URLhaus Database

You are currently viewing the URLhaus database entry for http://caipa.net.cn/docs/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694823
URL: http://caipa.net.cn/docs/
URL Status:Offline
Host: caipa.net.cn
Date added:2020-10-14 23:06:12 UTC
Last online:2020-10-15 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 23:08:10 UTC to ipas{at}cnnic[dot]cn)
Takedown time:9 hours, 13 minutes Good (down since 2020-10-15 08:21:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15DOC_17606224.docdoc 74162fa1b634bfdde5cbbc8882362c3d5083368cbea1e88ab8c413863cab2ac3Virustotal results 32.26%Heodo
2020-10-15REP_ZM7TRKS8IZH1.docdoc 760ea4f40eb97c7d6210b13d52fd6d6159b4ebfc38bec62527ab2931b526cf02Virustotal results 32.26%Heodo
2020-10-15FILE_PO_10152020EX.docdoc da773aecb5b38de74a2aa07b5e5f4c66165271f9bbe3fa5a5a4f06bed264adf3n/aHeodo
2020-10-15FILE_PO_10152020EX.docdoc 2a3d73d8e391636548a28421a0cceeaa7fab08cb60380bf090a57a1af35b96fbVirustotal results 37.70%Heodo
2020-10-15BAL_ZF2115861784WO.docdoc 8877bd46df4f972056ba63398a055c5fe92b53cf944fec3f5b7f58904c39ceffVirustotal results 30.65%Heodo
2020-10-15BAL_41684538.docdoc 48caa70a3b31ff976df78f2b4525b27307a53e88d1ce4f1846dd5801dd2c9b76n/aHeodo
2020-10-15DOC_44116526.docdoc b36b1ab739c6689f92c3da6e9a8c93a009756069b982b64e74e4075e98badc70n/aHeodo
2020-10-15H_IW3ELJUQ.docdoc 09b2a0a619eef827aca5df812a125f278c915c56afa75e6bcbd55e47265034bbn/aHeodo
2020-10-15576315813.docdoc 0bba700eccd740560f4344921b97e592f9fc4e31fea87d50bd0dadcaf73ddf75Virustotal results 35.48%Heodo
2020-10-15H_PO_10152020EX.docdoc 5fefd7066e7cb6344aa6f4ceb150de371e98cc1de2af7bfa2fa46cb4949ff0aeVirustotal results 32.26%Heodo
2020-10-15BAL_98732648.docdoc b716ead26e4edc1ca7925f26ba16cdbe932e9cff3fbb636630f3d7bad4ad487dVirustotal results 32.26%Heodo
2020-10-15M_08849932.docdoc 2cac6b6f1ed831e31b804e46839fb6e8e196a14ba3d75ba6c945d4b87dd18f04Virustotal results 30.65%Heodo
2020-10-15PO_10152020EX.docdoc 0acbd96443e33ed3c7bb5928e381f4440eb99308be50ab1a869a7bc118e57076Virustotal results 32.79%Heodo
2020-10-15IWQ_HF6B1LZ01NKLO.docdoc 25aa35b354712a75a1fa86936a9f4195ea8e3c08a6e6f2c3b9820cb4dd28209dVirustotal results 37.10%Heodo
2020-10-15D_AOX_100120_LEB_101520.docdoc 100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533n/aHeodo
2020-10-15DOC_PO_10152020EX.docdoc 92a930cc35f0b758afa1eb48adbd009a241f19b3a1e5a10f2fda6b5495256eebn/aHeodo
2020-10-15432476479.docdoc a9e9fd09c8758fd9bc32c4f3cdc9b19afafdeb894a288778c2a4df42944be7c0Virustotal results 35.48%Heodo
2020-10-15DOC_NHH570Y.docdoc 14cc0eaf88072cd7dc29c10554024abceb5d548710ad957dcece3133a3a37dc7Virustotal results 33.87%Heodo
2020-10-15BAL_28406355.docdoc 0ce691ae2caab090785a0378e42e72fb8c1b6e129c8b3f50e32462295cf128e3Virustotal results 32.26%Heodo
2020-10-15ADNL0NBMTF3L17C.docdoc 1c801dab1da2fe35b4c87872baf097cb7b5500b886bc75cc29cd8aad2e83d2d4Virustotal results 35.48%Heodo
2020-10-1595716091717738487795.docdoc 5b4c47d73226347391f06e552ff9caa035e74cdcd652ac424c4364ab6fcca280Virustotal results 35.48%Heodo
2020-10-14KJ_5IIA42ZSITP9.docdoc b1380f1fdf3f7636d79043feef8f62d1f57ec8694f3abddce522899895cf4dddVirustotal results 29.03%Heodo
2020-10-14EA_X0M8DKO.docdoc 9c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811Virustotal results 31.15%Heodo
2020-10-14ZUB_100120_OTM_101520.docdoc 766cbde7ddad3ff7d55d13146e76bdfdd1699d56ad5886d619dc2e74f2889d1dVirustotal results 29.03%Heodo