URLhaus Database

You are currently viewing the URLhaus database entry for http://cwsec.cn/ikmh6ypf/Documentation/9fg2ms/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:513045
URL: http://cwsec.cn/ikmh6ypf/Documentation/9fg2ms/
URL Status:Offline
Host: cwsec.cn
Date added:2020-09-15 10:31:41 UTC
Last online:2020-09-16 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-15 10:32:17 UTC to abuse{at}chinamobile[dot]com)
Takedown time:18 hours, 1 minutes Good (down since 2020-09-16 04:33:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-15BAL_18898546.docdoc fb643feff479ae9885669488962697766e6dbd2da0ca79b1af07c225f60b0527Virustotal results 30.51%Heodo
2020-09-15WG3801205247AH.docdoc c5d3e05040b167eefc00d3bbe6cac732b32b88aac3d3c6b7a640e8abbd9ef10bVirustotal results 30.00%Heodo
2020-09-15FILE_KRT_090120_FKV_091520.docdoc a27e34af3dd6de2bd605581cce065e11a651c8ee0544d3ea0d7419a9a3daa3feVirustotal results 27.59%Heodo
2020-09-15REP_57630085.docdoc 0a027ac005f0ab69b76b7587c1f5ac68377f933bb7d7aed7741899867ccd0032Virustotal results 24.14%Heodo
2020-09-1568773222078204494592.docdoc b701933f7ffd80577c3d8ea10ff3e373b79a72366c0ab41e91d424cd237a77d4Virustotal results 27.59%Heodo
2020-09-15PGQT_1248568170468.docdoc 9558bbbb8facaeebb9539a63e639acd60d8fffdaa69c92c05ceb23e26e61c41bVirustotal results 27.12%Heodo
2020-09-15PO_09152020EX.docdoc 2604650b41bbef926f06832278fc8850576ae9d1fa0fe497bc9129f9c8b5793cVirustotal results 27.59%Heodo