URLhaus Database

You are currently viewing the URLhaus database entry for http://tw.wndz.hk/message/Scan/61868541117/VQkCrqTZM/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:730113
URL: http://tw.wndz.hk/message/Scan/61868541117/VQkCrqTZM/
URL Status:Offline
Host: tw.wndz.hk
Date added:2020-10-21 16:08:21 UTC
Last online:2020-10-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 16:10:12 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:4 days, 22 hours, 16 minutes Bad (down since 2020-10-26 14:26:22 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22AA0670 invoicing.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22Inv. 062064886900.docdoc f9390045c0aecc111eb3b34d5a18ed0f8a5f639169463735528801c99fad0af7n/a Heodo
2020-10-22form.docdoc c62002794ed88e1776376cf0144fdaa74155895bd71f5a69b781acf83818f56cVirustotal results 40.48% Heodo
2020-10-22October Invoice.docdoc 3d7c9b4fc693b27da1baecc728c0b4cd72188bac6f7a4f0c8d763e11f63ea2d0Virustotal results 39.34% Heodo
2020-10-22INV #3699 FOR PO #05045588265.docdoc 188d183f83a1b99f55ae2810384c67e6f7be09014e6004bb5ddbf245abda02b3Virustotal results 36.54% Heodo
2020-10-22Invoice #109685272.docdoc 2beec2edda2346042fdfa829caaa7403e7842e786b9b9e89baaf4cd5e45d189aVirustotal results 36.54%Heodo
2020-10-22invoice #8956.docdoc b43eec40f03c1c241fe266b590459a9c24696ea0c5eb65d486fae81eef0f35daVirustotal results 38.71% Heodo
2020-10-22Inv. 108466749.docdoc 2a3debc28e12818dd54c53582337c7024a1cfb99138ea2baf06c6b45a36efc2bVirustotal results 38.71% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 12a9d00947e3f08cb67e3d1a197fd116e29836a17845009e590d283eb80e960eVirustotal results 39.62% Heodo
2020-10-22Payment.docdoc 5825492e4acb3a6e36349f5fafef4745159e86616e9d38b4db2e2b4c212e3119n/a Heodo
2020-10-22Invoice.docdoc 2acac0803d5b5de2f17bb7d2c43af5ad438be8af04faec7bdb33b4cddda2a4d8Virustotal results 35.85% Heodo
2020-10-22007548449.docdoc 2f11fb391c4e5106c86f7af02261b1ce605f84877b62af40538177fc258c9e05Virustotal results 35.85% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 9a666094b1345025d71c0b39d2adbd628fe43f2bc867345884787f6505777ce8Virustotal results 50.00% Heodo
2020-10-22Payment status.docdoc d824b5e0284791def5164b247df302a6cd675374f606a82564092fab93e442d4Virustotal results 51.61% Heodo
2020-10-22Invoice #06943.docdoc bfc258207c269b90840c0f912c129f0f366345cdc1c88c174f59a2848a979d8eVirustotal results 49.09% Heodo
2020-10-227722491419UD.docdoc 69d757b68d226d928a8538ca855767f25d71e1acc3b2cf87443689a15ef183ceVirustotal results 50.00% Heodo
2020-10-22Payment status.docdoc 97b65be9fd47454760b1e5fd5912b7ec4d36712b38bc2c381b4671464abc096fVirustotal results 50.00% Heodo
2020-10-22XA5656220252PB.docdoc e61b38e662adb534177ec713ebff6bb70aba8c3e9ba4bd47c6f06229f803c1d2Virustotal results 44.07% Heodo
2020-10-22PO# 10222020.docdoc 495313b4809b48cfad065e665cb9bc04759262897b08b142734ff1f15316f5d9Virustotal results 44.07% Heodo
2020-10-228998643084.docdoc a89a346ba95533594891a15e53625209199e68bad7519485b3bfaf1954b2a8b8Virustotal results 45.16% Heodo
2020-10-22Inv_74135.docdoc 973f68fa660b0ff4da0047bc9d942a6f2faf63713e745fe19eaf4cf5d29828ben/a Heodo
2020-10-22Electronic form.docdoc 7132fddab8ccd72577838968f3e91a36c9ce64950fde88e34635e5e008be8a13Virustotal results 43.33% Heodo
2020-10-22Payment status.docdoc e5ed1f6d9906107a56334a0f4903201eeeda7aa77f349ac217c53c9540b03c17Virustotal results 43.55% Heodo
2020-10-22Form.docdoc 3abe5cdbb82a1a48fb89ecf043e24351ffb466cb6112ea7316f6fb518244a289Virustotal results 47.06% Heodo
2020-10-22October Invoice.docdoc 2964a315de69bb8d274293c5de39c877468fa8f5395e04639fb3029533bc4c45n/a Heodo
2020-10-22Copy invoice #46758.docdoc 4d7e619f0381816bed7d0ffb6ea0a43ebd6050cbfb10f691c1bf8d8466c11345Virustotal results 45.16% Heodo
2020-10-22INV_45183.docdoc 055119f6a2254b8e3290900b29c2b27583428faa9f051bcf3b7c9a31f309f052n/a Heodo
2020-10-21October invoice.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 45.90%Heodo