heodo
2020-08-19Invoice-06045-7269958.docdoc f80a1c4caadca8da02db5df240f669e7051592338b29ae30312edafd41df3b96Virustotal results 18.33%Heodo
2020-08-19Invoice_CK04_733546424.docdoc 57907203628ac2175fe58a5a013f18c35e0adad4db02e3c436d737101723edd9Virustotal results 18.33%Heodo
2020-08-19InvEMOZ3666831912.docdoc 20fab520e65567fba7c6da6f12dd410532878d3c9b35bed6bbe7b07e77c44293Virustotal results 17.24%Heodo
2020-08-18INVOICE-0003770-265086.docdoc bb70bfcfda9d3e9df53c9e41b6625cc0896142d27a9d21b566adb5bbec1bf2c4Virustotal results 41.67%Heodo
2020-08-18Inv-X13-909037.docdoc 40f7770f2b4cf7b9278695e6fcea916099ecedae08d4f4b3070f3fb47feb413bVirustotal results 40.98%Heodo
2020-08-18invoice FI7 11331367.docdoc e2531260a88716bc42cfedc37b67576c03c26a31b38478d1a5ba6507a290e01eVirustotal results 41.67%Heodo
2020-08-18invoice-KICA00518-43229055.docdoc 98b8ad7ad36042dfa1359120a38724e21ceeba7375bec204748003bc4afd2e6dVirustotal results 42.62%Heodo
2020-08-18invoice-JN04113-295837246.docdoc 78592ac8692e506cbf84de53eb9e18f8758944a5bd60a40fdc7a5b11218af2c5Virustotal results 40.00%Heodo
2020-08-18InvCG000919060647.docdoc 34f6f3dfbf731cc3d87253cdb7a6cbf7cbbf8a47369e0ff4b5a2c966e8f2335bVirustotal results 42.37%Heodo
2020-08-18InvoiceB03588042285.docdoc 77b91e171886421bc7a87ccccd572453071795281331490c3984b3601ca941a6Virustotal results 41.67%Heodo
2020-08-18INVOICEAF00023086732118.docdoc 92be4a79167b433e9a255723e3b6e3e3b01bc350cdaa6bc01a1cb46653bdc086Virustotal results 43.10%Heodo
2020-08-17Inv-YUJ009678-865159969.docdoc 4cfd1a4d130209a42e6f1463451b36e01d0290a5b62df9a4b6a802eaa6580dc3Virustotal results 41.67%Heodo
2020-08-17Inv-FMH00066-972718.docdoc 78a2cd40d747f3c621c50eadc47b9f15eb11a59b729dda17d525ae52a89cac41Virustotal results 42.37%Heodo
2020-08-17Invoice AT0765 59888081.docdoc 8f519c2aaf3e05564df5221f4bf2f52e0ffb055e6f0466185ef43c721ad18757Virustotal results 42.37%Heodo
2020-08-17InvW007310991.docdoc 32754532f0eb0205b94c93df24d8c8dfadf0769460b0983c124988bc8c3a267aVirustotal results 41.67%Heodo
2020-08-17Inv_FNRB5_222714974.docdoc c194f0d9702a16ea1f8b9a5ffec32ddca75c5ab3076ad1e9d7e249fe6bab7d65Virustotal results 40.68%Heodo
2020-08-17Inv_Q00689_646914.docdoc 4de2466dd0aa46843aac10caf6fa9ef8a414ee57491d87eff8e1a4d6d3b7a443Virustotal results 40.68% Heodo
2020-08-17INVOICELQQY001101607474.docdoc c173dc0610840f39487d42dac104a6b6226faabda18baf6e22ea305b405191e1Virustotal results 40.00%Heodo
2020-08-17Inv OJWT016 467031633.docdoc 69aad8b30bf71211ae9950bb6ba0f258d420597413f988aa094e5e6f15dae70bVirustotal results 36.21%Heodo
2020-08-17invoice_TXW0813_987532716.docdoc f5d638d5d64bfb767081e85f1be73d5d6d3bd697b9c44443f168ca765c3b207aVirustotal results 36.21%Heodo
2020-08-17Inv_DFE77_811211847.docdoc 4fa07d2b92390ce810b09723ccf48c59d24051c791428e3daed60edd9bbe8248Virustotal results 36.21%Heodo
2020-08-17INVOICE-28-8824014.docdoc eb5662fa54e863a467aa8e7244ae292e56df5ce7e263521d7879fff32a5cbbb7Virustotal results 35.59%Heodo
2020-08-17invoice-QG0031-758344049.docdoc 36411b6b9a12fd7750db9128fbd093a70fe359b50c54898c61446c3af1940993Virustotal results 34.48%Heodo
2020-08-17INVOICEBATW0459724326212.docdoc 002fc17ef46f5a786a26f8463cd5ec94ae73ee28100e60d364eb8ac85e70a10an/aHeodo
2020-08-17Invoice_Q7_4509797.docdoc 25d674d0133fd5d5436990578240da96820b71e96aee7f75f3cc491a43259182Virustotal results 32.79%Heodo
2020-08-17invoice H001 7882551.docdoc 0858225435ef18d51362fbdf7228a8db3ed5b107ff8de17591a83a7366b936cfVirustotal results 28.81%Heodo
2020-08-17INVOICE-DYKE00075-1406352.docdoc ebeb93b496cad01ac3da5ccb47d1695200f0245e76275845d610b13434475fa0Virustotal results 28.81%Heodo
2020-08-17INVOICE0001199273.docdoc b72f7bb63db9da4a5d6d06172a5eb3e045ce63e192dfd37ee2e3c41fb0bca698Virustotal results 27.12%Heodo
2020-08-17INVOICEXFGM00297433048614.docdoc e882dad5b84a41853fdb21f8229c8bf081505ddb9334dba42ab48f07edcebc86Virustotal results 24.49%Heodo
2020-08-17INVOICE Y0940 5893363.docdoc b9878f3f33f338d3ea58d9e922b333821014a2aaf46a8d3b598c7a27aedac605Virustotal results 22.03%Heodo
2020-08-17Inv_W0_79165224.docdoc 6ab459f614b20e63e99e20d35636ffabb11a7b290abd3fb3a68fe5c8472dbadeVirustotal results 22.03%Heodo
2020-08-17invoice_YH1_452101.docdoc d33440881126800ecb592f63bc2e3d128adde303eee29a80c02aa5e76eae5ec9Virustotal results 21.67%Heodo
2020-08-17invoiceI00047583768370.docdoc c84ea22db06ef0d80eb9dd2151b40060ded6ba947466b1f863e3b480a8875137Virustotal results 22.03%Heodo
2020-08-17invoice-KRMJ0006-93931697.docdoc b2c6b1b963855fbf097accd55a62c09a1e79f547a6889ac3d86b25abdbcf2183n/aHeodo
2020-08-17invoice009952189.docdoc 28f6023bfe0f6ec89ed3bd76ac369c6347f97ddfbfe104362cd71e5c60bd7437Virustotal results 22.41%Heodo
2020-08-17invoice-YVF00295-830542.docdoc 0a7eaba5e79244be71d93f72b5bb4d0927a6b42b0a9963579c385c599e4ccb96Virustotal results 22.03%Heodo