URLhaus Database

You are currently viewing the URLhaus database entry for http://5daofeng.com/ddokb/9gv0eb0v06/common-rq9FoQnnRg-j4wc8bwxTwYGjx/special-cloud/TFzezzgaKHRh-85xk8I29fvJn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435156
URL: http://5daofeng.com/ddokb/9gv0eb0v06/common-rq9FoQnnRg-j4wc8bwxTwYGjx/special-cloud/TFzezzgaKHRh-85xk8I29fvJn/
URL Status:Offline
Host: 5daofeng.com
Date added:2020-08-17 20:47:35 UTC
Last online:2020-08-18 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 20:48:02 UTC to ipas{at}cnnic[dot]cn)
Takedown time:9 hours, 53 minutes Good (down since 2020-08-18 06:41:11 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18list-6423771.docdoc 95949b60f4f62597acb4c3f6aef2a3fb60c59f24eb80fc37c3491342432624dbVirustotal results 45.00%Heodo
2020-08-18LIST 20200818 912.docdoc fda68ab66880ec8154bdc1a9595ec1f34fbf612ed3e9c9d13c7424ca0df1a5f4Virustotal results 42.37%Heodo
2020-08-17Mes-2020_08_18-5880250.docdoc b2641f58611eeb5d42675a9aa68ae865ed1136d543e7ddafcaaec3f5d6429687Virustotal results 41.38%Heodo
2020-08-17Arc-2020_08_18.docdoc 818e631aced6291b95a641f2eace827a0b9f2ee202b364a3a09378bc52401e03Virustotal results 40.00%Heodo
2020-08-17Doc_DQ63728.docdoc 47b3fee25d6683706ef483aa30125377edf7bb21dd17638c81c52fa7e64966f7Virustotal results 34.48%Heodo
2020-08-17list_20200817_QY848693.docdoc 36657a2c319a75fb01062c12c134050249024acdfc8e5d32c6f02e6f783d2e97Virustotal results 36.67%Heodo