URLhaus Database

You are currently viewing the URLhaus database entry for https://wx.wndz.hk/momo/90i2xs6vo6dz4-006651/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:755703
URL: https://wx.wndz.hk/momo/90i2xs6vo6dz4-006651/
URL Status:Offline
Host: wx.wndz.hk
Date added:2020-10-27 10:10:07 UTC
Last online:2021-01-11 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 10:10:24 UTC to abuse{at}tencent[dot]com,abuse{at}qq[dot]com,jsquare{at}tencent[dot]com,dreamsruan{at}tencent[dot]com)
Takedown time:2 months, 15 days, 16 hours, 51 minutes Bad (down since 2021-01-11 03:01:44 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28invoice #1007.docdoc 6c9191798758c5d2cb92a9f60c5d221a0e2d737aa467dfacb65c2a86c5781586Virustotal results 29.03% Heodo
2020-10-280482833.docdoc 262b9ae34d1556927301b3a7e49f106e8a49724b527eaa327938fd5af61ec2ebVirustotal results 25.81% Heodo
2020-10-28October invoice.docdoc 787571d575b3aca0bb534467c986460f8713e2c3168e8654d4dfd2543f1832a9Virustotal results 26.98% Heodo
2020-10-28K9287975380TT.docdoc 92ae5315a4de0857a9f23fa0d4ef298bf2e87573ec75de5c05c6b82c0ca67155Virustotal results 25.40% Heodo
2020-10-28INV #00841 FOR PO #068994265.docdoc ec428d84e9c1aebaf97ee36639823702c4cc91734d326acc91799ba2b3b40495Virustotal results 23.81% Heodo
2020-10-28Inv_51316.docdoc 4adceae76870fb4ce7b6f62e11956b29535594f3b204e657f08f03c44f87e976Virustotal results 23.81% Heodo
2020-10-28Inv_33091.docdoc 1ffb519f7ee20c735692e941193543d406a780fa0756200654c9d442c5166fd4Virustotal results 22.58% Heodo
2020-10-28invoice #891597.docdoc a9ae4ffeff58b0aff2408b43bf5572e071f6d1d77ea83e1331981c2154e105c1Virustotal results 20.63% Heodo
2020-10-28INV #033377 FOR PO #0012447832737.docdoc 0402eac76e97d2bc47ed688412a18594674b7e981d4307bbe0b8491d8ba0268cVirustotal results 19.05% Heodo
2020-10-28invoices 18500 & 66052.docdoc 22ccc563e61d8e3c9936d06fb1d86632f7544d213ae91216e74ad8bef00b45c3Virustotal results 17.46% Heodo
2020-10-28Inv_537474.docdoc d1f0145ea0d4e036edd208387b5c7c012b0eec91562b6f210853152462b2ff63Virustotal results 16.39% Heodo
2020-10-28DH0938595041CR.docdoc fadcbe7aa3d7b823b03d2627cf8a05b229e0f6c7518a71b9c4a106155b04df3cVirustotal results 17.46% Heodo
2020-10-28Invoice #676974.docdoc c6d94cabee4abe9dc14f1ccdfcec3f631453b9e19046806554808e77ddda2cf1Virustotal results 17.46%Heodo
2020-10-28INV #756233 FOR PO #011265445.docdoc 4389a855fc217bc2a9ed342735f09fd3d8d148ff29272d80c2efd4a03a9806e1Virustotal results 18.03% Heodo
2020-10-28Inv_70610.docdoc abc441e8e79d4bbbc2cad82c9c8640e5556dfa439a39b965716dd1cbef7e2ac6Virustotal results 16.39% Heodo
2020-10-28TK-100120 YFZT-102820.docdoc f6835e95393920b5b465037c620c254f15629e9fc86a98b421876da191ff1904Virustotal results 18.33% Heodo
2020-10-28PO# 10282020.docdoc 569a317cc807f72c221acf953d5db5dfba9b51ca788884f24da3dce85e93459bVirustotal results 17.74% Heodo
2020-10-28INV #46321 FOR PO #013526780.docdoc 182920d9a5f644d48dfaf4ff4b3b45ba19446012b6d7a2150f6d53b5c8e773baVirustotal results 18.18% Heodo
2020-10-28Invoice 00080815.docdoc d3b789ffe8bc12eedec50bd95af1d0e1c37ecdbb8e15d61723a63a569c32602eVirustotal results 17.46% Heodo
2020-10-28JW06 invoicing.docdoc 08f27090512f9c3956ec27eea1e9a86ef36d6319b40bfe0b6f1e0c33621a709cVirustotal results 20.97% Heodo
2020-10-28Invoice 046756.docdoc 56e06f27b7f8905f084ac7ddc933236bdf650363aee629d7dd7e1c831aa9ca7eVirustotal results 17.74% Heodo
2020-10-28Electronic form.docdoc 7b55e5dcf03999a440acbe690dddf943d03bd37fbfc7892d196708992044efdfVirustotal results 18.03% Heodo
2020-10-28RXP-100120 YNMU-102820.docdoc 315f90f072f9b3fa2e7a990e0e99915149d5c04c8f772177234ab7c1729c7288Virustotal results 17.46% Heodo
2020-10-28Inv. 006198191.docdoc 22501e141b52a24309578121d2ba63249fc21c36c6b4dbfd0f22635c0a0aae35Virustotal results 17.46% Heodo
2020-10-28invoice.docdoc c63a8f44f5c09d698549f09ef33a6a724157ddd8fba5517d9ef6fa58f76a8ea2Virustotal results 18.03% Heodo
2020-10-28Copy invoice #87396.docdoc 913ad0deee7db9012293779fa15d6491806e2ea0d1935f45991a652ec1b76d4eVirustotal results 17.74%Heodo
2020-10-2800809836.docdoc 5cb3264fbe2a0a59b7e668199d83baa94fa26ef7fa28a375912cf972784cd861Virustotal results 17.74% Heodo
2020-10-28form.docdoc 55555a045c8b3878af56c302aac860598d4216873247ce3332c110e236b11b69Virustotal results 17.46% Heodo
2020-10-28Invoice 00577977.docdoc a77088a16b23e969ba4331abca1b875bdbec7815fe8cd3ca42438e6bfd862de4Virustotal results 17.46% Heodo
2020-10-28INV_03069.docdoc 753c4521e07dab9a1de57a156021942b8e1019f48da5659b28dedbc848c3d013Virustotal results 17.74% Heodo
2020-10-28Payment.docdoc bb6ce405f4c1532b5ae268aa259f4f466533cba2c8ce9b92761b2130ce26436eVirustotal results 18.18% Heodo
2020-10-2800135813.docdoc c029db1506724041de0474946f81191b9ca1c19bb453b59a35c9a4e6db6afa4cVirustotal results 15.87% Heodo
2020-10-28Payment.docdoc dae86e5f6950b75013fc995cadb73abc26cced79c643080cbf10815728971718Virustotal results 15.00% Heodo
2020-10-285739686563YQ.docdoc db1575e9ed5edb424eb7142501e0e6e35fce135e7730d60e63ba53c2d3d2489cn/a Heodo
2020-10-28Copy invoice #4254.docdoc 1ffa0f653207549990a81373d3a44a8be126ef0a7ad5bc5fb2e2dcee681c32a7Virustotal results 16.39% Heodo
2020-10-28INV_502778.docdoc 82916406590b0861a94ee0d149b1e96a4c93ef5cbdf511a95af76eab706b5ed3Virustotal results 14.29% Heodo
2020-10-28013263.docdoc f2fd2a7b312555a475a14cbc6a5300a2d7d16bbcb3f8f5409e6d4d9dd4cd0aecVirustotal results 18.87% Heodo
2020-10-28PO# 10282020.docdoc 80c6de9caa8fb29457e799ff74947cf9a28aa5bae84ca015cfbe75b1edb3c93dVirustotal results 15.87% Heodo
2020-10-28PO# 10282020.docdoc 9f132d350226a798ec1c896757c5b5e81ad9909f4c56f479121e733393ba3d8dVirustotal results 18.52% Heodo
2020-10-28invoice.docdoc d43cadfad58e74565b6629f25e5364e7266d223dfd97fc0eea5acd5665a438acVirustotal results 18.52% Heodo
2020-10-28October invoice.docdoc a0a14d3c83ee0266089dabde6d9b7f238920744382e92852153fdbf23c61f04eVirustotal results 17.86% Heodo
2020-10-28Copy invoice #9157.docdoc c462280cd587897e33d985491193ae9ca4485f62477802b51d41ffe660bf4f44n/a Heodo
2020-10-28invoice #098979.docdoc 2e2ed994b82e41fc67e954b4eb1f6ab9247d14e5b90fdff95a5a7931c926b2cdVirustotal results 42.59% Heodo
2020-10-28form.docdoc e4a4e6c278d0a2cf660e0d6e8cc8359851c32772b4c9fccf98e2b28c9aab7f44Virustotal results 41.27% Heodo
2020-10-28INV_7278.docdoc 59bc37fdfd7ca80bfaa9586846db4d3d14026324219c35cc909e7eed62533e28n/a Heodo
2020-10-28Payment status.docdoc b35d615da70e3502114b5ba61a1979d6f463f7eb8b0fd6bb17d4da8bd1561646Virustotal results 23.33% Heodo
2020-10-28PO# 10282020.docdoc ab8a246400a024e5490c031fe13b4c892da8e1db9687fd937766669b28467255Virustotal results 26.23% Heodo
2020-10-28Form.docdoc 1106469c950b1b99153c9c2a2be93e20fe8e4d91f453f68ef02115ff8d1a8f7dVirustotal results 24.59% Heodo
2020-10-28Copy invoice #59848.docdoc dadb5177f9e33a0b5ef8326cd051e20cf4fcc54cd974cb22879131041e167170Virustotal results 23.81% Heodo
2020-10-28INV #34741 FOR PO #00095947495481.docdoc a1546bd45c31f3d8028e9ed32b37a0394e615efc5a71ea3f36e4696a6a913c56Virustotal results 23.81% Heodo
2020-10-28invoice.docdoc cefdece809bb4ea44a6ed18923e403e409190c61aebfadc97e7eddc70da59285Virustotal results 28.85% Heodo
2020-10-28Invoice 0110160.docdoc 68847f9ed5d1abac2503ab07830a3cad791693b793112d82f0a825f8ebaf9dfeVirustotal results 24.19% Heodo
2020-10-28October invoice.docdoc 6c40a86cca19d777bd981ee02c7511d1e4d2cb3b958f17a34e06eda569c38be3Virustotal results 26.98% Heodo
2020-10-28Form - Oct 28, 2020.docdoc e39757188d82ee09fcb868b4d5ce2f37b8904f29335dfe60501e67a14fa09f51Virustotal results 25.00% Heodo
2020-10-28invoice #4092.docdoc 259791d906d7b260d302a7bdc647160ead5a7cb8c56f04e9888888bea7b5be71Virustotal results 26.42% Heodo
2020-10-28HY086 invoicing.docdoc 0046dd430f33eec36daf84e72714fd8adae02e6cf32755fc2284462d9bce05daVirustotal results 27.87% Heodo
2020-10-2700623561.docdoc 5a07cc5df83be11d085d9a031f8c188b40fc8133ffa322777aed9a7c9a239c5cVirustotal results 31.48% Heodo
2020-10-27M0 invoicing.docdoc eacdc62e23f4dd1edc262c2db5e0139bfe032e0a243db9378d568e0f9e32041fn/a Heodo
2020-10-27PO# 10282020.docdoc 7cdf46cacb08878324d471fc7cec17b333e38c7d76479a164d1115811dccceb8Virustotal results 28.30% Heodo
2020-10-27Y-100120 GOOV-102820.docdoc aaf05aa6da7de09b0f276cb3b3116e61aa22d72769e52a1c85f492d3a1a9e002Virustotal results 30.19% Heodo
2020-10-27October invoice.docdoc 5fd6570201a29865b41f8da78021803a4db2b28a392a583170a80c5f24d76e8dVirustotal results 26.42% Heodo
2020-10-27Payment status.docdoc 0010447fe3ce9d98c5dc301726aa2d717767c7abd1d78c14b39e3055602f7205Virustotal results 27.27% Heodo
2020-10-27invoice.docdoc afea9c0746825b9e47d2063ac184a7dbf66fb0fe1c2fc093a52e0d4cb6b231cbn/a Heodo
2020-10-27invoices 2280 & 3260.docdoc 062ccdaf377390b0400188dd4b76f5479b5c5e4cb11cc321ad63e9223179feaen/a Heodo
2020-10-2706674651.docdoc 14b520153f0acabf64bae7a76718a836373bc0c782a69f1f1a48cdb0ebf62989Virustotal results 23.33% Heodo
2020-10-27invoice #277730.docdoc 8572cb899b936699bc1d20c1b922b10340cab95df6e94f179476da4dd2286996Virustotal results 26.79% Heodo
2020-10-27Electronic form.docdoc 18e31e5b8ad5d3194d4fad561b4c5bf1bece67a65dc3454ef30e5019479afc42Virustotal results 23.81% Heodo
2020-10-27October invoice.docdoc a6d4e2b08b8440d239b850df7a27ee5b2269f64f6c898b0b4d04ad6d596d432bn/a Heodo
2020-10-27INV #01619 FOR PO #07233557.docdoc 26b6c08bbd6f91a2bed79c26264bdeecd3f1c92733a9870924e53eda84d5ccdfn/a Heodo
2020-10-27PO# 10272020.docdoc bb035dfa04791584d81e71d154e443811c21deb1ae691425a9bfe05696187c9eVirustotal results 25.00% Heodo
2020-10-27Form.docdoc 4a10c49813723560898495290eedafdf0dd7dc2ca1e0df6a54cae088c48b9b3fn/a Heodo
2020-10-27INV #0095386 FOR PO #000879936.docdoc c08f488ccd844154239cbddae4e7581df811648b6fa2ac1dc70194f194138742n/a Heodo
2020-10-278980764395JW.docdoc 434066f0379ddf1f34b2422a4ba77ae2447cfa3578993aa72c2ff73367d0a797n/a Heodo
2020-10-27Invoice 562791.docdoc 799de3c0b3c57093a424c4e80e471b26b7f7d121e6e4b75a250304ed59ab9d6fVirustotal results 34.92%Heodo
2020-10-27Copy invoice #463563.docdoc 415b92121d9ef5bb027cfaab1e727cfd0a49c70a998e2ced96f0b21182c6182aVirustotal results 35.59% Heodo
2020-10-27October invoice.docdoc 4dee867bbb0a188951ce67bac529c1d7aefcd46c4964b24f6603829639aafb08Virustotal results 35.19% Heodo
2020-10-27ZE0809927839NE.docdoc f15aa92472c84aa86cb1d1b5a7498713f4709fb544eecccec5d228f4e754561en/a Heodo
2020-10-27form.docdoc 5d36c2fbf5dfa8429067158c959a2d02d6958124a54cbd6f4b1fedae256ba60cVirustotal results 35.48% Heodo
2020-10-27Electronic form.docdoc 083c20d80dfd7f17a95d7bbfd891cc3756255aac0c24d4515b8c3b2d8bf87d12Virustotal results 33.33% Heodo
2020-10-27Payment status.docdoc 0021bbe25ff5b692875ec9b22ecc7f278d7859484560e1b975c37770a227a1cbVirustotal results 34.92% Heodo
2020-10-27INV_60917.docdoc 5c2b628049caab60d1e229c736ae6d06fba6437d2e29bde44349626e3e6b2bcfn/a Heodo
2020-10-27INV #779519 FOR PO #07173615.docdoc 08c57b13f16ca4bda6ae1ccec28d62aac7f7857703319815a6bc56debebb211eVirustotal results 33.96% Heodo
2020-10-27PO# 10272020.docdoc 2c1d441bc9fbb860924d2d11f2063f6273799543293e2979dfce5f0036b0dd61n/a Heodo
2020-10-27Invoice #4946.docdoc 05b7fc943b818ef784499d72667516f200a2bd1365c47470b18769629838f550Virustotal results 33.96% Heodo