URLhaus Database

You are currently viewing the URLhaus database entry for https://haikouweixun.com/jn5/form/cQCI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:446020
URL: https://haikouweixun.com/jn5/form/cQCI/
URL Status:Offline
Host: haikouweixun.com
Date added:2020-08-28 13:04:38 UTC
Last online:2020-09-26 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-28 13:06:04 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:29 days, 4 hours, 52 minutes Bad (down since 2020-09-26 17:58:45 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-29INV_325585.docdoc 5df4f10d255d1733e9450ecf67d166c73f6f29bb36efe88d6093a31d31ce0ad4Virustotal results 45.45%Heodo
2020-08-29form.docdoc 867f6ccabf112c3105f544c490f65b90fc6e09b18681e1ed7eb9619045ad60f6Virustotal results 44.83%Heodo
2020-08-29Inv_448241.docdoc 85a2ab80740ab3e2eee9aabd6943711cc3ea3d87dd795a473b3870bb33861ef5Virustotal results 44.83%Heodo
2020-08-29N-080120 DEVB-082920.docdoc 71df89329f89287c29afab47756e8927fdf739cf5086d353a967cf47b6238aacVirustotal results 42.37%Heodo
2020-08-29Inv_76517.docdoc 3a8a42c319462b67597a9fefae7c60c0a3917018eef2b0bba8bb02980e6ffe02Virustotal results 44.83%Heodo
2020-08-29INV #060709 FOR PO #03240052.docdoc a521f45b1de9146a13bd8a351c6999c9f2530183305f06315a2e681690ab40daVirustotal results 44.07%Heodo
2020-08-2901446999.docdoc 72da2757545a5a82bac55bc0d9ed9ccb5beb853d5af23f8497e6c3be60b5f493Virustotal results 46.55%Heodo
2020-08-29Payment status.docdoc e025c7438abe6ad8be1077eb7feef8b418706abcfbd2a10abb2023dc6dd7bcf9Virustotal results 45.61%Heodo
2020-08-29Form.docdoc 1f42096613819f1b1cf2ea163ea893ccc965e8b3fc9beb61d4b0a967d2374bb5Virustotal results 38.98%Heodo
2020-08-29Payment.docdoc 67e47cc8c442792139e942d1ecf8f3b6c6137f4c61254ad4dab1aeb052e68bdcVirustotal results 38.60%Heodo
2020-08-29INV #065270 FOR PO #55538740330.docdoc c98ebc2ba9a8e8f27e921e635f8742cdbb64688b48b57e7300575ccee61930a5Virustotal results 35.59%Heodo
2020-08-29August Invoice.docdoc 612c6999b9e40c8779f0ee1fc54ec75c362cced1953097d7a1cd3cc80ed75b2cVirustotal results 36.21%Heodo
2020-08-29invoice.docdoc 60f661d0a3444cbf34c1c249572f83e9d7c73bfcf4aec6790b856574c1906aacVirustotal results 35.59%Heodo
2020-08-29Inv. 040511.docdoc 5354855cf9c113bafd6c1284faf05ad3d8937c59843f31207ec11ae9ff32454cVirustotal results 35.59%Heodo
2020-08-29PO# 08292020.docdoc 5f5c3281702a2ecabc7797e25671a80f30335f7d4a4a6644b230346b7bcfe942n/aHeodo
2020-08-29Invoice.docdoc 7a2ea6bf67afad967a724ca65954848493d2b3d60c68a583219c0d8acff06db4Virustotal results 32.76%Heodo
2020-08-29Electronic form.docdoc 55e432b28c27aa0f65c75c46dda9a367a1d97420c5dad4b07cabbdced34058d5Virustotal results 31.03%Heodo
2020-08-28Inv. 0076054.docdoc acaee01eb81fad1793634836807c913a67f13ad7d260b9a1e51ef0994148734bVirustotal results 31.03%Heodo
2020-08-28Electronic form.docdoc d39436c50b9667b5827c801070c34c0747f3ec1a8cb14b0602a317fe47c4331aVirustotal results 28.81%Heodo
2020-08-28form.docdoc a457afd23063f580f5431f2118cc0936362067a7440f76d90eeb270da41508ecVirustotal results 28.81%Heodo
2020-08-28Electronic form.docdoc 975d4a820579783493877ec35f1ce5cc1e6ccf7f7a7b9d12dc72b4a5db5f9c86Virustotal results 29.82%Heodo
2020-08-28Inv_872139.docdoc df199d182f56a9ca1aa93778b0d2d4d64f1bdd2cb2800ce66935e46b0846dacaVirustotal results 28.81%Heodo
2020-08-28form.docdoc 0bd6fc0b137ab4dbba7bfe081efa83190edcfcd01b5d6e6e48f675dd6062e750Virustotal results 29.31%Heodo
2020-08-28Form - Aug 29, 2020.docdoc b89e478d217b03e8c0042bab248bd9431243f6fbe54c13d26d77b63b93c0c99cVirustotal results 28.81%Heodo
2020-08-28Invoice.docdoc d022da59e50434649d9292537c3c675835c9c9f958bf9a421d9688fb864439ffVirustotal results 25.86%Heodo
2020-08-28Payment.docdoc 96955576446f803417498ea62363fb51274e644a275afcd1086cfa9a60df1d92Virustotal results 27.12%Heodo
2020-08-28Invoice 0138898.docdoc 16b0a947af42c8da09ac18ec604070b9614465fe7afa4074b5631d2b6b4837e7Virustotal results 28.07%Heodo
2020-08-28Form.docdoc 427fa32e1296a2edfcab458af02c46f7ef53c82d98e29ab7161e5d8f8443b932n/aHeodo
2020-08-2804887.docdoc 2d126cea0296b49145f3c12f2caf2338568fa92b40810c44f5c32195d7d01ce8Virustotal results 44.07%Heodo
2020-08-28invoice.docdoc 17040e536cb711011ddfe95c5302469d68db8f57e368902fa164633d4104c7e3Virustotal results 43.10%Heodo
2020-08-280259856670.docdoc 3fcf99d952244b4dc0d194ef52b616c67cff47317237f80a392b78a96dd0db0aVirustotal results 35.59%Heodo
2020-08-28invoice #16914.docdoc 9401d8e81e54ac8c32e0d24ab51898ef9858a626cc2c75aeec9ecae380ed8be0Virustotal results 36.21%Heodo
2020-08-28Invoice #807779230.docdoc 67484a298833085645e58633dac097e76989a91be839c3c28d3e7253c04a37dfVirustotal results 36.21%Heodo
2020-08-28invoice #8804.docdoc 9fd6f0a503fcfc4d47a3035cf5d80d452de33354006ebcd57d5d74f2e2e8d1d3Virustotal results 35.59%Heodo
2020-08-28PO# 08282020.docdoc 0aa77c933e8451e7d453fdab34e946320d0682c2bd91d6ebe1889fb0d100b578Virustotal results 36.21%Heodo
2020-08-28PE0055 invoicing.docdoc ce9412446d25e1e902e8c557028566d248d0e81cac7ad062815c00d0e65b57e1n/aHeodo
2020-08-28Electronic form.docdoc eb2643323c03b0e4f951c27f3d3003dece58d31ade3490d2d2dba0c480c21695Virustotal results 35.59%Heodo
2020-08-28Form.docdoc 4119649803a8168b6e95925b6a82c14d651ac14a9f781cf7d5fc963a23f034d1Virustotal results 32.73%Heodo
2020-08-28invoice #49508.docdoc 56385c138dcd6e1f59be2fadd0cb3e78305d5a8b74de904c00ca85d68aa84809Virustotal results 34.48%Heodo