URLhaus Database

You are currently viewing the URLhaus database entry for https://lehuohuadao.com/sys-cache/ed5FfWnoJ2H4l5uYrnyQdhtN2jthwLml/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:755250
URL: https://lehuohuadao.com/sys-cache/ed5FfWnoJ2H4l5uYrnyQdhtN2jthwLml/
URL Status:Offline
Host: lehuohuadao.com
Date added:2020-10-27 07:50:13 UTC
Last online:2020-10-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 07:52:14 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:2 days, 5 hours, 58 minutes Poor (down since 2020-10-29 13:50:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29FILE_PO_10292020EX.docdoc 761d87bcf6f5369f3cf451125ea7a56b683a729b1a4caf4a329bfcf95591d189Virustotal results 41.27%Heodo
2020-10-29LIST_PO_10292020EX.docdoc 1238adf50fa7010276bea39eb50bfd1915d8288181fdc1a10682755abc9b4897Virustotal results 38.10%Heodo
2020-10-29L_AR9B2YFNDQ.docdoc 6a727c9f4dd9cbd0b46dfbe10424610f304eed108280c8e6bed80618b45fa65eVirustotal results 38.10%Heodo
2020-10-29MES_ZW0324572121PF.docdoc 4bfdf04e63422e1f2b89b19ccdd74439826ca27342cac0f98e259109043cb251Virustotal results 37.70%Heodo
2020-10-29ARC_PO_10292020EX.docdoc 4c8eeccd2a16f80874acd0057d5ec622d3701e32a3198bdb763f39e39ea28982Virustotal results 38.10%Heodo
2020-10-29INF_MI2782512961SP.docdoc 40e1e0d4ba67280ae17c0050feb66bf13f27e271efd4fc91413f8553dcf12a09Virustotal results 39.34%Heodo
2020-10-29Mes_66176257.docdoc ed5a9cf9f1dc54e472bd41658cb3f19ec7eafcb34da7257c6407697b879a0535Virustotal results 38.71%Heodo
2020-10-29V_QBPMHZ0EL.docdoc b97d2b5410d55c774746d336facb4fac9b81552a5f84073496d20901af3c5f71Virustotal results 38.71%Heodo
2020-10-29UNTITLED_MV3Z45ON98QP32DR.docdoc 22c6a7d49453bcc0cba779dde369eceffe882a0c338e712b6340a144e4697c98Virustotal results 36.07%Heodo
2020-10-29FILE_DE2494397200TD.docdoc 17d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7Virustotal results 36.51%Heodo
2020-10-28Untitled_JT1599938124ZG.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 35.48%Heodo
2020-10-27doc_PO_10272020EX.docdoc 7d2f13626cd91555d5f9cbdef3a3c17f832e03fc8dc38afb61822dfa3aa37649Virustotal results 31.75%Heodo
2020-10-27INF_UIZ_100120_NTR_102720.docdoc 36178a3ed3f924fd1a1b08abb9f65e5adc5c7e46ecb8c927f993de6dbabbee47n/aHeodo
2020-10-27Dat_49251934.docdoc ff22e77b88e0475f28d9a9b2dc4822b61b19e7f15738af59dfe973bc0bbedaa7n/aHeodo
2020-10-27Arc_76461495796158158.docdoc dcbbbc144f4bffa1f934ff14c9d8a916b19ded7738dfcd1b4f123e3ea73da2d4n/aHeodo
2020-10-27arc_48OWACVDEF99H.docdoc d7c6815a6c9839cb6e4c7b87dd865a478181918dea81112af9afd68e330837fan/aHeodo
2020-10-27Arc_79232313224568.docdoc 8f323b8ed745f486d1959a02ec0b57609d3461405014d5a1885ddb8f9d171118Virustotal results 32.26%Heodo