URLhaus Database

You are currently viewing the URLhaus database entry for http://dh.1314.ren/xhck/Reporting/ogajb5ecxj0o/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:562351
URL: http://dh.1314.ren/xhck/Reporting/ogajb5ecxj0o/
URL Status:Offline
Host: dh.1314.ren
Date added:2020-09-19 01:33:07 UTC
Last online:2020-09-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-19 01:34:27 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:10 days, 6 hours, 26 minutes Bad (down since 2020-09-29 08:01:02 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-19TU_ROF7GEC42.docdoc e9325a711e0f6f605b85898c5b507d4320e1f1dc672c68172b06cda359b5107eVirustotal results 34.48%Heodo
2020-09-19QTGU6KRNXZR2.docdoc 7f3de15e944bb1542274b9fcba2c85be0c2c2f82e6745e114a5f791451264a40Virustotal results 40.68%Heodo
2020-09-19J_W730GQHTQY.docdoc e94370a66b084c6e99c0a16d5b777ba5d77c0e9a63ff4c237635ea1b37281072n/aHeodo
2020-09-19DOC_ITK_090120_SIM_091920.docdoc e1e9afb5bbc575dbf36a065e3f986bdd46ddb7a3282b2d41a5fd8259520c1cfen/aHeodo
2020-09-1987786519.docdoc 3304ef9cd1d55e1d892f5a18644273b8e62254f587e24e42428a460305129396Virustotal results 54.39%Heodo
2020-09-19HD_28651319.docdoc 20afdfa7a7c7a299565cdd046c41bcbea4b1cbdc4041edc9f0e51d52dac04a0cn/aHeodo
2020-09-19K0GU811BG.docdoc c8fc2ffef7922459d1144fe2ea5973e62255d0256394126a4cb635bcaa107fben/aHeodo
2020-09-19VJI_090120_BOZ_091920.docdoc 5e26ff2da8ec2dc57e3ee7a4a6aec18f5d6c6102fd03e5e1ad8caeaa1c2943efn/aHeodo
2020-09-19990151515789947443250.docdoc e5d9bb556a385de29f04eccbf388a0e8f73f556394bfcaff0a6c7ffb15e85a48n/aHeodo
2020-09-19BAL_PO_09192020EX.docdoc 6da6b99d1e7334c2df666c15e596c4fb9cca58c3f3891e9cc6676580e5b1dcbfVirustotal results 35.09%Heodo
2020-09-19INV_HJ6963633974ZD.docdoc 161a56d18d19f07897fe02a41e186be65f9bb1d33230e6bc26787c0d5a20231en/aHeodo
2020-09-19BAL_PO_09192020EX.docdoc fffbe59f1dc6c2deda79ca2307558610f2c5abb3e030a07d7e0be1969e2fd45cVirustotal results 31.58%Heodo
2020-09-19X_437478299568162426.docdoc 15533d02d9310a6707f2092410bb3deff89174f7bc64f893a98e946f2ae3ba3fn/aHeodo
2020-09-19GT4526306828UY.docdoc 7c391c5dde83d6bcb96a44a794bdced0a65235c65e6ee19d33bd602b09df433fn/aHeodo
2020-09-19BAL_07309844.docdoc 23e85a68c4a3b9d299d2ed531ada64c13d44ea288cad289752aa9dd3d3e08884n/aHeodo
2020-09-19BAL_NPF_090120_XPG_091920.docdoc 64e48a3ff70c94d505c873e8a67d31e9e482b8abca66fdae7b73d4f89b69c7c3n/aHeodo
2020-09-19W_5970074127381.docdoc 918a64048af4a066fdd935050729fcc70f074457f2943f59469ee5f3bdb0a70dVirustotal results 35.59%Heodo
2020-09-19REP_17T0QVNRDOIJBWX.docdoc b14f0e1f1d44b106d892cd44c08878b06eecb430fe4244185d68a5faa1cab7aaVirustotal results 41.38%Heodo
2020-09-19JD5845944324LK.docdoc d0916058bac3e5720c7979d05019d5fbffb9f64eb341116f0d3febff67abea01Virustotal results 35.59%Heodo
2020-09-19FILE_6RX719CWL8OKWIZN.docdoc a0427b223aa7c526dd3cebfcc4d97cc8a6e9d272e790a314a0ebeda94ad3f183Virustotal results 41.38%Heodo
2020-09-19FILE_WD4912304089WR.docdoc 7991a69a5cbfa005b7685a29ded3f4f849b24fed6a340cbba97dc86d6db9b0a6n/aHeodo
2020-09-19INV_71374927.docdoc aae82415f0c1d33438261bb6ea1039cdff8bccc786541f5177e6938497f5b2d1Virustotal results 40.68%Heodo
2020-09-19REP_722878337868834024.docdoc 44e47d913c76d153f7ec6638faed21e1a728e49130ad53d30ca01416220f217dVirustotal results 30.51%Heodo
2020-09-19E_31926722.docdoc 32fb5e68e6524e8f2ea13cdf8686e2f0a5fd28042071482fde48d4110a714158Virustotal results 35.59%Heodo
2020-09-19OT0409499179QW.docdoc ca453113011d23c6e8b95d9ca6c1b36fe27cec37139b376a7f9fd7f2a665d42fVirustotal results 49.15%Heodo
2020-09-19REP_PO_09192020EX.docdoc 3d64095f4564ebc30eadbe6a61d8dd290bf34c82c7c49a9accc8179312fc53edVirustotal results 27.59%Heodo
2020-09-19INV_G9IIL23DP5HE.docdoc f29d80209cde1118a9399b3937016f28ff68863180d6f36ef6d55fd099de06c1Virustotal results 35.59%Heodo
2020-09-19U_A4RXPBC5JE3FYG.docdoc f45366fd48bfadbe704572fe3f559494d82fc82a99673cf792e760777f56ece1n/aHeodo
2020-09-19INV_BS9YEGQ4JGCQ83.docdoc 4198131e8d2f03d52598f0c99b1f8765ed8d7380b175ec0ee5e9ef4e845f90feVirustotal results 40.00%Heodo
2020-09-19DOC_PO_09192020EX.docdoc ebb66d12381191a931ebf207ea13eebdca01c5860177d35a6a5967bf1dd00586n/aHeodo
2020-09-19REP_RBY_090120_GNR_091920.docdoc 8edaaf5279e9bbfba0c2952d8545563f327f0648035e56774baef612d4777aafn/aHeodo
2020-09-19INV_36548523.docdoc 8de8ea6861abc663aa24c26703bde4b83981117f06c438a6d82c295d178ce970Virustotal results 25.42%Heodo
2020-09-19XRVR_UNLBVQ5CR61Z0.docdoc ee2bfb3bfc62ad36246c4533bb4bb8c41aa21ffeb8bd74b216d3c6088cbc7b62Virustotal results 37.29%Heodo
2020-09-1949337673.docdoc 56813b1ff2c178be52fb844d4656d77d7d061aeeb71e90418d1665f9aac64978Virustotal results 26.32%Heodo
2020-09-19PYK_090120_XGO_091920.docdoc b837078057329148a35e96ef42c7c83e16fd7f203fa7f1f225fc1a42246349c2Virustotal results 36.21%Heodo