URLhaus Database

You are currently viewing the URLhaus database entry for https://www.hehouzhu.cn/wp-includes/public/91999w/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:587634
URL: https://www.hehouzhu.cn/wp-includes/public/91999w/
URL Status:Offline
Host: www.hehouzhu.cn
Date added:2020-09-21 16:38:07 UTC
Last online:2020-09-21 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 16:40:06 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 37 minutes Good (down since 2020-09-21 19:17:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-21BAL_14329203.docdoc f87c10d05f454254da53ad0717ce0f42871dd7293e1b24157355fc0544ac8926Virustotal results 24.56%Heodo
2020-09-21REP_LC6906721247XH.docdoc 23d5d8e9c92d53d3ee2027f177ca8a6a51be1fd82c937219ed25eb2c0720a377Virustotal results 27.12%Heodo
2020-09-21152370738213041813.docdoc b446e1f7810a4bbd7e7b28125c2226d9998a12086945c37647e3a43db0a5ca65n/a Heodo
2020-09-21XAN_55174484.docdoc 9f20d4c02cc0a17cab07b9dd439952f5b036ebe4e1b1adf6bfd639386ce05eaen/aHeodo
2020-09-21FILE_TNY_090120_TQX_092120.docdoc f004c200aee13a599b9132f323cf3c1752babe33e106d55ef045391c394211a8Virustotal results 25.86%Heodo
2020-09-21FILE_1833993907124977806766.docdoc 4a302af09a3467c26893b329b0646fc758032a20e47f1c6a9209d0fdc55d05edVirustotal results 28.81%Heodo