URLhaus Database

You are currently viewing the URLhaus database entry for https://hy-api.cn/ceo-retirement/payment/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694426
URL: https://hy-api.cn/ceo-retirement/payment/
URL Status:Offline
Host: hy-api.cn
Date added:2020-10-14 21:14:07 UTC
Last online:2020-10-15 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 21:16:02 UTC to admin{at}zhuliuyun[dot]com)
Takedown time:9 hours, 55 minutes Good (down since 2020-10-15 07:11:29 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-158532243272023892.docdoc 1cc454d75dc586cd5025eab16ed2a8097e3d412f9efb96ddd568041631aa0ebcVirustotal results 45.00% Heodo
2020-10-1526738107239173.docdoc 3cbba280192a0fd99aa090f95cc1e2291a670a7cf53bca32811ff38da7289a95Virustotal results 36.07%Heodo
2020-10-15BAL_DQD_100120_GRO_101520.docdoc 48caa70a3b31ff976df78f2b4525b27307a53e88d1ce4f1846dd5801dd2c9b76n/aHeodo
2020-10-15REP_PO_10152020EX.docdoc b36b1ab739c6689f92c3da6e9a8c93a009756069b982b64e74e4075e98badc70n/aHeodo
2020-10-15K_5680593223050533159038495.docdoc 09b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbn/aHeodo
2020-10-15REP_WSV_100120_JLV_101520.docdoc d2d28ce9e628712a8478ea1439e111036497efe3d10a12bba622baf2952ded06Virustotal results 35.48%Heodo
2020-10-15REP_NPR2H1CIG2WC8.docdoc 7527e19a60407075d5ecb0a0f304aa0608f6deb102d4f9dbc42f65e03e985426Virustotal results 31.15%Heodo
2020-10-15REP_06480291.docdoc 41b09124fb322b43ded11ccfc493a3ce6885ba4d1b520fe896cabe2ffc3b2490Virustotal results 35.48%Heodo
2020-10-15INV_7PXTE9DY4X2N.docdoc 9c3dffbaa146c61c106f2b76127fe024ec9193641c046de19b1d144335206b7eVirustotal results 35.48%Heodo
2020-10-15J_65586025.docdoc bcd20ead58694ee7adb822b6a4c40c62433fc6ca968f2a728a7e10fd21d0d1b1Virustotal results 29.03%Heodo
2020-10-15VK_16260533.docdoc 0cf59450f4af8123dc62d34cb387c1f4bcc5a3c38cd4c966acbd7552574d9fc8Virustotal results 33.87%Heodo
2020-10-15FILE_4176635039201.docdoc a81218fa6f93ea8937a48dd0a2f9e44226d1cc1d0c14f973d4c4b2d8199aaa8dVirustotal results 31.15%Heodo
2020-10-15M_OT7579391937TF.docdoc 92a930cc35f0b758afa1eb48adbd009a241f19b3a1e5a10f2fda6b5495256eebVirustotal results 33.33%Heodo
2020-10-15JZZ_100120_ENE_101520.docdoc fd12780ca0e4c591da35bf3d215c22a47050b1a68e524ce4d0434ee2414cbf3aVirustotal results 31.15%Heodo
2020-10-15343727328.docdoc 1790c5fab1f40df300b33f400baa6f3981447142c4368a43e01a5b76b1beed3an/aHeodo
2020-10-15G_HL3002035550CW.docdoc 275d247b675319a0e083b29b0e1c88b3bae28687e80b83a5b6db109ae72d954dVirustotal results 31.15%Heodo
2020-10-15NUP_100120_XDI_101520.docdoc 1c801dab1da2fe35b4c87872baf097cb7b5500b886bc75cc29cd8aad2e83d2d4Virustotal results 29.03%Heodo
2020-10-15REP_IMN101180M.docdoc fc6514ef333a9a7df16243a938d3a6e2c9fcf1410d492381598062d92b267346Virustotal results 33.87%Heodo
2020-10-14FILE_RW8046636059MB.docdoc 3e222a87ae7cd1bbffb29335e25d2af2896c60be6575ff6070da3341b33b4c66n/aHeodo
2020-10-14REP_49031551.docdoc 9c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811Virustotal results 31.15%Heodo
2020-10-14REP_PO_10152020EX.docdoc 0d6731404ab523678e4e70272959a38c04c12861e5d94284b88316c3830f0b9bVirustotal results 30.65%Heodo
2020-10-14REP_QQA_100120_DNQ_101520.docdoc 9c6b0725805166528d2cbc739cc8157205fb247d5775c86058f8037522e235cfVirustotal results 30.65%Heodo
2020-10-144BZSVEH0IFU46OU.docdoc 61460977a0fa0d8f4341f551977b617fac983f78239dd6f5f4db96d36f513184Virustotal results 35.48%Heodo
2020-10-14990276454201454822763683.docdoc 57fc06d63e0e5452edcca6c9a6cf60b7176637ab252e8ae8675f080c0bed51c1Virustotal results 29.03%Heodo
2020-10-14ORW_35314557.docdoc eef9ce8af0cb687d9c2cba626d32c2c422cdf4af29344709135f8f5e79a75598Virustotal results 27.42%Heodo
2020-10-141215304244137798772679848.docdoc 521a53d518e84c5c1975c7019ce22c19f8a9e56401c060a2228768825a495411n/aHeodo
2020-10-14PO_10152020EX.docdoc 71fa0aaad2c5cd2e5e01af73667f97eb339a574575e69a2086b5f4c84ea05800Virustotal results 27.59%Heodo