URLhaus Database

You are currently viewing the URLhaus database entry for http://huabaogame.cn/wp-content/o9sx7j/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:532559
URL: http://huabaogame.cn/wp-content/o9sx7j/
URL Status:Offline
Host: huabaogame.cn
Date added:2020-09-16 14:01:44 UTC
Last online:2020-11-25 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 14:02:13 UTC to ipas{at}cnnic[dot]cn)
Takedown time:2 months, 9 days, 18 hours, 49 minutes Bad (down since 2020-11-25 08:51:44 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-18N_WPE_090120_PXT_091820.docdoc 84015141ee67fd7d83bb8c912c6b0b32a1caf9d27e65b62d47494985973d0c45Virustotal results 32.20%Heodo
2020-09-18REP_682535118370532175043179.docdoc adc4c37ef10a1f8cc10c505ac5b3d8e294b31d5892d651c416b601b151f90e74Virustotal results 30.51%Heodo
2020-09-18V6YSUFYN2A.docdoc 2d14279414dca849e4148148eaa21237c4c7a73d826fb02538c7bb2083e4fb1aVirustotal results 27.12%Heodo
2020-09-18Z7BUUBMNLWRIA.docdoc 03dc985b52725fd858b9aa8c59742e209b646a9bc6d49f57884f15a187e2bc3dVirustotal results 24.14%Heodo
2020-09-18J_FDU_090120_FUR_091820.docdoc 8374175eca948acc27889c306139abbe9dfd4cbd93b05f1487c379cc1d213e6fVirustotal results 24.14%Heodo
2020-09-18D_IH8559775150GK.docdoc 2121c5bc91b394da5845d8effc92948979f57c4bf252ffd09451fda76e1c273bn/aHeodo
2020-09-18FBD_090120_OBK_091820.docdoc b58b532ed578092ac8a863ccb0eca5ca78a76c32aaa672f253524fdad31ca12cVirustotal results 20.34%Heodo
2020-09-18BAL_69OUHYN2O6ME1U.docdoc 83676faad35894bb04262d898f1279995a52ca4f91f343223e0403b6c915311eVirustotal results 49.15% Heodo
2020-09-18REP_SPO_090120_YSK_091820.docdoc 0ee056bc50491229f8d2446fcc124112ae7ca2705f26aaa207e11537c0872e13Virustotal results 50.00%Heodo
2020-09-18DOC_RS0967017900VI.docdoc 01dc05c389198097e73f0e51d7e1ea7d9038367c30cf1e0408129374d3ed7db3Virustotal results 49.15%Heodo
2020-09-18N_PO_09182020EX.docdoc af0e40cc260afaf98685419c7a7e2a7bb5071876da22daeafb069c208b8a9ff1n/aHeodo
2020-09-18FILE_JH3577001535ZQ.docdoc 4fc5f9e0ee25a110929851c3a515b195197663205e6fec290ba9b86b0228af11Virustotal results 48.28%Heodo
2020-09-18DOC_PUO_090120_TPY_091820.docdoc dc0b178d082fb9ef3479c57bb72a459f9129a9dec9ae09543e29610b27df1baaVirustotal results 48.28%Heodo
2020-09-18M_5UTFU1S22LW.docdoc 2111e686944a54f955abb3629f1c0ea08c05a3f1dd451181a8612dbcf4e25cc6Virustotal results 50.00%Heodo
2020-09-18DOC_GYA_090120_GKH_091820.docdoc eaf897448ba42c47e03919da87640483febb9e38c0f457471d5b91d0bd6b99e7Virustotal results 46.55%Heodo
2020-09-18VYH_090120_IDU_091820.docdoc 1121962d0a0d52780b13618c7cdcc2916ea8ffdcccb17ae0e54e0b9f8799c5eaVirustotal results 42.37%Heodo
2020-09-18DWM_090120_PUF_091820.docdoc 8de1f0bc21df74b36c7d23af7047d1e92050ec37ed0daef2adadb8dee5322488Virustotal results 40.68%Heodo
2020-09-18X_PO_09182020EX.docdoc 88ef0981b06e7ac4b9df459d7c10edc857fcf9c170057b9220ef9ddfd550f06dVirustotal results 43.10%Heodo
2020-09-18BAL_16433623.docdoc 3c558e63407682d8fee665283a24bb73c5839f85317215925264c1b15071b061Virustotal results 42.37%Heodo
2020-09-18SS7996730000LZ.docdoc bf8ba8f948673c3556726edb8ae210bb81ee962e4c6a15cfd27e3901396960a4n/aHeodo
2020-09-18FILE_776956146697506999304.docdoc b93adb958e71ae93847f4db73ae4fb7f9f596e3f9ff08cb951842dfa36911795Virustotal results 37.29%Heodo
2020-09-18DOC_RQW_090120_BUY_091820.docdoc bb86997dfeeb53c0434119028526baad7180e7705c9f111b56b3b0e56e37ae60Virustotal results 38.98%Heodo
2020-09-18REP_MYS_090120_IQV_091820.docdoc fd659c59f931854b96e0428e622a370da964253713c66c1b28343011322629daVirustotal results 36.21%Heodo
2020-09-18LSL_090120_YRI_091820.docdoc f6bd46837e705aee39428d412f28116876f6351e1148b7ce01d5e1848b7d0061Virustotal results 36.67%Heodo
2020-09-18FILE_0H2O3WO1.docdoc 230fa7a324c31b742bc3e78cd724d571d7a462ba188b8e6dfc9f7060cb24fbc6n/aHeodo
2020-09-181381194902171.docdoc 344be8e47a1c334ca0f6e8d6383c509d62ca9004f050e5a368e064e87e2e947fVirustotal results 36.67%Heodo
2020-09-18REP_47031344.docdoc 5c9ee841d3f2ca4934e2df7970319d3d7eaa875a68f3df8f691f19191fd138feVirustotal results 36.21%Heodo
2020-09-18INV_222310873865.docdoc 6885a68b8ea6eddc639d7f787451c8f7d98f44a57f7a17d48e5f93cb4aaccad1Virustotal results 34.48%Heodo
2020-09-182189308491099718637906000.docdoc 09c747a3e72d8531c6bc31fb7da3dd71c0112e6bdc7a08c92794adbe46857574Virustotal results 33.90%Heodo
2020-09-17ZL7149696585JY.docdoc 36d46656d6969e3946e5b7d590c3f84bee9577d16dc333b05a115c41760636b7n/aHeodo
2020-09-17A_2360527823638022384596.docdoc 07fe17bd8243f8e0fe98a9a39e811d8179edde1dc7b144a55f8bde0662ff8ac2Virustotal results 33.90%Heodo
2020-09-17DOC_427066466422919114939456.docdoc 3d0e327579a0412b41e40642776caf0be54df0872df9e9ce553e048802249ac0Virustotal results 33.90%Heodo
2020-09-17ALS_82910031.docdoc ebce78b8c9a54b4d497ed1c424eb689cd0959596daf9f6748a46b65aa84b91dan/aHeodo
2020-09-17M_PO_09182020EX.docdoc 9c119c1d39a1e41201dfbb087466fa543558f959d147c3e8ef77650beaff2d9fVirustotal results 33.90%Heodo
2020-09-17XVHACBY1CQY.docdoc 794d05a964943c6e59eef584b6bd5ee060dec7907a990ec1a0d71260e641c74dVirustotal results 47.46%Heodo
2020-09-17INV_GZ0032872516JA.docdoc b0fdd6bc85ccfb2d9e1eddb4f79f8dc13ae60ca8e27e00e0ddc0e89389dd67d5Virustotal results 47.46%Heodo
2020-09-17INV_PO_09172020EX.docdoc 42672053a8a7951c0df29a2a4de07128b0577be82c17609a53a93556faffb7abVirustotal results 43.10%Heodo
2020-09-17INV_PO_09172020EX.docdoc 55f67049f14332814d65bbc5690f2538dd7fe24edb943627e039a7ff43ab1fb8Virustotal results 41.38%Heodo
2020-09-17Z_PO_09172020EX.docdoc 03de8778d73e8753ae7006da7b533c87ac0ee1c1552d06188e045d5d578782a7n/aHeodo
2020-09-17FM9446127777EI.docdoc b1c4f3f033c7084b7df61be8340d0190e40a7ed5742d46dccb477e27ee853c96Virustotal results 35.59%Heodo
2020-09-17TT500JNGD.docdoc 6f259bd35269f76ac42871f5c84e9d480c5ab4b878108a381a7040a8cc0b5434n/aHeodo
2020-09-17FILE_9626615263435980951.docdoc ab673a4d98deaf332cd304d7285159dc8a473d8fb207d7746403ecf3e81371d7Virustotal results 32.76%Heodo
2020-09-17PO_09172020EX.docdoc fabd2f3729de07ef5f673b245597b0d770876cb520d02fe15d4e9e62c7c7efdeVirustotal results 32.20%Heodo
2020-09-17DOC_WRY6HRSFASB81.docdoc 9ffdb4d90517b3838da2fe89fe09c33a7351ab0d5b14173bf9674c01c88c1a7aVirustotal results 31.58%Heodo
2020-09-17REP_PO_09172020EX.docdoc 9de91f69583b1765c182e6952a78af003dd26df75c249ca6c8091fa96fbc5fedn/aHeodo
2020-09-17F_09523930.docdoc 71d6d6e89a4d037f612549e5ffbdf9a46da63f9781d662460c048dd573a33383n/aHeodo
2020-09-17REP_29299206.docdoc 1e7768f22ed163e40214a6e4cc98050525441233f7a49852621606f4eedf937aVirustotal results 32.20%Heodo
2020-09-17REP_2369947751648103678.docdoc 9858faec65e0756d0003cfd8bcf4e322ebb83c537243e039ae6e43b4893c514dVirustotal results 32.20%Heodo
2020-09-1799508350.docdoc 5a9d0acacf9a1616330ac1559a2243f80f03ec322e564298c0cff70b28014a7cn/aHeodo
2020-09-17BAL_XK1860810327FQ.docdoc a831fbca2d81fbf112e8404702e34d5012199f825fd1db85eee8d58cae245402Virustotal results 31.03%Heodo
2020-09-17DOC_HT3289759246LU.docdoc 24d870441096e99a67d348025f42e44c531b85ccc3a98c5f138e666ec44dcb46Virustotal results 31.03%Heodo
2020-09-17INV_5892761789205.docdoc 46b9776b6dcbbc272429563afe8cbf980019b5a57e1a4625c5495dd553ef439fVirustotal results 35.59%Heodo
2020-09-17REP_PO_09172020EX.docdoc ff89c1fbff53a20e37f95ba53c554cc3e185ffea3af08c722c963aced19af949Virustotal results 37.93%Heodo
2020-09-17PC5516630397QR.docdoc dfc124f5ed8d3ebb78c8d924921f3195fc05cc1aa1a635e51161dcbe1106a386Virustotal results 36.21%Heodo
2020-09-17PO_09172020EX.docdoc 9bf20dfb53d447d25176c2839e17ba601117c7a1a4f051777df513d7641ebd80Virustotal results 37.93%Heodo
2020-09-1771427590795651281452.docdoc 32824dd0392573b686def1bda2f7e63f82bec5181b405e1714f7590872500688Virustotal results 33.33%Heodo
2020-09-17DOC_76572081.docdoc ac629bfa977c9c601f69581348de29fc7da506da5a9b40c3c9111d37dbc3076en/aHeodo
2020-09-1759873663276019147518192.docdoc 803c6c54c4ebc1733d67a3a13191e80339304b93da85bfd7945fe48a0bc95fefVirustotal results 30.51%Heodo
2020-09-17REP_ZMA_090120_TIN_091720.docdoc 24b838aac8e817a378d69923bc4457869372cebb8b6db06af6eff5f41110c700n/aHeodo
2020-09-17VO6792780044XN.docdoc fd0f987936c01acfb91bb84e9e9c3e6f425f55d07887f14ee595ec418d252849Virustotal results 40.00%Heodo
2020-09-17DZM_090120_HWK_091720.docdoc 0ed1adf222903a5b3335427d554d4a74c05a27cfd1a438788c04f3b3d720c002Virustotal results 38.98%Heodo
2020-09-17M_JBA_090120_HNR_091720.docdoc 51d460db7db57fd212907c9aed23bba4891c43175f73978da2c791c60a412c43n/aHeodo
2020-09-17INV_PO_09172020EX.docdoc 595abb95ad8bea9fcd875fee5c21baaf5f829e997eb430384a8fd7f43da2e0cfVirustotal results 38.98%Heodo
2020-09-17PO_09172020EX.docdoc c3474c39b7b924e42872d74244d0854423f1a19a0bc7bf53337994e269cad134n/aHeodo
2020-09-17BAL_FXQ_090120_LCI_091720.docdoc 9a88ee70e3fe3b917d0907d5061182917ad1a2fce66ea4cea78b8a9e870be220n/aHeodo
2020-09-17FILE_WJ7658952005BU.docdoc f0c89d19ca9b6c30286a2f5a0383fee0c9516589dabbcde5749a541cb666b41cVirustotal results 38.98%Heodo
2020-09-17U_AX2746071247HN.docdoc 83208fd10a9c71a12a3e48e4231e27e17a061f6c741c37ec8ecec9050be6a811Virustotal results 33.90%Heodo
2020-09-17INV_1319727984220685901.docdoc f3905c73171c859ac62800e08e653b667959363d0f57538eb82202c92543f12eVirustotal results 30.51%Heodo
2020-09-17INV_20064069013624759148.docdoc 8e99f89167350bf2a136c964cc8a1321455466a47090ff97ea49603c3290e95dVirustotal results 36.67%Heodo
2020-09-17DOC_O1HVZ4UUNF308A7.docdoc 8bed6a4e027b38076c316eb5378c9d60d8fd9305217dba0e315e93974091667cVirustotal results 34.48%Heodo
2020-09-17P_PW0926004496NZ.docdoc 6ae2e4149596565feec5f8af0750c8e0a86040b93c237bd20be37f723bbba750Virustotal results 36.84%Heodo
2020-09-17OUDQQXT8LQ.docdoc 7787b958e5df87b1f31bc7382f7b5ff4b6bd764b807e381f75b8b2756623f393Virustotal results 38.60%Heodo
2020-09-17INV_FCL9F7HDW4.docdoc 430ef6af760d2105f3c14655f66ff5dc191916c938a26256085965a4a536c827n/aHeodo
2020-09-17W_48330593.docdoc b1e7a7277e944331a98e7ae6a5910af8b595bf329d5da053469800cdf447f2c8Virustotal results 30.36%Heodo
2020-09-17HH_792935955428021838.docdoc 3cf8f34ba881699b5932783c60c591a6b88b1523d772b1fa292425764b0aa3f8Virustotal results 28.81%Heodo
2020-09-17OK3604040523CD.docdoc 1a487a6af75caefff2748862adf7200a692c1e5f6453c1d86ebceab252b5bd66Virustotal results 25.86%Heodo
2020-09-17Q_003694199578035.docdoc 409d5db4ee06957895e043e25c81a8d9b2438a172c248bfc3f149c6c947e3ce3Virustotal results 26.67%Heodo
2020-09-175422431219349.docdoc 53838205956eab8a004b3f1cd4ecb92e6cfc4eae4cb978b4dafd2a8560c5186cVirustotal results 25.86%Heodo
2020-09-17REP_PO_09172020EX.docdoc 8f96a4ee289f6093a2f1afe8c584cba4a802c054ef22fde70d451254191872fdVirustotal results 25.42%Heodo
2020-09-16SIQ_090120_GIK_091720.docdoc 66bd50b4b2f0524aff6b9f64fcad5a686d04778fc56eae470249da88f7c40077Virustotal results 25.86%Heodo
2020-09-16FILE_RQ2281336328NH.docdoc fd4fb3464a7f787ee4d5b1795fe7b4d8ffde4a1683fc6620602fb78ba52f52a9Virustotal results 26.32% Heodo
2020-09-16FILE_IC5343780224WE.docdoc 73158e3c574c5cfbe98520ebb3b8c4270609205751d997b87414e5a43980f960Virustotal results 25.86%Heodo
2020-09-16PO_09172020EX.docdoc f8be1cb32fdc9776f4b599f4b99eb0315d3fccebbdc850498b96f6a65fe9e02cVirustotal results 27.12%Heodo
2020-09-16DOC_17844964.docdoc 76bf8d09a314a6ed1f11e8794d3027fcedcc3762677e37d8f7a304e4d370837cVirustotal results 27.12%Heodo
2020-09-16DOC_5526859575898677192655231.docdoc 11edbb83a5be58e02605322f9c28134420f1aafe0e30a23b264ef751657c70daVirustotal results 25.42%Heodo
2020-09-16GZG_090120_LVF_091720.docdoc 85ecc831aac84128028e315d8229777d99b91e6adba5a437b18e0f2a3c34e76eVirustotal results 25.86%Heodo
2020-09-16Z_JPY_090120_WEQ_091720.docdoc 2d28945e5e6a8cb9f9e82d32bbff50d953e72e8f55c46e910c596d92bf646963Virustotal results 26.67%Heodo
2020-09-16V_NT9422006805TQ.docdoc d30169f108ec72fbaf16bb8726e798602988e1c42a7b3020b0ef0ad0572f9625Virustotal results 25.42%Heodo
2020-09-16OLR_NU8459384077LO.docdoc 1ecaceaeb20649c823b3a63accf639925ba8e4c350b2509496c04dbd622d5d4eVirustotal results 25.86% Heodo
2020-09-16706940696650698034.docdoc f656f7fc2ac175767aea79393803f493b18211403a390c2daf9c5dae720e26e3Virustotal results 25.42%Heodo
2020-09-16DOC_69650817.docdoc b2bfefad5d4d6a3dff230f61a9c4b055d5ae4b37b8fecca5550317c89f615504Virustotal results 25.42%Heodo
2020-09-16DOC_87246241.docdoc b3f921be965718a9741b8f63d9b29dba0345f98cdfda7a0cabae90ffabc8043an/a Heodo
2020-09-16PO_09162020EX.docdoc e247f4f69c1be4c95bdf6687e2ae1adbd1635c126ace3b544ad989024da5fb3cn/aHeodo
2020-09-16BAL_PO_09162020EX.docdoc 7ad1bb86cc5ab4b2563548f2fc53faf9ed64e5216c895c9a425aea815a45b6b4n/a Heodo
2020-09-16FILE_NUQ_090120_QOR_091620.docdoc d7f12b14c351620ca64769a126560507c4746cc966510d04d0fa882e521128c4Virustotal results 41.67% Heodo
2020-09-16C_3K9MV9NKUS.docdoc 37af168ebcdcec12d2835ecc3a569839ed4660717927ae3ab0cc6a4b8a733012Virustotal results 38.98% Heodo
2020-09-16REP_PO_09162020EX.docdoc 278fc88598a0bfe49be55465fdb975272c6315e3845d604caba7631cc5f32595Virustotal results 38.98% Heodo
2020-09-16FILE_CGLE9I58US7US9Y.docdoc 25d1788ec133f048b97e9f205cf6c7b69e50ed0418bd9877553aba8a7bdaefc8n/a Heodo
2020-09-16WYW_090120_RCM_091620.docdoc e9e98328d96157a0fd47c6abe8d1d60d8521171a61378aded651b274a0619993n/a Heodo
2020-09-16FILE_06100779.docdoc 234a1653236e959e6329aec64c1de58538db56e66156f95517c05b62487d70ffVirustotal results 38.98% Heodo
2020-09-16INV_20786542.docdoc b9a6ff1bdbfdc506e17b3e590738e75cae3ce59614c8a77074df2b1d2abc3801Virustotal results 40.35%Heodo
2020-09-16N_XTE_090120_YDB_091620.docdoc 557b0821e60a4ec8b803e5fc3f9f0aed39d988bd8d1bd1ff7904c5f07fb24e1en/aHeodo
2020-09-16INV_49750607.docdoc 6820256b4c1c4c5b50146126f828d2317ef12e023043a390611fe9b036cfe638n/aHeodo
2020-09-1612925126.docdoc 25a6131ae25ca2ee10362cdc735535fed0c9bf3698dcb965b751015139477987n/aHeodo
2020-09-16CT3932990988EE.docdoc c714262e7ca075c2816149ba0cf39cd465e11d7020a2675a228f4180df6163c8Virustotal results 32.76%Heodo
2020-09-16INV_NIJ_090120_NQQ_091620.docdoc 0c982fd7e6da85d772a410a46a6569667df380d6fd19d4c597ca1a0f30c140acn/aHeodo
2020-09-16UZ0OS6M36BH4J2.docdoc 361d848b59beb5b40b7839f66735d926f31725d38136435f01499fb0e4a66463n/aHeodo