URLhaus Database

You are currently viewing the URLhaus database entry for http://hxtoutiao.com/lh0wh/closed_v26c7lxAx_mKisqRStUxqOY0n/interior_portal/EqARawXBVM_2K7oeocr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438494
URL: http://hxtoutiao.com/lh0wh/closed_v26c7lxAx_mKisqRStUxqOY0n/interior_portal/EqARawXBVM_2K7oeocr/
URL Status:Offline
Host: hxtoutiao.com
Date added:2020-08-21 19:36:05 UTC
Last online:2020-09-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 19:38:02 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:1 month, 5 days, 22 hours, 4 minutes Bad (down since 2020-09-26 17:42:21 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-23MES 20200823 ZHF620.docdoc 341e9a1b4252cc46eaaf7518c4a09a3f4caea692bb29798760dbc23601731ca5Virustotal results 62.07%Heodo
2020-08-22LIST 20200822 J0143.docdoc 73671924a4061029b1e17f7269198c454535d36894f36d3874eb25a48aff64daVirustotal results 57.63%Heodo
2020-08-22REP-20200822-USI98472.docdoc fa2a1d4f51b1afa12671d5fc760dddc993ff2ef768e3edec3d54dce07e1ad744n/aHeodo
2020-08-22Mes.docdoc 141ae7bd833a21adbe67d57ce9791cdd5ca210777ffa0df005892c94b01f78aeVirustotal results 57.89%Heodo
2020-08-22Mes.docdoc c101788996fd465167fb930e0ee443ba396607808c74fa8ded82e0bcfa9f7f64n/aHeodo
2020-08-22dat-2601.docdoc 6efb916faef60ea0d4799e040975dc4ffdef08bb0aa5b15385f0bf6fbf426407Virustotal results 52.54%Heodo
2020-08-22MES-20200822-701425.docdoc 44be463c465e4e229df4dcea734d505a424cb65601ccdcd1348117882ad9038cVirustotal results 45.76%Heodo
2020-08-22File-559753.docdoc 93517c3302157331caeed0ad1170abb2e5b16b1336fbb649fff15fd94a604b07Virustotal results 35.09%Heodo
2020-08-22ARC 147852.docdoc 0d62984f302057e3206f8ffb7af2b01402726b9a6d7146509f4420e5aecd80e5Virustotal results 34.48%Heodo
2020-08-22Mes 2020_08_22 20096.docdoc 41e117890931d05a1eaa233b22b71bd5de72311491f54ccd76c7141d37a2c2a8Virustotal results 34.48%Heodo
2020-08-22INF_1685598.docdoc eb03beecb5dbcd12f2191ec6980a4b9abb56b43907f1bff900378a80daa3699aVirustotal results 35.09%Heodo
2020-08-22Mes-2020_08_22-0922848.docdoc 7e23b5d1c6802917ef79115b4b1a242be7cd7465aa52247ae9d01092bcb49da1Virustotal results 34.48%Heodo
2020-08-22INF_2020_08_22.docdoc 46821d694a7c94efbd9aa8cf863377946de88c036c813decd85ed3cd8bfb6cdeVirustotal results 34.48%Heodo
2020-08-22file_20200822_PD393972.docdoc 4cd4ea7314c2268401c1395af0e562dcb530b081eb42c55152e03990a62bc4eaVirustotal results 34.48%Heodo
2020-08-22Doc-20200822-093605.docdoc 6c07e097125602926df0ea025482c72e280b3f4b72f2fe5f0603c0b23811ef4aVirustotal results 35.09%Heodo
2020-08-22arc 2020_08_22 58295.docdoc cfe9b00366296aa5a8c8cd03ea3bba651df2c931c4bb37c6ad12e087dc3849ebVirustotal results 32.76%Heodo
2020-08-22ARC 20200822 00026.docdoc bf613424225d5260ce91473ce6ebfe8adceb0588ea8fd5bb613437a9ce55f5cbVirustotal results 34.48%Heodo
2020-08-22file 20200822 OLQ447.docdoc 0de50412884992ba3c3d7727aed28ea0d5c6bc3c8a2dfafaefbe05b65c853df8Virustotal results 33.33%Heodo
2020-08-22Rep_20200822_A530834.docdoc 38ad7eca5e40a7294cfd489d269d4dae16920886c3e5b69674dfffb9e75daeb9Virustotal results 32.76%Heodo
2020-08-22inf_2020_08_22_400.docdoc 554418877730d4dee3eb89b119139b9525488871911b50e38b4264d4e02aedf0Virustotal results 33.90%Heodo
2020-08-22dat-B08837.docdoc 3c425e91c6383bae63a5768f423894b4db16efeaa0224ff93d8e9878e0422ff9Virustotal results 33.90%Heodo
2020-08-22MES-2020_08_22-311510.docdoc f3910c447952615a78e47e19bb4d3f313f015a74e603c83b15fbe812d5437d4cVirustotal results 34.48%Heodo
2020-08-21ARC 20200822 E873280.docdoc e24041660f6d832a70a84a90a7e3b77497c2698f58c28b3b9c20d985d461aae2n/aHeodo
2020-08-21Arc 20200822 2327.docdoc 5027992f3f1c092f72a1f03d8617eb280d1a262c52e16a3b3c06c09e2d2479a3Virustotal results 33.93%Heodo
2020-08-21INF 195991.docdoc f303289ccfa96ee597e4ed497e6aac8ca9ce382b04c40f5d17f21b63228ba66aVirustotal results 35.59%Heodo
2020-08-21List_20200822_3633851.docdoc 0f3ea8a85b8cc1a40f92aa8b39d9a728d5dcdb79a209ffdf5e63cb37054dea55n/aHeodo
2020-08-21Doc_2020_08_22.docdoc 477e5903ab426d0f8d08786b9ee6332240fdbcb967dac106e7de5705a84ef512n/aHeodo
2020-08-21doc 20200822 0898795.docdoc f5c802f7ea024701b5da84ae6654fb6d08915fb996f178622a4d2808016cf0aen/aHeodo
2020-08-21List_20200822_PA151848.docdoc 66c2feab23d975284146875a86d3d1293e68a12485b2ca65594e8d5d9f1bac2en/aHeodo
2020-08-21Rep-LC1413.docdoc 603d629a760eac3335de2eea279b70f0eb80380c0b8028bc31da451010d718ffn/aHeodo
2020-08-21File_2020_08_22_8849.docdoc 888576b006def3935c63b3044add14aff8f8a2f56a1a52592f895f1182d25ce6n/aHeodo
2020-08-21DAT 20200822 3129578.docdoc aa5a4eb52d5e8701ff524488939ee045bb87e08a430e7297908342ee32bfbcc4n/aHeodo
2020-08-21MES.docdoc 045722a598eb4956a7229f49d8208b80677db2ae6464d4916ab9908d961bc1d2n/aHeodo
2020-08-21File-20200821-562.docdoc 48a7604dcb51f7fc9e0bc37a40f2c7dcde23bbbacf719ae5494c9ed2c795a27an/aHeodo