URLhaus Database

You are currently viewing the URLhaus database entry for http://hxtoutiao.com/lh0wh/OTJjNbOd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436799
URL: http://hxtoutiao.com/lh0wh/OTJjNbOd/
URL Status:Offline
Host: hxtoutiao.com
Date added:2020-08-19 19:08:07 UTC
Last online:2020-09-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 19:10:03 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 month, 7 days, 22 hours, 31 minutes Bad (down since 2020-09-26 17:41:48 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21QD5210482314SF.docdoc e327efa33b90324aa3b4082314e8426468e52d0a27633e4f3dbcd103297cb84cVirustotal results 30.51%Heodo
2020-08-21INV #06163888 FOR PO #3771764.docdoc 5ad1d00e81e5e6bbc93829790980fabae6eab63a8638ed9bc024a27d083ffb87Virustotal results 25.86%Heodo
2020-08-21invoice #504593.docdoc 43638c344ac4a446af722c229682fee9a8434923ce1cf6dd1a19bd2a0fc78c21Virustotal results 25.86%Heodo
2020-08-21Copy invoice #6611.docdoc ed0a6eec86f44151f9815362fdc3c778a7f176378e582bfaf012098d9b98454cVirustotal results 25.86%Heodo
2020-08-21August invoice.docdoc c577ab86ca1ba758fa9c15c3924999345d8fb5d596bb1e091f9b223c559515b0Virustotal results 22.41%Heodo
2020-08-21304162295.docdoc d36a6c6b491f807acefa65d267627215dc919075551c5f10749fa44c5652de4aVirustotal results 20.69%Heodo
2020-08-21Copy invoice #397460.docdoc 762a08ff51aabd7ee2cdcb6f27fe687ead902ab8f3b84925b013904d356cb622Virustotal results 18.33%Heodo
2020-08-21Form.docdoc 7552ebec57d7bd58dbd5e68f18c92abaabee85b838225aaf83ab280ad6a56c63Virustotal results 20.34%Heodo
2020-08-212120047288MO.docdoc 13d2079b2caabbd56dc776517810d9dbf355138869ff3030314e9f4905e68192Virustotal results 18.64%Heodo
2020-08-21invoices 2161 & 7077.docdoc 73e5878f60f55c29173fe8d7ffcbaef00ece1a6fd67e137f33bc492372ed79c3Virustotal results 18.64%Heodo
2020-08-21R007 invoicing.docdoc e194c7cc8ffedeb69d1b752e312fd6605be5ae9f49e9b652a38246d0c865dab2Virustotal results 18.97%Heodo
2020-08-21Invoice #660.docdoc 847717b8f4573eabf8736def4405be87f319a2f5aa3eae17a33ae61f13c9b3a0Virustotal results 18.64%Heodo
2020-08-21Form - Aug 21, 2020.docdoc 595bcfd89190ec1ce1b6c75d8b8b2b4f924106df47bb8d5a3671dad83104d473n/aHeodo
2020-08-21INV_037238.docdoc 1956596f7ed909a0c2291a2a8b6ce38918255ae87ced9b557c898972bcce4d42n/aHeodo
2020-08-21Electronic form.docdoc 310dc3ae17963a0ac8df3cda0697749f205c3c01787d4e24026bc30ccb7f90b5Virustotal results 20.34%Heodo
2020-08-21T001 invoicing.docdoc be0c986b37c30a192c9f2e62d6c85b635a3e25bc10cb8a8b4ddac390bbc93163Virustotal results 21.05%Heodo
2020-08-21Inv. 0482850992.docdoc ad61f377cd0d259cfabac17a4a874cd5dbd88b076e00680d5fb1d31706816ca7n/aHeodo
2020-08-21Copy invoice #896757.docdoc 1313ff749e2cbb39eb12cd00b080dc06159270b9309b7211be0fb2223b924d1fVirustotal results 20.00%Heodo
2020-08-20INV_841849.docdoc ed8f3cd480b6fef9996f65e02cc1cb3d295447728fd009032ac3838d32e01f37Virustotal results 33.33%Heodo
2020-08-20August Invoice.docdoc 3fb4829564edbb691226f1298c052a8a39087d1a99e583bcca9781e9061b4c44Virustotal results 32.20%Heodo
2020-08-209296512007EQ.docdoc 73edfc2aba2a5e763fb0b40b55a4695a6d9e6f0069b17e693c982385b150b4c7n/aHeodo
2020-08-20PO# 08212020.docdoc 4e132ba6d019767be2f8156e367e5c0f60ee91db33f3517c525d22cace8bfa9bn/aHeodo
2020-08-20form.docdoc a5257e575894b7fdceb18f36985ab8d6394e335b4458d40dc376703089368bb7Virustotal results 32.20%Heodo
2020-08-20Form.docdoc d602c575bf86a934dfc17916699ff512aba1b2b6829f1e4fd1ac6c4d1a9e9d55Virustotal results 31.58%Heodo
2020-08-20invoices 750 & 0352.docdoc ae09a760faec9e5c8f9d147329271cb1fa3971b119943d8cc9e16ce71c8e5fd3Virustotal results 36.07%Heodo
2020-08-20Copy invoice #876242.docdoc c2860e92b00a96df1031b68a98c104f55bfdc472da83ab5c7d4ebfada4a70383n/aHeodo
2020-08-20WYM-080120 FSJV-082020.docdoc ce4cd4d124a577ac6f489568a077a53e6745170cb71a64c5b4bcba502af51347Virustotal results 21.67%Heodo
2020-08-20INV #006801649 FOR PO #013025843.docdoc 5636cd51c28170e8a684da99be292a5a523e7ded2895dbf028c3d95959844c52n/aHeodo
2020-08-20Copy invoice #09273.docdoc 65d358d5c25eda27078f168b3fd190c5250bfdf1b58bceb28681f2535de96423Virustotal results 41.67%Heodo
2020-08-200848079003NN.docdoc 35cdbc32f50870b20e2cd551f4805152d7ff4c9a9977739de4036d9fe76a6e0cVirustotal results 42.31%Heodo
2020-08-20August invoice.docdoc b462b6985f21115db5a18167bd1701f4a2599116fe237a0156cc2cce93e96edbVirustotal results 38.33%Heodo
2020-08-20invoice #42232.docdoc c500d1d7cc11d82b241b378d7e3015d381ddec5170984b634f89786580b27a24Virustotal results 40.68%Heodo
2020-08-20WX5030353622TZ.docdoc 210f3cffbbc984d2b04c012fb54991ba7cec609aaf5d6e97c4b7715fa179a770Virustotal results 40.00%Heodo
2020-08-20August invoice.docdoc f378d52ca240609ddf42cfd7fe5f3c83ed70ce0e560a3e669e0e8c229a9c1f28Virustotal results 40.98%Heodo
2020-08-20Payment.docdoc 252905fc07b8d4de77b22dd1c68bba23716cb7bfbf56bae15a624f59b7e69c70Virustotal results 38.33%Heodo
2020-08-20Copy invoice #463908.docdoc a0601dc3c3afeb7471b9fe739ce24e0b476d100c3f2ee756df211888184f67f0Virustotal results 36.67%Heodo
2020-08-20Form - Aug 20, 2020.docdoc e10d9e51f37cac947f9dac20f25fe6c9cdbc9a27072d1f54575087d0d63179fbVirustotal results 38.33%Heodo
2020-08-20Payment.docdoc 3873789add951f7faaee58644422e134440be2903271725124cff640acd0ad4dn/aHeodo
2020-08-20INV_684286.docdoc 416a4f17b5bc066941020cd43640276363268db7cb067a8cc7f1d27c3cb3cdb2n/aHeodo
2020-08-20QLJ-080120 LQZV-082020.docdoc fa10393ccc08487ee9b80a41d01c9e5e87c3c7690a74327b1b19e47f3638b66cn/aHeodo
2020-08-20T0391678633QG.docdoc 2cceef317fac265bf56fc5819196f6a58b95574e8085a889f61ed9cd5c6c387bn/aHeodo
2020-08-20Inv. 329126875.docdoc 741eedc40d043df1d8abba1e18fdeab3d276fd970087ad3b980243aba3c4878fVirustotal results 38.33%Heodo
2020-08-200898802.docdoc 04a14a477cf1d1d2e5a426b932542d931d6264a101a10da26141be2752db8a72Virustotal results 38.33%Heodo
2020-08-20August Invoice.docdoc cf817564329bd4a2f3c9cdb4ce0609048d648917967fa9f9ff5c05a656ee3cbfVirustotal results 35.00%Heodo
2020-08-19Electronic form.docdoc 8fef0fa03aec63f50c5f6c1b055fc5c7c90f092a2b4549ef022e6696d49c9bb7Virustotal results 35.00% Heodo
2020-08-19967291.docdoc a91ca25ee6629da31d5ed352b923e1bea33384d268d8ea57dae1c5bd9a84c6a4Virustotal results 32.08%Heodo
2020-08-19Invoice #612266.docdoc 3f50adbc111dad1db785e1c67241fd31740db030e0307cc9a2f1e4ff21aa2f56Virustotal results 28.33%Heodo
2020-08-19form.docdoc 2a532523cb09773c9d7a9dcdd27af27c026dcf5a433abf13c392fa73b32b8fb2Virustotal results 27.12%Heodo
2020-08-19Form.docdoc 63f883c9dcea56ba10f482065f752933d7fea115f16f30b53a15e4aa729e3b13Virustotal results 28.33%Heodo
2020-08-19AKH-080120 RGDG-082020.docdoc a42cda56ab706210a825c2992a112c9ede1476180e2564ea2d1d9a5e21287c1cn/aHeodo
2020-08-1906061258.docdoc d220bbc8081710b4776297c19f586d5ea6353b14ae1b1dcc7819e1f969aead89Virustotal results 26.67%Heodo
2020-08-19Form.docdoc 12e589c0bbe01dcb772c25535f983687a52bc64a253a2aff5e6a1b79e69eb188Virustotal results 27.12%Heodo
2020-08-19Electronic form.docdoc e518a717decc9cfeb174f53987f99d4a4c1802301dc8a18f5d83c137cfd95d31Virustotal results 26.67%Heodo
2020-08-19Payment status.docdoc a1502f115a7017cb9c7c69031663b6c1ffcdb53af33a3dfe8b2ed61cdd0bcc63n/aHeodo
2020-08-19FBM-080120 FIDY-081920.docdoc aaa14437f6dd748c3f483550973aa8a386d763a94036204ac1f2961d104a64eeVirustotal results 24.14%Heodo
2020-08-19Invoice 009127313.docdoc 3f6ede3e0181e7fd9efb5449bf7d89d05cfc819f83c78068116a366a5dd105e2Virustotal results 27.12% Heodo
2020-08-19INV_9638.docdoc 0440f355f55d3cabcb1120d2fed5485a39fe15b167e0d9a0b69f0f31f8374997Virustotal results 26.67%Heodo
2020-08-19August Invoice.docdoc d69e7c1cc00bca634b35c3ad6f47a9682c9bb54a804e431c357f4d4b2a41619bn/aHeodo