URLhaus Database

You are currently viewing the URLhaus database entry for http://jiafunongye.com/application/NJ3Ta/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:735814
URL: http://jiafunongye.com/application/NJ3Ta/
URL Status:Offline
Host: jiafunongye.com
Date added:2020-10-22 17:47:14 UTC
Last online:2020-12-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 17:48:05 UTC to abuse-noc{at}west[dot]cn)
Takedown time:2 months, 4 days, 20 hours, 17 minutes Bad (down since 2020-12-26 14:05:34 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-11-21wPf9vIpCD4Zt99.exeexe ff5facd40715f5a716a3d9deddfcfdc3a7660eed8265be526f4f1c21454825c9n/a Heodo
2020-10-230O9elApNA1sbXoPqg.exeexe d5427a7047589c85e3399825b7c014e93f704b6e8449a2e744937faf1f31817en/a Heodo
2020-10-23pupVmg.exeexe c5ef1b94f4eb546590690961645000597638c9ac624976d83b688e0cfd791829n/a Heodo
2020-10-23WPIcXj8BRaP.exeexe 107158a43512d72ad9452b79827dd8462120043f24133826622b30310c58399bn/a Heodo
2020-10-23C2Wa.exeexe 339ea641c251e8e1cb1483d98223b1c8e0f4c409554fc066cf8de910dbf9f093n/a Heodo
2020-10-22lZr.exeexe 69fba1bcf41f9b083505a76de6e1b89876e53c1dec8d19488357f98a3d26c7deVirustotal results 19.72% Heodo
2020-10-22sbJg1jyMhqia15r.exeexe 4defc8a720af12cba0c041c7a1e273a4195dc53856ff4bbec162ebd114a28376n/a Heodo
2020-10-22seHt7tGf6JJ7m2bm.exeexe d0f26d1527386ca662631815343bb8a544ecd8c33e89cf36dff16e7e6a6cdc2cn/a Heodo
2020-10-22YVEuFydffH1.exeexe 266a796d72ca12079b41a83df50f258e93ff355f9a58fe5985e6d21642630a5an/a Heodo
2020-10-22u.exeexe e8661b574ca9fac5417360aa3030c1d3a27f2a7e5af7fc2d75a80d223d640b30n/a Heodo
2020-10-22QUb0hICcQYd556N.exeexe 33ce64a25c20eff56ca3598d6dbdd184b83e6832b490251af167a3d4ecfd6c81n/a Heodo
2020-10-224PeV0SpAgewz.exeexe 174fa39bedf9321a68747e25e2a10d72cffe9f9270939f513e2215984e4aec48n/a Heodo
2020-10-223BjSc.exeexe 06d7f6c87b546676e0a0c7952c1f010c8261e8bf7de79f71765db43501921a8an/a Heodo
2020-10-22fIn7oHrYpz1kDoOjb0UF.exeexe ec4dabbbe18be8f9f711233bd5db7a3ff5ca8d910f6be3f8cbaf3f0bbf392ecbn/a Heodo
2020-10-22fiMHwZ6zH0DGKbyA.exeexe 7bcd3e36b49594b6bc36a664fc9e18f82476ebc2f5a03637ba1deeeb6ceca1ddn/a Heodo
2020-10-22GHCRgQeNXYQ4pk775TNP.exeexe ecee41831c3ac135d08d81f97c8a659e5602a023f3dca46bd5426f17ade4cc02Virustotal results 50.00% Heodo
2020-10-22hLcZ.exeexe d00322e456e8366f7aa26fcc64915a702fe182017f575f8dd899228e659275d5n/a Heodo
2020-10-220aMz3.exeexe 74f085a4c021a705c6885b4adbf4f972d941ede2df43ed91f2e444ce8cba26f1n/a Heodo