URLhaus Database

You are currently viewing the URLhaus database entry for http://yzlangfeng.com/wp-includes/2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:610210
URL: http://yzlangfeng.com/wp-includes/2/
URL Status:Offline
Host: yzlangfeng.com
Date added:2020-09-24 15:14:06 UTC
Last online:2020-09-25 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 15:16:02 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:11 hours, 58 minutes Good (down since 2020-09-25 03:14:29 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-25gHSmz7ev.exeexe eaab6e104bccdface6b6fad1552ec7cc30b3fb0a21fa0884aa602173e8374b49n/a Heodo
2020-09-25lqLFl69UYIFaOpk0.exeexe a72f520508ac46a99870391e5a0629334a6192b87e399aec19a802b3fe8a8cb4n/a Heodo
2020-09-25DnNijTjrdR.exeexe 9219beaa1080e298e69f3efdc237daa0b82d214c6d2f11b94dd8046bbc64fd91Virustotal results 21.13% Heodo
2020-09-25RIiiRMMN41XYt2c.exeexe 83866ee352a9b6ab198083638ddcd08904a95d624a4bf9504765fa119114c9f6n/a Heodo
2020-09-25k134cPT.exeexe b67d6ab319624b8f70a365f34fe4737e686e8db5a3408719b4db97a3acca5a34n/a Heodo
2020-09-253UaUDbLX.exeexe 5c19205adab4938a020d5799604a533a4f31af3a5244da44af53833a66f98a1cVirustotal results 19.72% Heodo
2020-09-25YoApxqXK9t.exeexe fbc8a876742abf3995d670e4d7311f56ce3c2f10ed1b83be5181101130a20960n/a Heodo
2020-09-25tzPyH2s1pXk6PUp3DaJ4.exeexe 451e32349ec669e502c9c3dc6f6aa850e797a3b92ce12d9a0382f223f3cb114eVirustotal results 21.13% Heodo
2020-09-25DagKvapP1GQ4q.exeexe d5b0ea504bee142ba4c6c932383cccb056bfde40255945c934bfba7b9bfc442dVirustotal results 21.13% Heodo
2020-09-25ylnX5BV4w.exeexe b36e3635a3678d517488baf66feeb2dd4e67e880b61655f798fe3d9d82a52d4an/a Heodo
2020-09-24MWQJ766Klx53LmJ.exeexe ccb5262c0fd15e05eebe99790bddd1b4f1ccd1e1bea9231414d0a3e984d8d7a8n/a Heodo
2020-09-24Okdug20X3Rug9U.exeexe c0ee28d14e9c01a11a8ff415f1c822aac03f28c347be9a76fa96e90bbcc8a833n/a Heodo
2020-09-24YkUZD7Gl2ZYF.exeexe b67deab63acaf2e4dd236813aac905174af6d3b1d53da3f0d7901602b157ca64Virustotal results 19.72% Heodo
2020-09-24aBwp.exeexe ca909cb86795ae01d12b2e60c86fd873753cfb7dedbf0b20a7a78d0d9d919702n/a Heodo
2020-09-24vxFXXWx.exeexe 4539cbc3fc6a97d1d3dc01648eb28e9e135b1a6751cd0ff8212eeac0ef4b267fn/a Heodo
2020-09-24snlCoFOwCN1TGuhCT.exeexe 1e1a61a29a4ae91ff8fc7cb6f86c60ede149b551f0fca45561ba66ff23801df7n/a Heodo
2020-09-24GPVdf7a0RBCqeuStD.exeexe 2992480985886785a42d3c57d25dac8ce544a1efb97a1860b2a10f261f3114dcn/a Heodo
2020-09-240N3se7Ur.exeexe 04db6b3aa905c7f6ff347aebfb44aa801fecb479086f863f6d9b6f0e15f3521fn/a Heodo
2020-09-24kMb31bQvrlYaSLJcAid.exeexe 360d3d447e46167c3bde05b3f7406e89864bfbaa89e8c39c9832d2a3e96623c8Virustotal results 19.72% Heodo
2020-09-24RDUrarkK0.exeexe 996640c9015ca510082aa3aecf33be0227d65fcd3138c3c913ca567f183e638an/a Heodo
2020-09-240vizQ8sVZPoMSPiKWzUx.exeexe 59a6dfd3431cbc6cfc756c210a9370ad77791206006859faf0fc5cb4aa162839n/a Heodo
2020-09-242TeHKjR8HDBD.exeexe 5a7f2b9da5d732824f71374ca29b400fdebab7800797357f167edfd1a56f76e7n/a Heodo
2020-09-24GiQn1XJjo.exeexe 53a592db5d85dd5769332c34b85b38b1a4436e421e0e204d832fbdffd795edf2n/a Heodo
2020-09-24jbXSXuYfmJ.exeexe ee582da13038e190e419783f6c07f2aa4ca4e0217ee189da1446f201af27eb61Virustotal results 23.94% Heodo
2020-09-24ZOfHW7.exeexe 584bbb2d7f24c95cfee5040afc1ba66a65426153351850f2c8a4522c6a95ccf8n/a Heodo
2020-09-24ZMFjArvTz1pkCKz.exeexe bb7e95d23f7b33623a937b0069aa1e521b1ca77f378b9833d266f825e24c2c53n/a Heodo
2020-09-24RDg1oX.exeexe 8e7851ef61a846a21cf13ba7aae9d9ec2c5ecdeac389b2c18117e6bcba2fe0dbn/a Heodo
2020-09-24g8qWn.exeexe 49a4d48831ffcd434ae73c015d33cb0a8e0828a449a366c5934d861da43339edn/a Heodo
2020-09-24mrnn86oTFNBc3.exeexe 182515dede44b5b12f48243aec2205f975a3a931c05e104e9fb4998a8f08f943n/a Heodo
2020-09-24JKORxVld9Uh9JU8DY.exeexe 057a55718077bd8dd2c64f275014eb31fab5a68b7cdeb01b484a678324fedc42n/a Heodo
2020-09-24A8cpTx.exeexe 820d025a189fbb367f3b4c12f5b57458ab556f892dc9fe2ffee2c7de786dbc2en/a Heodo
2020-09-24dw35.exeexe 1a17bb46b115075ce96a5484b621ec170418ddda6ed335402bf0bcfc5e3b10e0n/a Heodo
2020-09-24jZi1JGYyY5McIFl.exeexe a0e9cc558e69f80b19879d71abb377ca9b95a6b1aea714f4ab721fab2cc4692eVirustotal results 19.72% Heodo
2020-09-24N61vGm.exeexe aa0eb9c8d811af0b08b5776b165a65045cb380579ba44253a42f2657ea479c27n/a Heodo
2020-09-24F7m.exeexe 883ed0446e3e306ed04e73de50fe229bc9076bfc022d523df11e36f880fe83bdn/a Heodo
2020-09-24coJrAjqF.exeexe 0bd71bb6096fd22ed6fe9e931c4978839f6bb1de9cf1db39e91a5532d8a177ddVirustotal results 19.72% Heodo
2020-09-24SsJRAb4L7.exeexe 565bcc84564266c96bb24aa2155d9aa4245889748e07f2177eead270c9ecfb4en/a Heodo