URLhaus Database

You are currently viewing the URLhaus database entry for http://zgtaiji.com/uc_client/eTrac/3Bl2OpI5DMoQyaxhH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:548586
URL: http://zgtaiji.com/uc_client/eTrac/3Bl2OpI5DMoQyaxhH/
URL Status:Offline
Host: zgtaiji.com
Date added:2020-09-17 21:34:05 UTC
Last online:2020-10-01 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 21:36:18 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:13 days, 10 hours, 10 minutes Bad (down since 2020-10-01 07:46:55 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19FILE 2020_09_19 6241591.docdoc fca26f8a9f6995a0a5dccd24f54b77b3d5c855fe48084f99f9b2da3382f88c2fVirustotal results 30.51%Heodo
2020-09-19Mes-20200919-GA5697.docdoc 2ec44c17b6b065e7bf34a965fe298674f2d0089335d479b0a504ca375f0d0c1bVirustotal results 35.59%Heodo
2020-09-19Attachment_20200919_984701.docdoc 5c8826f1210fa85335233abd36c1a1139d5689142c5842c0da0c688f104c6410Virustotal results 35.59%Heodo
2020-09-19Dat_2020_09_19_8044690.docdoc 610c4e7f9d0c567d7d8a230edc8cbe856baae5fb20c5fbebe2a43c7c7d007feeVirustotal results 24.14%Heodo
2020-09-19DAT-20200919-KEG08150.docdoc 12184c3b864ed546a8c1c0b94d18631228a2cd6caa38e1d6c332c113d327f21bVirustotal results 32.20%Heodo
2020-09-19mes 2020_09_19 087.docdoc 67cc9853ec0a3e3d1283d0ccc57907b9c5c60ff1359dab4e9456b581a3ebc3bdVirustotal results 22.41%Heodo
2020-09-19file_2020_09_19_Z712.docdoc e0343838dbe81e4a9395924017c0f16a9a100c8f03f14eb75fc8be10c72edd60Virustotal results 22.03%Heodo
2020-09-19DAT-2020_09_19-PTE86301.docdoc f5ca634bdeacd64ccc52ea932bd221762cc68524fcef2df96c77ecd777d16670Virustotal results 22.03%Heodo
2020-09-19Attachments_20200919_4493151.docdoc 6584db21f3b24953242d8d42e4ffa62e8026aebaea9f5c6b5cae066f4c279370Virustotal results 22.03%Heodo
2020-09-19MES_KZA5886.docdoc 23c8490e131915effd12a2adf737b6fb74515b1b54759d0bb237eb7392338c08Virustotal results 22.03%Heodo
2020-09-19262 20200919 O9585.docdoc 9b15f15ca0fc3748ef3b9f9a91bae081e2b5c076d1b39e7e16cfbe3a08cc5070Virustotal results 22.03%Heodo
2020-09-19doc_20200919.docdoc 000dd08101567f408a0ee2b7d095d3baa02f532ed3839f66b60b9d64ce065d17Virustotal results 22.41%Heodo
2020-09-19Attachment_982.docdoc ea48e310224317a3a93d7679dbb50ae967383d973cf7713613d8a240224ff454Virustotal results 25.00%Heodo
2020-09-19arc_6553.docdoc 1b92e7710017ee24f07eb3119de1f3556bc53d686201c428cf4538d133fa8fa7Virustotal results 24.14%Heodo
2020-09-19file-BOY732.docdoc f56906e33a9a9bd3b074b3b5c24c2e98ba58817c4c61452977054f27d0d9312dVirustotal results 22.03%Heodo
2020-09-19REP 66272.docdoc 0e31dc003b5fa4ef58751e94f3718852fdf5c75f438a8a587eac213cc8786c23Virustotal results 22.03%Heodo
2020-09-1969696247 2020_09_19 70592.docdoc b7b9257d8c50f28e5aa87090083acecd0359655c255d52dd1030c0375097e0e6Virustotal results 24.14%Heodo
2020-09-19Arc-20200919.docdoc 7234cb8db24e20ba0abe1fb9f9a177573e1e83122a6f3b8debd45e34b67a7775Virustotal results 20.69%Heodo
2020-09-19rep_2020_09_19_Z94281.docdoc cab5f70f9a6d1f300828e8c715696273befca7a141ca5e75b69b5a408ee432b2Virustotal results 30.51%Heodo
2020-09-1985819271 2367248.docdoc d6ae83f018f7848b69c8e3f73f71992caabb9a19ab572796adf043a08bf46c11n/aHeodo
2020-09-19mes_20200919_81366.docdoc 4cd1338ce62760cd78c5eeb9a795195c5801a562e6adb2d0f0984640a5719bc3n/aHeodo
2020-09-19Mes 2020_09_19 6152.docdoc 32f41a25d60eecd90e5e66e0ac2850bd6fbe4f97ddb2dd1e1c3998ab3089f391n/aHeodo
2020-09-19mes GOT8021.docdoc b81a03fb70bafe2e7fd636ad7371dd77cd8fb21b274fda2b5bfb4b2d4356e91en/aHeodo
2020-09-19Mes 2020_09_19 BG353027.docdoc 0f8726a2e1ed31116d9cf065548921ba480bafb9467bbbccc96ec094859734e7n/aHeodo
2020-09-19Dat-20200919-2916644.docdoc 0af0e4a065d036488bc54043089879cd5e6b6a4db8c164ba0b7f45140aa616cfVirustotal results 25.86%Heodo
2020-09-19Dat_61049.docdoc 5c9595da8f021c0eb6c4da08ddfff0b280e4b1f2c7b0c9a1908f8c5bd98163e4n/aHeodo
2020-09-1930011728-2020_09_19.docdoc be971e5ec9022f9fd6f2362de737a9133bda66f8e69ec70d11bba08b47f81075Virustotal results 22.03%Heodo
2020-09-19Mes.docdoc 34d91dd2c961c7932b2e9f2a6ce803cdd745ef4d3b0fd60d429858237f8e45daVirustotal results 22.03%Heodo
2020-09-19Arc_2020_09_19_NDF097446.docdoc 614c62ac24ffd787e87c3f0be186188b9c87530dcc81b1559e388c1e06d1e2c7n/aHeodo
2020-09-19rep_2020_09_19_J88539.docdoc 9e398469dae4d767b068930ed48a2283bade08114e66f158454ede4cf08d5bcfVirustotal results 20.69%Heodo
2020-09-19Rep_RWP49723.docdoc 7da90a568b11f5619217fc3f607646d3fba7a56ef64303b2ab72b8751d9308fcVirustotal results 22.41%Heodo
2020-09-19dat_119.docdoc 50e2ef861a0588af5e970bd2bd2d4d52e68f8c65d8f82b2c2f6457adc2302ea1n/aHeodo
2020-09-19doc_20200919_KWY887.docdoc 59ee3757e66be242efc0972dd6c65966fd25efedac6d7183bf2ebb22f73ed835Virustotal results 22.03%Heodo
2020-09-18Arc-000.docdoc 0d6380a49e7088513773efca368acb3a783954a2d4df49ea9b730c9e49969458Virustotal results 22.41%Heodo
2020-09-18Untitled-2020_09_19-439782.docdoc 3eb7679ffcb5eb0cd537545d2e28ad49fdb4bc89366476f731659703b6707ff5n/aHeodo
2020-09-18mes-20200919-6363611.docdoc 7e37d762b881d0b1d6897e3d3c7ae449bebad8d250e6573923944ad8c0c22c28n/aHeodo
2020-09-18Untitled-2020_09_19-QNA3413.docdoc 906eb841dd00ed7c09bdb5dc7c0d3722f6313536e45201301a2db07d0fe04beaVirustotal results 22.03%Heodo
2020-09-18579EZ-20200919-OVL905.docdoc 606c981a35630090fe7df6ea2bd78be7c01eb20f5d266ba2432b209e9bf26eb8Virustotal results 20.69%Heodo
2020-09-18Inf-20200919-9024.docdoc 03caf29484a047db9c68e15e6117f665c59b1cc6ea7cdacba9042f80149861b9Virustotal results 22.41%Heodo
2020-09-18dat_20200919_Y39657.docdoc 2cbeb14e3ad7c8a795f7454334ae6793f020780e53173535e65ddee8c2a717afVirustotal results 22.03%Heodo
2020-09-18UNTITLED S422.docdoc 8aef0f99e6ad886e7a947f5a99fd0b0016cfdd32cf2c62ad525364452c8c7c41Virustotal results 22.03% Heodo
2020-09-18DAT 2020_09_19 QS620.docdoc a4ea07f63c702a260cfc87703c09e635cf2fab0a0ed510439a57936ee5f6d4b8Virustotal results 27.12%Heodo
2020-09-18ARC 2020_09_18 TB4410.docdoc 6c10c2ec829e5c74174f1c3237f44a6aaee6d53c6fa9eaec16e8caeacc3a8b9bn/aHeodo
2020-09-18Arc 20200918 5164486.docdoc ee54db7e18eb7600da577fba32adbac6e86a7bd9fc9134fd1ed5020bc4b7b03cn/aHeodo
2020-09-18dat WJ406.docdoc 1d188489aa0c86820ef03aef6d4c6737367a5872ca87080c9fb14670099d756dVirustotal results 31.03%Heodo
2020-09-18Mes 20200918 641.docdoc 007235d5a7194d94f5ea60ef1b957c3cee5c1d97918ef115e77b1d4b1836577an/aHeodo
2020-09-18arc 20200918.docdoc eb92607adea44ca6e7b91a4626d35cefeba06a41ef29cf5ee84535d12f97a59an/aHeodo
2020-09-18file_20200918_379.docdoc 5ab22cc852aaef34ff92b6dfc926ae182c1ca84cc17ddefb9cf2340a73dd7b64n/aHeodo
2020-09-18dat-1345176.docdoc eacdcc7cf9952035830dc27f100869efcfac8117ccd84d9ea01817baa805d970n/aHeodo
2020-09-18arc_20200918_ELM564.docdoc c28856f7c6f79ce4375de0cb399c29aca9d00ba67ee4e65f86fa170ae7683ca2Virustotal results 25.00%Heodo
2020-09-18UNTITLED_663.docdoc c3b361e3ab7b82eb20f5af057abff8f96c2369d0dbc47472ab1430390ae8de1an/aHeodo
2020-09-18mes_2020_09_18_3362876.docdoc 858abd3d8e95ff9e3e6cc3248b87ee49e9a57c339a4f849bf6a8436d8c7fabd6Virustotal results 25.42%Heodo
2020-09-18FILE LQZ167674.docdoc c6f91ca4de4035eea0cee737bcea230c3a1fc1b9bc3e0b8e59e1b0cb2c212dc8Virustotal results 26.32%Heodo
2020-09-18MHB5624_20200918_77119.docdoc a5ce864f2c3bca89c24abc1fa1068e590b7df70133a6f8d4ddbfb26f3f72a85bn/aHeodo
2020-09-18881U-2020_09_18-D7745.docdoc ccb79dda93025e923e331ed559dede37b9d588886ae7a227fddd3c5e439672aen/aHeodo
2020-09-18GZK3183-4375441.docdoc c150a6907d073e3342215712f5898b7b4f1bbbd09664f2163c973bbcae0e2c40n/aHeodo
2020-09-18Attachments_20200918_58441.docdoc 7f9a58c15ccb78968557ce3d1a009c37718ab6739a1b09484c91e624c4dfd939n/aHeodo
2020-09-18INF-2020_09_18-TPO30867.docdoc 72e7bd4d09757bec76ea8bcfbdc7764868642f075916f99b6fe0623a5729533dVirustotal results 23.73%Heodo
2020-09-18944XJI-2020_09_18.docdoc 4e32005b1ea54f5b7a05f50fa7630e992190edb459666a026ebb506c2e1a2c8cVirustotal results 23.33%Heodo
2020-09-189366KM 20200918 AP3380.docdoc 2ffe410c23611da6f521bf9ea1c738509e7d399ef3fd0b539a2ac9469a132479n/aHeodo
2020-09-18Arc 20200918 NNH1166.docdoc 47dd03d21da43926252b2684001feb039dbea83bcc5753aae3d30f193a799ed2n/aHeodo
2020-09-18Attachments_20200918_MSD599.docdoc c82c3dc7341a149248f768f8f7da5e9f1ca7dcd9f2d1cd61a56386cfef07ff7bn/aHeodo
2020-09-1848457US 2020_09_18.docdoc a4e9fa7e865e2c2bae3abbd6d249ecc57198eb070b868ff767ac9220fd806efdn/aHeodo
2020-09-18Inf_KO81575.docdoc ca63d9c9e846ae66ae0030d7a8ec4041674dc2b6189b86eefad806122c65a092Virustotal results 20.34%Heodo
2020-09-18ARC_20200918_475.docdoc c344bba1f2dc6e25025c46cb5c4ad485d9f683c5f04bca7838367b8af73b7c3bn/aHeodo
2020-09-18Mes-2020_09_18-ICD385736.docdoc aed6d4341e22ca90e6f3f46dacf7d7f76dad515f651f5c75fe4362dd7848ee69n/aHeodo
2020-09-18FILE_B279670.docdoc 82e331bd54e99b710c3f3446239c18c0ac59e4b668cfcc1b78c1d4217173f865Virustotal results 23.73%Heodo
2020-09-18Arc-F6294.docdoc f764c5a489ae94b2a089f5333c8911cc6f4584805203a09110346af8f427a5ccVirustotal results 25.00%Heodo
2020-09-18Attachment_2020_09_18.docdoc 6c87c3c0acb5c7c76282b4f9327967f3405cdf95980d565c690fe1a7c6caf189n/aHeodo
2020-09-18Inf ALJ47677.docdoc ab459ec3860feec3e8cbe7e4e00f1520b317fa7671b8d088e2eaf237f3450b80n/aHeodo
2020-09-18LIST 2020_09_18.docdoc 4418e78d38e4119d63168efb8e0e4b0001f4d5de4db0d7ea9ed526aee126a659n/aHeodo
2020-09-18LIST 2020_09_18 BHC881656.docdoc 327782e36e23c26b07c924376ee2b5f73ca8a498db216fa153c0a6d4830d0f26n/aHeodo
2020-09-18mes_2020_09_18.docdoc 8a71a31b415de755bdbbbb231e79978f70d94b2a8bed5f73dad5fcff6f735b16Virustotal results 17.86%Heodo
2020-09-18Dat 2020_09_18.docdoc 507e7abb40947dfb7985ab2e1986bef80a9352e6cb5770c369422562a4df203dVirustotal results 18.64%Heodo
2020-09-18List_20200918_R240776.docdoc 23cbfb675b38359788fb1f2ea9602ba6ad72c26ca1765dfe3c24d4c61b2e21e4n/aHeodo
2020-09-18List O92931.docdoc 4f3d22c52b1b34560307bf95b348de9d6cfb59a23d6e3156d934f45e5e6a5e0dn/aHeodo
2020-09-18doc-626.docdoc 17a69b1fbc9455bd28f59830de156396f05d316f5a763dc30d20a72a81995b83n/aHeodo
2020-09-18Attachment-20200918-3402853.docdoc 8bbd95bf430fd81a07c1d7a4da8c52f11723d9377d058fa0d6fe565a94a81cfan/aHeodo
2020-09-18REP-20200918-8210447.docdoc cdbddc6e344dca0161e590649d5937d6271bd7c6fd53cdfac8ac5f235b4b2ad0Virustotal results 18.64%Heodo
2020-09-18Mes-2020_09_18-B1288.docdoc 6fc658810e553c73a9fbe5167def20b6919c2d71bd7b6e538cbc58bd147e6771n/aHeodo
2020-09-18inf-2020_09_18-QQ411.docdoc f46238433591d85d9addeec9f39f4628401a5bf8c9744cd151a5cdbefd5ae9c9n/aHeodo
2020-09-18UNTITLED 2020_09_18 559956.docdoc f7e1fe4839c50d856348e43ae96317d626904298293e3a0c3c4c1f8934847e58Virustotal results 50.00%Heodo
2020-09-18INF 2020_09_18 886.docdoc fb614dd4f7faf0c4f3c4ea8c0b77238a4b024247c5e3282a3c9f2a8a0ab24e09n/aHeodo
2020-09-187964CZ_2020_09_18_2020222.docdoc 08351527dc3368afc69b9bf7060a8f5346c318f56212006abec92f731070d67dn/aHeodo
2020-09-18Dat 2020_09_18.docdoc b2f4fe15d94caf88194505573376786dac796dedf0272c7f339e4c0455ff7abcVirustotal results 49.15%Heodo
2020-09-18Attachment CZ5509.docdoc 2a4e902462327eea660cd484d54617960e688bd970e891f9de176f2564e1196fn/aHeodo
2020-09-18Doc 20200918 PH39666.docdoc f250226924bb32a4e80192c9ae83d43710a49f1d3827052c6e75c6f53e518883Virustotal results 47.46%Heodo
2020-09-18Attachment 17525.docdoc 23b73b6d7e3d2266bcf0c20586d750bae5d4b3e873447a95e582df8e1d31f945Virustotal results 48.33%Heodo
2020-09-18ARC_8071.docdoc 2803a90ae1d2443a47eb09c48dc3b21cafff5fc1e70c87222b14a3379a757236n/aHeodo
2020-09-18594RZ_2020_09_18_MDU773430.docdoc 1cba542ea755572052ee0ee05629e5f1a0b3161fc11106ad6e2679fc5ee2a6f4Virustotal results 41.38%Heodo
2020-09-18rep 2020_09_18 941.docdoc f6255c1d9d5c191c0265b5b1fbca564c2a9f38fd1e93cb25ebf3073f0e560e29n/aHeodo
2020-09-18file_20200918_RM42062.docdoc 2d8ed5e3ab00fa8a391a74010c5c60103922c5646f56544f780c761f73b20aebn/aHeodo
2020-09-18Untitled_2020_09_18_30360.docdoc afec45f4897df0117cbcbec6972de56bd81af8ee3e6b1cf88507764596a9f927n/aHeodo
2020-09-18U03803_1358678.docdoc 8669123b64918b7f8a0706453cdfb5886208f5e31dcf5d89e598b2ecd0dc025fn/aHeodo
2020-09-18doc-ESZ857.docdoc 5408fc0375d93c087881cc171b925203fc6ff99a1bc78716bb0f2cee15a69c3dn/aHeodo
2020-09-18rep_20200918_WS5134.docdoc b66215c81ae8df5da62c75848142dac423c6b48bb860d3117eb6cb9d65e8399an/aHeodo
2020-09-18DAT-48085.docdoc a5dcf96a690cc7c036613316d9003c9f6ee74e66dc2a8ac00502e63f8dfae85fVirustotal results 35.59%Heodo
2020-09-18list-4798404.docdoc c386868e3f526e0cd5d9093ae760761ebadb17cf74591886e56d8de0d3097f1cVirustotal results 37.50%Heodo
2020-09-18file-RMP8969.docdoc d43356345eda22fd3100b860df7cd151651be7931f0b01eeedf055aad895cbe6Virustotal results 35.59%Heodo
2020-09-18QU0011_20200918.docdoc 562c1a653b94bfc9219306d06089d0621f9f3fd9712476d1e543828e67d1eb83n/aHeodo
2020-09-18file JMA352141.docdoc 68a6ee3668a51859a1ccabe683a3d6148c90ec6cab3ed3e4cbf58e3dbfbb5ceen/aHeodo
2020-09-18rep.docdoc f9a9596b06fd6053fd9fe2f73a3cc010078c12423f3e963d553675df3a02b77bn/aHeodo
2020-09-17Rep_20200918_2889561.docdoc 0fe021634d1bf18c9da5198d5627924f63245cd526211ade2e1670ab78e9518bVirustotal results 34.48%Heodo
2020-09-17dat 2020_09_18 91388.docdoc c4c1c3441a6ee140589b9595e1da059946510638048a725450b3ac99c9dd95f6Virustotal results 33.90%Heodo
2020-09-17INF-2020_09_18-271.docdoc a799324029ea75b6b4a71f02bce59d976fd0926ce98d134c071d39e892f1da2fVirustotal results 33.90%Heodo
2020-09-17Mes_2020_09_18_RJM06355.docdoc 7f8b0c4424e7380c14127e52a14ff6e672914b9b042fd9e899702e09bef69484n/aHeodo
2020-09-17inf 20200918.docdoc b2333c8d2f6d1bddce72b7f65bb31a0ffc83dc7d933e262391377410c1655b7bVirustotal results 33.90%Heodo
2020-09-17REP_YK962819.docdoc 61d12a7df062c201b5bcd55a6a873064ab65df1eef00f4b71c5304ba86044673Virustotal results 33.90%Heodo
2020-09-17arc 20200918 NVC4399.docdoc dc33cb6f700e7453aa332b8ca55dfac6a7ad1473c496bc183ec73c84b8ea538dVirustotal results 32.76%Heodo
2020-09-173271 60371.docdoc d80641aed13ba5e1b8d4dfc10810d0a6533a51231342b46851f4357025945129Virustotal results 32.76%Heodo