URLhaus Database

You are currently viewing the URLhaus database entry for https://fzweiming.com/wp-content/public/uExlIqZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:717125
URL: https://fzweiming.com/wp-content/public/uExlIqZ/
URL Status:Offline
Host: fzweiming.com
Date added:2020-10-19 10:30:08 UTC
Last online:2020-11-02 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 10:32:07 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:13 days, 21 hours, 21 minutes Bad (down since 2020-11-02 07:53:37 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21Form.docdoc 948bb869d6a5a753b67269eb5283d5b20cedb51f1759f031d75565c662f210d4Virustotal results 32.08% Heodo
2020-10-211381046643JK.docdoc 326dc3efbb3c157a00369c8ec16b1c404b95a85458b0417cccc92282178a4496Virustotal results 29.79%Heodo
2020-10-217806343115KQ.docdoc 335231c83fd73bed46bea76a81706d2348880433f130fd464e81381a81e8f301Virustotal results 29.09% Heodo
2020-10-21JU52 invoicing.docdoc 136727da9e9bf447ed1e4d28162afc8ff4af1819c1ced08571ee835190d56704Virustotal results 26.23% Heodo
2020-10-21Form - Oct 21, 2020.docdoc 8ec66231199f5f5fe7ec4b7165225152d2a2eaad0d4c868f01121d0398db1c27Virustotal results 30.19%Heodo
2020-10-21October Invoice.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21INV_3651.docdoc b7b2d0ef7df5007d18a8a857ab7b35956aa9060aa4edfb1bd80e17299d53d9a7Virustotal results 50.00%Heodo
2020-10-21Payment.docdoc a190cc4bd4d39b253f7e560cdf793dd829f74b0f816bbddc666525007a02412fVirustotal results 47.54%Heodo
2020-10-21Copy invoice #50089.docdoc 10a79d7cf0b1366e69b0473e9164dcdf109149a6551b18a6c277a242261f5dd3Virustotal results 45.16%Heodo
2020-10-21invoice.docdoc e321ead5188a4d2e7abd2c7f2ca1bc74c905e875d34703bea49fa84c50cf4ed0Virustotal results 45.00%Heodo
2020-10-21Invoice #67228173.docdoc cbc98038cc0dab8d10dbfa4950f8228777c05eee346ce80ab1f2002c51939ac1Virustotal results 46.15%Heodo
2020-10-21invoice #689125.docdoc 5ab195348086d508a9be2e1c480fa60e9de009a7f057dbaf696f8468ec4fe0f5Virustotal results 45.28%Heodo
2020-10-21invoice.docdoc a3bd9261b5a8844a6a6a77e06f0eabf6a21d998001e99718a42f8bfc8147762dVirustotal results 45.00%Heodo
2020-10-21Invoice #8262754.docdoc f230273ae9e5eb57e36f98c374578e1a9856504dfbfbdcc7f815d20ba5974f2dVirustotal results 41.94%Heodo
2020-10-21JMH-100120 XDKJ-102120.docdoc a4b9c8bd73e09cac4fa51d9601686766c566cc1afcba7986eb46da97f56449d5Virustotal results 40.00%Heodo
2020-10-21Inv_5842.docdoc 20c81e0a8e1547a4fe23a6d435e61f31253f5036e68c7564ad0c5d1fbb79120aVirustotal results 41.51%Heodo
2020-10-215383634554SK.docdoc d590ed65aef80ecdc7f0a44755ee436937f30c0b05287ce6d177b654512940e8Virustotal results 40.98%Heodo
2020-10-20Inv. 015948.docdoc 79083e8a8ffe07dce171b5e20d5665e9317f618845036d5d3be76d6c8149a0e7Virustotal results 40.98%Heodo
2020-10-20Form.docdoc 368608fc48be7d6239425f9a9e23b2aa19d22aaa001796c8c0e391858bd2932eVirustotal results 39.62%Heodo
2020-10-20Payment status.docdoc bc671ede4242e59e050fff534673dd447ebcdb084f7e7504d004ca446707d409Virustotal results 38.98%Heodo
2020-10-20Payment status.docdoc 0fd8d47fc4990dfad6cb0567737449722837d2aa312d68143295e1a2846ed1ecVirustotal results 40.32%Heodo
2020-10-20Invoice 53344.docdoc a8e92bb15ad9bcd8e93e71644a570c2aeb6d030e2b496412500deb4ee2a23889Virustotal results 37.10%Heodo
2020-10-20DMG-100120 VTPP-102120.docdoc 513b71ba83e2dc965d906445134bc392882b7628f49e973b9d6021139f0ac8ccVirustotal results 33.87%Heodo
2020-10-200069459185.docdoc c1a2f053ac0b9cafe6d08072e6971d0dfad8f938cc167753df413b1a5ee4065bVirustotal results 32.79%Heodo
2020-10-20form.docdoc 36bf9ecc1a8a1ba3e8b3adf9e916e0f5d5e7f0247f6c4efc53dcdc496443de74Virustotal results 34.62%Heodo
2020-10-200025436338.docdoc 1949d127f8cad19649adb5f4534e1b6eff752a31d5ea73e427d0ef8c90511ceeVirustotal results 32.26%Heodo
2020-10-20PO# 10202020.docdoc c9804b898a9d2326b05f4037b2eace298777d1a387273033692c9f6deede6cabVirustotal results 34.62%Heodo
2020-10-20INV #0638252 FOR PO #0086132403588.docdoc 943cf94b0b03d8b04c8a0e977e955ae48b3713bfddd6a3f00f37618bb410f201Virustotal results 34.00% Heodo
2020-10-20October Invoice.docdoc d71d5d04020304ab739545240d25684b106882802e265a64cba2af565ca6c8efVirustotal results 32.26% Heodo
2020-10-20Invoice #4452668.docdoc 5de10aad274888c1ae2d0b13f1cc5199b0fbf596200f2f0d567aa2e2df2e2e22Virustotal results 32.20% Heodo
2020-10-20Payment.docdoc 98bb25e6f42b7ed9cbaff96437ada2d6b17e0a4bb5a6d1d2e2a8636233ade5a5Virustotal results 32.26% Heodo
2020-10-20Invoice #0500229.docdoc 61835e08172767d73a9e6c5dfb1fcc8b904d60c3b9cd7b382bcfe43aeab5c2c0Virustotal results 30.00% Heodo
2020-10-20P1549012796PI.docdoc 18286f51c980997e07241a170822a950f101cfa264c232edbfcb4d67694d5b45Virustotal results 31.15% Heodo
2020-10-20invoices 63194 & 68480.docdoc e59ffb1d8684c5f593de0d953edca68b56546935b4c9eb2bfc7b55958865826fVirustotal results 31.03% Heodo
2020-10-20VGU-100120 ZTTG-102020.docdoc 589c7b11cb037b2183fcee493e98930358a15693532b1340c7f4cf1d2f50c636Virustotal results 32.20% Heodo
2020-10-2014158.docdoc f86eebc5209b2e92bd174a3c00c80a3b021c7ab0ba5c60b46e91b9d92d8f23d6Virustotal results 30.51% Heodo
2020-10-20Form - Oct 20, 2020.docdoc 47914da6e4ee4b6892b42cdb0076cc23a9887a862a7b366434d7c77c0a21123dVirustotal results 32.26% Heodo
2020-10-20INV_406493.docdoc 6e81190ea76657504baff9bef3ee1e2b652f05d439d5d47cd39fe510ac240b26Virustotal results 50.00% Heodo
2020-10-20Payment.docdoc f2b4ccaa7caba74f3265769fd42bcf4d97cbcd5dcac848aceb801bc8cfc227e4Virustotal results 56.45% Heodo
2020-10-20Invoice 0056325.docdoc d3c44070ddcd9f8da355febd4a42d13f43e04b5a63830770aaae535e44fb4549Virustotal results 48.33% Heodo
2020-10-20PO# 10202020.docdoc 00fddc023c2f5c9f500b8592592b4399de427ab2e657776af747214d6e85f282Virustotal results 50.94% Heodo
2020-10-20Form.docdoc 79fe11a895e4e6d9945022d70da2ea0c06927b3b91d7947564e610377117ee72Virustotal results 48.33% Heodo
2020-10-20Electronic form.docdoc 03ed194d560f6e7b976f45dd5678707c7132079b5d6d1bf0366c7163e939cb1bVirustotal results 49.06% Heodo
2020-10-20Invoice.docdoc d410b71a4badf540641e5b102f7296d63455fb941f370f9c8248d0fa8176896eVirustotal results 50.00% Heodo
2020-10-20invoices 9276 & 84667.docdoc aea562896196459f11e274751fcc92aad6234db3e78088c86bda7f2b31be9b4aVirustotal results 53.33% Heodo
2020-10-20Form - Oct 20, 2020.docdoc f5996a9cae20e6d4cc8ef73a116b7b97723ef49093a4d518c6c85d757126cdb1Virustotal results 50.00% Heodo
2020-10-2000494282.docdoc 9274f1cccd6ac0af51801682a093404e9f2f3453120e01d07f4e2086d73606eeVirustotal results 50.00% Heodo
2020-10-20October Invoice.docdoc 1d6ddacfa157c7a54a7f33fc1f1941a643a4a4f799268d4f2fdb333e4d6d49a4Virustotal results 49.18% Heodo
2020-10-20October invoice.docdoc 73f22ba33ef477380a8177c19532c0e6a7c993ac47333c22b3ad4b53544bade1Virustotal results 49.06% Heodo
2020-10-20FU-100120 MBRY-102020.docdoc 45327af6d3d75a274f4c5d122adc41d42ddff44e520c7c02efb3df87adc64be0Virustotal results 50.82% Heodo
2020-10-20Form.docdoc 2e687ca36b3132b0704c1da58bfd462aa6bf5272d6ecbc84616059abc2fab4f2Virustotal results 49.06% Heodo
2020-10-20Form - Oct 20, 2020.docdoc 925df0de20c1970feff21e7c085d0c4ba2f3f2feedec51001b1f2410c2c31846Virustotal results 50.00% Heodo
2020-10-20QS16 invoicing.docdoc a6ce54965c51dcd7657b5f704c2564e330d3172da005cc06b8fec033582bc50aVirustotal results 48.98% Heodo
2020-10-20Copy invoice #7967.docdoc 0fc8e8b6e2bd46027ae6472ec944995b2976399582013b8a7ede625f362572f7Virustotal results 52.00% Heodo
2020-10-20M-100120 YMYW-102020.docdoc 477afd6f4a7fed4b0886e1d509e130c736c6f2203be85ed8c18d40bc6db385f0Virustotal results 51.61% Heodo
2020-10-20Copy invoice #7574.docdoc abb1fa28c17964d8d4366e43c3fa606bb40eb59a69d128368a37c9ae5ba84544Virustotal results 50.00% Heodo
2020-10-19Invoice.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 40.98%Heodo
2020-10-19Invoice 0484416.docdoc c22cff8c43e59c186145e91cc19bf98b0aa99956c6b462715d0b72959c3b71f8Virustotal results 41.94% Heodo
2020-10-19Invoice #89514.docdoc bf531b0222093b2361b9fefa68e81086ee5546a96f3d61a889199094a5a98a5fVirustotal results 37.29% Heodo
2020-10-19PO# 10202020.docdoc 88dd95edc7f24c985b398873d6279279760db09de42abf2d8a2e5b24197fb41aVirustotal results 37.10% Heodo
2020-10-19Invoice #8190.docdoc 65d548a2c80c974c878eff21c34e9d94965ab43d7da72c2557d3e47f61484738Virustotal results 40.32% Heodo
2020-10-19INV_01917.docdoc 8e4896d7b05dfde0b51d0d29dfaa4f133ef855cd8755e446a2450656def56bc1Virustotal results 37.10% Heodo
2020-10-19Payment status.docdoc 32287e572df07a7450ca513789cb55b10900c74a408d0c698bdbbaa7d8013660Virustotal results 37.10% Heodo
2020-10-19INV_697285.docdoc 96d88d8f9d91defeac3ba252e0b4fd5d37a9d58d3eb583ab00c38e7d3900edd5Virustotal results 37.10% Heodo
2020-10-19Invoice 00596834.docdoc 2534bd1e3dd2ba890e903ecabb7906799e2111c09dabd87103d76820125fa324Virustotal results 37.10% Heodo
2020-10-19invoice #07994.docdoc dda605b9508755b7ef1e6b208c85c2f57e819a3603bd12008d45ed25e19de07aVirustotal results 37.10% Heodo
2020-10-19Copy invoice #703220.docdoc 2ebfd934653d819ff21fc97193d31245e1af1a7ff512c0cc9932a49328702446Virustotal results 37.10% Heodo
2020-10-19form.docdoc 2725334fb5f7d2ded56c9fd29eb4f35bed2440f9605815628c005bdb7f344296Virustotal results 38.71% Heodo
2020-10-19INV #00062774 FOR PO #00739300359.docdoc 6fdb21e6d0b448b9f4066af8ed1556b9e9706d0da50efbab8b9d91e961bee682Virustotal results 33.87% Heodo
2020-10-19Copy invoice #4600.docdoc 4aa74b49409e94ab976c378a624a8433b8b366a4ae90469b3b21d5f79c4accbcVirustotal results 29.03% Heodo
2020-10-19PO# 10192020.docdoc f048adfc0ddc30161753c936fc8bdf8ebfe7ef196b91b6dc9d18512263d6647bVirustotal results 37.50%Heodo
2020-10-19invoices 3828 & 62797.docdoc 1146ef7f2b51b0c7dd97c68f1c2e19e7dd2c4b16b32e3b4eae61feb4c0b85ce4Virustotal results 36.07% Heodo
2020-10-19Inv. 094518.docdoc a5e0b39bfb2940276129d16f3fc3ff000386b32d37f86e87c7851d8f5b9047dfVirustotal results 32.26% Heodo
2020-10-19CP-100120 WPMG-101920.docdoc 9cf56ebc5e58b34ab1632a4c30a334d9832c086258739c067ed83a334510992fVirustotal results 29.03% Heodo
2020-10-19Invoice #664430.docdoc 8576aba5a23c73da3e3356ff4d55dc8a20ce03cc0969d700e027cfdf9418d69fVirustotal results 29.03% Heodo
2020-10-19Form - Oct 19, 2020.docdoc 087fd4cd1a8f90ea9b00236885e326c54f3478939949bccea90115fa52ac4dfbVirustotal results 30.65% Heodo
2020-10-19INV_21219.docdoc 0db374b28dca6accec9922cc9cea3c56eda7ba671018cd439ad0d276fbf5e919Virustotal results 31.15% Heodo
2020-10-19Form - Oct 19, 2020.docdoc d92a2149efb4bb36191863d615539a062d846296985116874311f6b6733687f2Virustotal results 27.87% Heodo
2020-10-19form.docdoc 8b556f9746db0fc7f51d52bf05efbadb0d23c4a926e03fc453ebe4130e94e18eVirustotal results 27.42% Heodo
2020-10-19Form - Oct 19, 2020.docdoc 48e47f4f38a8a75d27f390be7aba2a82303b7a0ce23b462331814a6c61235012Virustotal results 28.81% Heodo
2020-10-19Payment.docdoc 6510557442baf6b31805cf410d325ba2fdba9b3c28800b0184cdc8b494f42870Virustotal results 29.51% Heodo
2020-10-19October Invoice.docdoc 0dc24e6403ef1cb7caa0c5ac6279db62b96aff3ce815de2b1e2c29ddadba47c4Virustotal results 27.87% Heodo
2020-10-19CH1846654859PL.docdoc 2fb5890b9bcd13a90e2738c8d3e4a9f6d8278d99dd4106e9b583ebf000cf250eVirustotal results 27.42% Heodo
2020-10-19Copy invoice #0073.docdoc 39d251b85a4b04d7b8fb0feda1785ba7c4eb61bc7adbd85726284e25e8ddb9a5n/a Heodo
2020-10-19Copy invoice #88428.docdoc 52525ddfc452cf2e8ed6553c9e4f17fb4f7dbefe1e9f2b8c4f99060cc6696702Virustotal results 27.42% Heodo
2020-10-19OZ09 invoicing.docdoc f770989bd0becf85f6a092d5dcdcf1b5d8938e81f92fd1e80a003a50d8fc4aa9Virustotal results 27.42% Heodo
2020-10-19K009 invoicing.docdoc fbe54be79c471b4bd1e07d539c212938686b838796e7a12bf116a33d25109589Virustotal results 27.87% Heodo
2020-10-19invoice #8110.docdoc e54b5de668787c57fef51bd0a0edaa2810c60d7954eda50dafa9dd243b6180b0Virustotal results 27.42% Heodo
2020-10-19Invoice #28348081.docdoc 827b3b3211b1e6694e7a8484f7fb53f40b3fb5f93cc4039fdd037ffcda0798baVirustotal results 27.42% Heodo