URLhaus Database

You are currently viewing the URLhaus database entry for http://www.chias.tw/wp-includes/report/gcuifocmct/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698675
URL: http://www.chias.tw/wp-includes/report/gcuifocmct/
URL Status:Offline
Host: www.chias.tw
Date added:2020-10-15 22:06:06 UTC
Last online:2020-10-22 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 22:08:02 UTC to hostmaster{at}twnic[dot]net[dot]tw)
Takedown time:6 days, 10 hours, 52 minutes Bad (down since 2020-10-22 09:00:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17FILE_D6IH2R7TNQDJXH0.docdoc 8d13034de40b71141b07afd251984bb9b827f62b140815127683e779ebb9ab43Virustotal results 51.61%Heodo
2020-10-17DC_87567144134635.docdoc db234da6bba5f671c8a6fad07cfc6ad7ce1b078a32f920e2edb4b142167e18dcVirustotal results 51.61%Heodo
2020-10-17DOC_PO_10172020EX.docdoc fd0ec2733cb7fc4d8f934cf81b56a9a6fd2dd7290c257cdf4c2a1b3da2bcfc10n/aHeodo
2020-10-17DOC_PEQ_100120_NJT_101720.docdoc 4f6043ed53481592c3b9db4608a157df568b466062cba2018b8e5c59bfb40563Virustotal results 52.46%Heodo
2020-10-1743843356.docdoc 72bc6543f22de398e1374caed638e9a1d24ec0b37a5fa9b5ac10ade7559ab839Virustotal results 51.67%Heodo
2020-10-17QX4573472525WL.docdoc 71c1be4d00ef4ec74c73abf05187dacf0335a393a145eff2b2efd68cbaa91b67Virustotal results 54.10%Heodo
2020-10-16SSG_100120_VMR_101720.docdoc 3772d83153c2d54a8a3dd72055370d3db69948bf4eafeb69018ce518c7801d05Virustotal results 50.00%Heodo
2020-10-16W_04183703.docdoc 2d4a3ae690cd64017a114de08ffb095c8208ca65f5647809600f6caf8ff7cd97Virustotal results 50.00%Heodo
2020-10-16DOC_WI8563416682LZ.docdoc 6647111dcc98f3a01470eee7de5a3b93b579a08c585cd3553cbfbdf3d54db556Virustotal results 48.39%Heodo
2020-10-16H_C8HWI19XMHI.docdoc 1b2a426d5d7d5a0185640c82655ec40245f89ff62644ec1a04de9894a169114cVirustotal results 50.79%Heodo
2020-10-16FILE_09764443.docdoc 050d172a5e413b5f0a7a68bbbb0684b485f20b0b5f89bf3f9711b0c8e844b723Virustotal results 53.33%Heodo
2020-10-16BAL_SMD_100120_LHL_101720.docdoc dae05fe983f37d53c614de68c40f3da714bccb7dd377adecaf6a7592c31cdc4bVirustotal results 51.61%Heodo
2020-10-16LJ5347314182UV.docdoc 59330f6abd11ccf8373697955746b598be71ca8c69774640b41ebd9650abb398Virustotal results 45.61%Heodo
2020-10-16DOC_PO_10172020EX.docdoc 8e4239eda8a4993212d0de12a0e6fb748c995f1a89e8fab3417a0140b9f650d8Virustotal results 50.00%Heodo
2020-10-16DOC_FCA_100120_VXM_101720.docdoc 9c44a164c70d7fdbd796c9805e3ce506cf8fd1d8df4d84e27384d794e3c075b1n/aHeodo
2020-10-1699329525.docdoc 153c0d18a1b3639fe85f33bd426a65c66aa6af75ba5aa2ebfa89d6cdb7cc62aan/aHeodo
2020-10-1641794539.docdoc a556f655a5fe240f6e969c6e0c449f47d357b453c5940205ce2d867f7ca64e4eVirustotal results 50.00%Heodo
2020-10-16ECM_100120_FKJ_101620.docdoc 58d9abbb83b6f4df5a5dc7b782ecfc3a0a400197866d76f14500b97d206a7eabVirustotal results 50.00%Heodo
2020-10-16FILE_MJD_100120_MFI_101620.docdoc 27fdb3c973c1b3937b2df582f0fb1f1f6cd4d3139a75a8953a1da41a7815fb31Virustotal results 56.45%Heodo
2020-10-16INV_XXY_100120_EGW_101620.docdoc cbe66db13454415d1c87617d055c8ad6421a9bf6d53b6764c4af1f4d9bf2c9b6Virustotal results 32.79%Heodo
2020-10-16REP_OQ8295129815DS.docdoc b3900bcd297271f2e9a902ee2c398ddb51468949bd90a5cbfb6f0531360cc22cVirustotal results 32.79%Heodo
2020-10-16DOC_FI3211383593TM.docdoc 9e16a1c487318559bca602d0c341d760109650549d600ab32ea6c5b07b9c838dVirustotal results 33.33%Heodo
2020-10-16FILE_DX6250872666RA.docdoc c4e5490b2508ceaa3f196549d3c7d2865225ebbd56af97bc4a753542204c6641Virustotal results 32.26%Heodo
2020-10-16DOC_24490183.docdoc 3550b173f084aabdd854dc658b31eeac18f28c421c23052d45d5e8a92f8a3e93n/aHeodo
2020-10-16DOC_73042599.docdoc 2fc8f20d9cf100c7de1244d5ccb17f14230e534ff24921e0cb537ebce7668908Virustotal results 48.33%Heodo
2020-10-1640367254.docdoc f0abef25579afd4a06a70b4a55ce9b492df87c17b66b1949f541f679f6376b84Virustotal results 48.39%Heodo
2020-10-16BAL_KN3182764846ZS.docdoc 4175a2dd2295146108a2fb6d370f0d24239715d3709a82c0c6ec420a962efe90Virustotal results 48.39%Heodo
2020-10-15INV_8154198104194572490.docdoc a44bec73fa5d84c99c152a133907faff21cecbabd17faba199a628c8259be229Virustotal results 48.39%Heodo
2020-10-15ZOB_100120_EFL_101620.docdoc 3a655449935db1d07871d79739c4fe01d8792844b72e4bc0c3f2c936b6d5ee1fVirustotal results 51.67%Heodo
2020-10-1504142893.docdoc 5781607bc4d3aa2d65dc523aab5dfea022ffae444327c4463969d7e461822367Virustotal results 50.00%Heodo
2020-10-15PO_10162020EX.docdoc 0ab272f979fa9aed2035beb2f578c7dd1b689f64452457def9e7aca2d1c91a3aVirustotal results 48.39%Heodo
2020-10-15REP_28693553.docdoc 6bd70c37738737b137dddf5e137cff39eb5baeca80217787c95d5ce885c5854an/aHeodo