URLhaus Database

You are currently viewing the URLhaus database entry for https://iwxdy.cn/wp-includes/Reporting/zzQsH4VfgLL2uc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:627229
URL: https://iwxdy.cn/wp-includes/Reporting/zzQsH4VfgLL2uc/
URL Status:Offline
Host: iwxdy.cn
Date added:2020-09-30 06:38:11 UTC
Last online:2020-10-07 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 06:40:15 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:7 days, 10 hours, 39 minutes Bad (down since 2020-10-07 17:19:53 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30rep_892607.docdoc 6d193f1c374677806c9b89aa300b0bfb12767e81211123827920b74837da36e0Virustotal results 22.95%Heodo
2020-09-30Attachments_20200930_RDR794.docdoc f5de87215c12489f4834be4a1b71fda51d010a845429e71980e6024e221b86ben/aHeodo
2020-09-305592-2020_09_30-YS9690.docdoc 913f98172cbe570c40c669297d3e0fd52e3109a2433467ddbca9e443d7ee438an/aHeodo
2020-09-30REP 2020_09_30 E050560.docdoc 0a72f410fe5254890d7fa49499a305fe366a747e010e5e84cbb1e6f60c425b20n/aHeodo
2020-09-30Arc-2020_09_30-JNS42954.docdoc d68f7a17ddc794e99447927fe7bfc0b7245f8fa2730d64c3f3996445853192a8n/aHeodo
2020-09-30Arc_2020_09_30_BOU52345.docdoc 540c085bf41d7ded925345f785582459e99ff1125a0400d9e6b151676fcc5f6dn/aHeodo
2020-09-30UNTITLED 2020_09_30 5835052.docdoc d2bb090ca35305b0fad24fda5d80294d4d4213ac4dd4c733e8df0f8550810b1bVirustotal results 22.58%Heodo
2020-09-30doc_2020_09_30.docdoc 0fb5239fe5bbf70f02bf41a8ce72d2048e609f230eb3adc8dd8a903c9fcc9d28n/aHeodo
2020-09-30rep_20200930.docdoc 85457cce94346f14602525c4c114a035aeff9de80b2d25f2cd7aee042c5477caVirustotal results 20.97%Heodo
2020-09-30Arc-20200930.docdoc ae08f6ca3d49c7a6f89007400a01827f8fa1e32ea4d88e4e38ff705f70c810ffVirustotal results 20.97%Heodo
2020-09-30mes 2020_09_30 8590.docdoc cd5afbedbf9512e5a427cd5b8d732a5fb2d8b3c6f410e688611bb21c76ac2aedVirustotal results 20.97%Heodo
2020-09-30Attachments-232527.docdoc c150b29360cf15b5be8f3cfba987464841892845367de5fc5985678600998bb3Virustotal results 21.31% Heodo
2020-09-30mes.docdoc 8ef1fe169003bb04c8f9c01d621a69d1ea9fa127df3d9c2baae8c97f6d955cfaVirustotal results 21.31%Heodo
2020-09-30Attachments 2020_09_30 R6802.docdoc a145c68d6733bdbef62c6d009986cf4ac6100b25b6e44571b92f9e5257fd3a2cVirustotal results 46.77%Heodo