URLhaus Database

You are currently viewing the URLhaus database entry for https://www.liugehan.com/1/anc3976072749662ueqqpq7wk94/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437174
URL: https://www.liugehan.com/1/anc3976072749662ueqqpq7wk94/
URL Status:Offline
Host: www.liugehan.com
Date added:2020-08-20 10:04:15 UTC
Last online:2020-08-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-20 10:06:05 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:16 hours, 23 minutes Good (down since 2020-08-21 02:30:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21FILE_HL1569959027IJ.docdoc bae16ea340cc512d6e1934d205bb3f0e34da81c10bbdf1a411b338c91f415c03n/aHeodo
2020-08-21NY7614527134GE.docdoc 1125770ca72ec38466e63abb84b14f1128a7b5fdee91ab098dd25c53230e1537Virustotal results 30.00%Heodo
2020-08-21XD_31670206.docdoc 0a10c7547caff2ef72359bb8941e5b1d66920f7ecefd54c795b7d18c1474ab9dVirustotal results 30.00%Heodo
2020-08-21PO_08212020EX.docdoc cf949407cd2ac080beab74ad3f668e760f555bf85a0b919c14580aafb5c8651aVirustotal results 30.51%Heodo
2020-08-21ODS_080120_LZY_082120.docdoc 827b61d3f0f0d3d42ee69919ecdb9a190e3939c7d32cf425f7cf355276a3d2d4Virustotal results 30.51%Heodo
2020-08-21INV_PA4515866481SM.docdoc 3c86a0b190ac5ab87b216155e1a11d7a756739986e3545d994fce52d209cd64cn/aHeodo
2020-08-21INV_XKJ_080120_FGY_082120.docdoc 5aef84eb7042aec5b21c949a61c3beb6aae3ed2e1d897d383e802a60766af3ccn/aHeodo
2020-08-21FLS009JPOAVPKBU.docdoc 7523d22aeb84f9371a23ac8932c4316ea64ba34548df83083e4110ab90ce9cabn/aHeodo
2020-08-21INV_2674804558562769640256.docdoc 87fa434c22634148cd773528a464946457014d363c09cfe28a9a28b69f14f136n/aHeodo
2020-08-20FILE_LHYZS96M7QS3ZQL2.docdoc 2a1df4345631fb171486a4030f429df645518685e10efd27e6c0844ef61640e2n/aHeodo
2020-08-209I6K8TPM.docdoc aac3f9b6d09a48b999dbe421aba8e36591e5f245f960a292bbf0cd518c23b922n/aHeodo
2020-08-20INV_52530281.docdoc ea9a29f42ce90bd0cc4aa2b4758dc76ce4a5d639dcbe1ee8f4f0b61632793577Virustotal results 30.00%Heodo
2020-08-20FILE_OG6U71DBBRCW.docdoc 172af56801cf4f253a30974aeeddb1910408d1417b4d8bffbefe887436c3b633Virustotal results 27.12%Heodo
2020-08-20REP_TG0146727468MC.docdoc ba76ba6e85a81cbac52654f9de3f6b2e7d3416f2bb3245be7a584944a9e7949fn/aHeodo
2020-08-20INV_XL3341477752FF.docdoc 60222c9a16cecc0e2cdbc84cf33986aa7663cbf80321a3106f4dc0b096529401n/aHeodo
2020-08-20DOC_4R0GT0SIW3WXH7A7.docdoc 0c03dc40a8db0afc9ae714106e0bf60601869368336a60842cde31c0a3c8b55dn/aHeodo
2020-08-20NKO_080120_EOE_082020.docdoc 02beded3bf97160a812d8bd478ac0f798e12c3b82c464bb8429c8a5d78ae0c3cn/aHeodo
2020-08-20BAL_44792605.docdoc 713e8a1be959b7dd6086d6db1966d903ebbcc7c9b3df5fe7d7d5e0033bcf4f4fn/aHeodo
2020-08-2067014442.docdoc 3d3214a91f8fa0fe6c54f9de7d331ac31f1a562aa0c0b0e33fb5aef75163ff95n/aHeodo
2020-08-20BAL_TIR_080120_PZG_082020.docdoc dc62b29f01e0debdb807f4adaaa4c22ca3f21e5fd5a48e7b2cb6b994d76cb36aVirustotal results 23.33%Heodo
2020-08-20JO5UH8Z3ZIL50M.docdoc 62aaaf61f90d1c3f0c657fb7c0698dc7e72492a3e762c2161612a93b9ffe2aa1Virustotal results 23.73%Heodo
2020-08-20TJD_080120_PIH_082020.docdoc 29b52f890109db1441bb1fab0d062383405b49e076d6f8c04c40644a9cfda15fn/aHeodo
2020-08-20REP_05281862.docdoc af814b93d391c55cf505da148f1c2115049dda290499697b1b91cf51e099828eVirustotal results 23.73%Heodo
2020-08-20RY7047618472DR.docdoc 66adaecff904f859044c0d2aacc5bf77afc7928a3827c0e75dda7e79c0c29601Virustotal results 22.03%Heodo
2020-08-20DOC_FJ4357526955VL.docdoc c3fded67568383b8de3ff5c451ac7182cddaaec771851a6a262f47c68edebae9n/aHeodo
2020-08-20KN6VUMESYZ.docdoc 0fc24e52f38dc2987ac5826abe05dc4861ea6207d44b82b557222611f19173c7n/aHeodo
2020-08-20LPE_080120_VNC_082020.docdoc ab47a062dbbd97fae72fe297e5cffaea9d96c74395b5e6e3113c55364df5f6a1n/aHeodo
2020-08-20O_NLX_080120_KEE_082020.docdoc 9f32a654f894dafb884f98c4e30ab391b1fe3f15478273bedd8397903990c781n/aHeodo
2020-08-20G_CJP_080120_ZVT_082020.docdoc 568471d2d31e15f9b46076ae0167cdda7da49957b7cb120d330a0e450bc2c7f3n/aHeodo
2020-08-20FWZU_2771651203200498313822.docdoc 7d25d64f715231e2df3f268734ba75f0b09e05794c9ebba4faac4020c883d770n/aHeodo
2020-08-20BAL_589O4LPCDL7Z.docdoc cc9254149ac0a5f25e859e00fd4ae509b05a23e42d49708d4c0a15e4628b1c66n/aHeodo