URLhaus Database

You are currently viewing the URLhaus database entry for http://yixuebei.aitutor.cn/framework/sites/9639841272513841/OFdIZhm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:717459
URL: http://yixuebei.aitutor.cn/framework/sites/9639841272513841/OFdIZhm/
URL Status:Offline
Host: yixuebei.aitutor.cn
Date added:2020-10-19 11:48:13 UTC
Last online:2020-10-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 11:50:07 UTC to abuse{at}chinamobile[dot]com)
Takedown time:6 hours, 22 minutes Good (down since 2020-10-19 18:12:38 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19form.docdoc 1342d806b2b4c5f985373fd1e8c09df85566108333cc0d1b83d89b157e1e663aVirustotal results 37.70% Heodo
2020-10-19PO# 10192020.docdoc a4b8c92319f985d73c2a18a503da3014f22c8d223bc9b37e66eb2288ad27c300Virustotal results 37.70% Heodo
2020-10-19invoice.docdoc f048adfc0ddc30161753c936fc8bdf8ebfe7ef196b91b6dc9d18512263d6647bVirustotal results 37.50%Heodo
2020-10-19Inv_043172.docdoc 2e566c70e52436fc0ea7d447067ed8219ac3009dfb0e7e913fe438ff83b34a2cVirustotal results 29.03% Heodo
2020-10-19Invoice.docdoc a5e0b39bfb2940276129d16f3fc3ff000386b32d37f86e87c7851d8f5b9047dfVirustotal results 32.26% Heodo
2020-10-19Payment status.docdoc f6fd3281268f9d9852dd943457df8c216e4bc14ea1038a0fe86333c4edca389cVirustotal results 30.65% Heodo
2020-10-19015265.docdoc 2bad4983e0009f8f1779d5f668d2b550ce0f75d13bc2b58c3c572c2ada02b21bVirustotal results 27.59% Heodo
2020-10-19Inv. 4432510233.docdoc 76e7f7b569dad6c681fbf032a776f648235158621dc87d8fa6a69244923466c0Virustotal results 31.03% Heodo
2020-10-19Invoice.docdoc 0db374b28dca6accec9922cc9cea3c56eda7ba671018cd439ad0d276fbf5e919Virustotal results 31.15% Heodo
2020-10-19M-100120 YDDX-101920.docdoc d92a2149efb4bb36191863d615539a062d846296985116874311f6b6733687f2Virustotal results 27.87% Heodo
2020-10-19QY245 invoicing.docdoc 5db493718c936256efa492dd02541a687dca5e6dae3419d1794e00f7e6714ae0Virustotal results 30.65% Heodo
2020-10-19invoices 3006 & 7143.docdoc 24b273394c2d503427b680543c2b7464faf5f68ff100dd044404b4229ab56b8dVirustotal results 29.03% Heodo
2020-10-19PO# 10192020.docdoc 6510557442baf6b31805cf410d325ba2fdba9b3c28800b0184cdc8b494f42870Virustotal results 29.51% Heodo
2020-10-19Copy invoice #40429.docdoc 0dc24e6403ef1cb7caa0c5ac6279db62b96aff3ce815de2b1e2c29ddadba47c4Virustotal results 27.87% Heodo
2020-10-19PO# 10192020.docdoc eada559321cb97dfc16509b8cd28a010890c143764138f8f921eb293a48808b8Virustotal results 27.87% Heodo
2020-10-19invoice #64444.docdoc 8ab4861de9dd1a62d8877dcc6d2a82b657d51eb856d507c7f506693dab197353Virustotal results 29.03% Heodo
2020-10-19Copy invoice #6725.docdoc 1219071871b841eb8c5d961956ad81c515a3215513f41291495392f2e5020652Virustotal results 25.42% Heodo