URLhaus Database

You are currently viewing the URLhaus database entry for http://xiaobihu.top/wp-content/closed_zone/open_cloud/4i2gNslKXz6_516yGLrH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435598
URL: http://xiaobihu.top/wp-content/closed_zone/open_cloud/4i2gNslKXz6_516yGLrH/
URL Status:Offline
Host: xiaobihu.top
Date added:2020-08-18 12:00:08 UTC
Last online:2020-09-15 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-18 12:02:02 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:27 days, 22 hours, 16 minutes Bad (down since 2020-09-15 10:18:59 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-06arc-20200819-IY628112.docdoc 267f48018f6a55a78062298bfa8465627d26be628b6a125899b3def1f9ef3ee3n/a 
2020-08-19arc-20200819-IY628112.docdoc a834eee056511d26145abd3184681bc4afaf44e4d370bf83d950e66751704ea5Virustotal results 17.54%Heodo
2020-08-19Dat-20200819-LB2355.docdoc fc3d622adccc98bf7aee3ff98037920892cf9ec8e29b6a2de393217d74499b7en/aHeodo
2020-08-19doc-99377.docdoc e9da8132017bc36f1448def9ba8b2ea44184e68bf955c08ba75f2560ade79372Virustotal results 18.33%Heodo
2020-08-19dat-XKH379004.docdoc 17904f8a80c29c5ed3d3048aae5f62027b918b756006c67893220e03e7a0d7c8Virustotal results 18.33%Heodo
2020-08-19file 1778.docdoc 87a90ac40158e53a2309863a8bebfe1218f13262f87b93db76e5fc79ed1c388eVirustotal results 18.33%Heodo
2020-08-19LIST_2020_08_19_25093.docdoc 44116755a469545747d98ca4dad33a22c5565d571be3001cb95cb4971c532c3cVirustotal results 18.33%Heodo
2020-08-19INF-20200819.docdoc 9d634af91f6a53ac776bd53e7c54fedb5e03e4428401865df1774123fafa15a4Virustotal results 18.33%Heodo
2020-08-19REP 20200819 696326.docdoc 06f924f51874c7df81f49a607dddc6e977b700d5ce712232c7e962d77150bb01Virustotal results 18.33%Heodo
2020-08-19doc 20200819 V82175.docdoc 4aff494156109cde9b6e276763ac3797bdcf712a55c119b108b3d5d854bb8fa4Virustotal results 18.33%Heodo
2020-08-19Rep 20200819.docdoc 4a1a50b2b4fbd12c0a323d5ac275bcdec7c1ca37fbb518a9c11a86dfde2b0798Virustotal results 18.64%Heodo
2020-08-19Doc-2020_08_19.docdoc 741441215f02f536e57bad81a0cd2549669c22dabf11a9db8076f3e7ec6acf1bVirustotal results 18.33%Heodo
2020-08-19INF 20200819 382689.docdoc 568b22f1a6fb077fd3828a09858b4bcd8401325c01f2aed85b3a39e12777cb35Virustotal results 18.64%Heodo
2020-08-19REP-2020_08_19.docdoc 20694db459b3cb2ccbf97a5f2923759cac13520542fe78e84733947045a860e8Virustotal results 17.24%Heodo
2020-08-19rep_UZA80854.docdoc c94255c1e218f6578be80a7dd64f4d75acb2c91812aa436908f37c81d531df90Virustotal results 19.67%Heodo
2020-08-19arc 20200819.docdoc da820b108be2808d9d5d1909a3d8683f33f902abe5ae4e5e319d6aa766aba61dVirustotal results 47.46%Heodo
2020-08-19Dat-2020_08_19-1188.docdoc a09fb497ce5738081489fafa343ed354128eba16cc5f8f6bfbb26ff79e19ceebVirustotal results 47.46%Heodo
2020-08-19file-20200819-0111792.docdoc 1c98753feb43790bf0b2979ae0d73c4760638ab1d9c5d6b6336ce2241ba31aa4Virustotal results 45.76%Heodo
2020-08-19File 2020_08_19 OF61774.docdoc 305d205cdb3c030f05543db463c783753137d91a3d8c2721189a94fb36e4f7c6Virustotal results 47.46%Heodo
2020-08-19doc-20200819-631276.docdoc 4d3b86d9dc87fa84b6283d3c9ef68a508bd41eb8f2930650cecf08f2ae86c2b3Virustotal results 47.46%Heodo
2020-08-19DAT_FS14522.docdoc f6feee3a8137cb0cab6667842f06e07f96e54fc2f15ebe079dc30b4060d52452Virustotal results 46.67%Heodo
2020-08-19list_20200819_OIR58761.docdoc 00ae8c566e55be2bcbcd11072f67a71e34b8b28b3e3dcb0f949043c17c398ecdVirustotal results 46.67%Heodo
2020-08-19File-20200819-ETD05266.docdoc 8ecfd0e0dbd4257b0b0f97f99517f9d1d825e32d7862b1ceb1b6bfdc67b205a0Virustotal results 45.76%Heodo
2020-08-19LIST-2020_08_19-N0422.docdoc 60529051426888b950c39051f1ae3ffd04df199460f8f08ad2fb4ae0d65837f6Virustotal results 46.67%Heodo
2020-08-19Rep-9869499.docdoc 7916fa0619bd4a976c48a8b068040591dd8f78f9eb5b2bd3abafc019ec1f0dadn/aHeodo
2020-08-19Doc G612.docdoc 5a63ce9de6a721eaabedc5a95a579a3eee404a94034db171f646e24517fed367Virustotal results 46.67%Heodo
2020-08-19Mes_2020_08_19_71012.docdoc 682cb4ff880f1a6a000f5a227f8dba42abd73d836308162dc519644d9dae94efVirustotal results 45.76%Heodo
2020-08-19MES_2020_08_19_HJT5101.docdoc 45a1dbdb6b372ed28b9806469cbe031baa76035067cb69b5e936960e53988a80Virustotal results 45.00%Heodo
2020-08-19dat_2020_08_19_I38568.docdoc 7833c0d39d11142241550af1fa9cb743026dc00c841f79a52d695fd8e9bfdd43Virustotal results 46.67%Heodo
2020-08-19LIST 20200819 GB171.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19Inf-C577242.docdoc 5df568ab274842e91a3f5717af61fdbe6827249fc71e135fdc493f5177ccac7aVirustotal results 46.67%Heodo
2020-08-18Rep QV2226.docdoc eba02aeb5ab35694f34f8048ad03accea87abc6915db54d0905d905a155901ffn/aHeodo
2020-08-18Rep_20200819.docdoc 96ff6e1cf0debb38b542d25de485f8bbedbebacc99a76bc427946603266b19b2Virustotal results 43.33%Heodo
2020-08-18arc_2020_08_19_KX696.docdoc f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cVirustotal results 43.33%Heodo
2020-08-18DAT 2020_08_19 AJR30967.docdoc 5fe3b8e6945f1fd2e0c85c1b8cf1c0969965447dcb9d72deb04c28e05c9116b4Virustotal results 44.07%Heodo
2020-08-18Rep_820803.docdoc 58a56d18575486a19f725b7a1ae5cde8ab091e272638e1df1ccdcc69cd83371cVirustotal results 43.33%Heodo
2020-08-18Doc 20200818 FO67274.docdoc 17300227be521550f2f2047dc5be4dcad326b59b87378c8a1372dbc867fb29c8n/aHeodo
2020-08-18List-7742.docdoc 94ace7e2d381dfd76ee7a14ca9dd506f68b294af71ba21068cf646c1442e9d96Virustotal results 43.33%Heodo
2020-08-18List-92619.docdoc 8eff0446f444542435bf1ea66d34ac5b2339a87d7702ba744f403dc5ec5d4795Virustotal results 44.07%Heodo
2020-08-18inf EP032.docdoc 2665e27cc12b9a111b35b73a7afd85da8a5d1877d6270f6d8ea48edd2acc0718Virustotal results 42.62%Heodo
2020-08-18INF.docdoc 5ab26ba89dca2d8b250aeb563b2d6c7215c10c0a62f544d7dc78af3c638cf2f2n/aHeodo
2020-08-18arc_1832508.docdoc 52386a3f4ed721abc491a22e4d08ba4497e8392249b04e5fbcdcff39502cb314n/aHeodo
2020-08-18Inf_7920.docdoc 28810939674484b940c1b242c2defba24f6fa84ca59b37ed3196792e22adc284Virustotal results 40.00%Heodo
2020-08-18rep_2020_08_18_3317.docdoc c2c31857eddef908bb15ebce07f54e91a068ffff5b92014fd70c1d5ce8f34cd6Virustotal results 40.00%Heodo
2020-08-18arc-2020_08_18-F98767.docdoc c674ec5f3cdf350eb7768e985c94060f26903274d10b581bab0fc71c730f0179Virustotal results 36.67%Heodo
2020-08-18Dat_20200818_J0352.docdoc 4447568080893f02a97ee86ec9e776b6d5b4f7ea644870e130a19f3df9b16667Virustotal results 36.67%Heodo
2020-08-18FILE_20200818_53374.docdoc 220f661d5186fcdd525b47c5a909197b80b076950ab2a2f94b6799328cbd1f19Virustotal results 35.59%Heodo
2020-08-18file 2020_08_18 T772.docdoc 46411363967383fde95f164b6ca16cdf6f2da8a1269ee7c150b892d445cc9f20Virustotal results 29.51%Heodo
2020-08-18mes-20200818-HD21789.docdoc 96c73835686797a5dbc5dbd37ef4a7291b69f848d7ca403c9ab404f4f7f650e7Virustotal results 28.33%Heodo
2020-08-18FILE_IW61993.docdoc 5761b96d033bca0977cc67ee0a51123d3986e1ea0e0f7dad51925b7a2a141555n/aHeodo
2020-08-18Arc_2020_08_18_OOA571559.docdoc e623eae3d71737cf64d678b398b83dafca4698f24b80d315bd3dc57dfcfef726Virustotal results 21.67%Heodo