URLhaus Database

You are currently viewing the URLhaus database entry for http://iog.com.cn/logo/zkTiV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:758128
URL: http://iog.com.cn/logo/zkTiV/
URL Status:Offline
Host: iog.com.cn
Date added:2020-10-27 21:35:07 UTC
Last online:2020-12-23 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-27 21:36:21 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:1 month, 26 days, 9 hours, 6 minutes Bad (down since 2020-12-23 06:42:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-01Untitled_1134185824.docdoc 1053508dba9607d8d25a553d3059249c8ff3fc0f143ea47103c1842a20098c2cVirustotal results 73.02%Heodo
2020-10-29INF_PO_10302020EX.docdoc 7c6a482b48b1e04e7e5229c4d04be12cb8ee21aa7a7410219fdee44e048e5326n/aHeodo
2020-10-29UNTITLED_MB3997159061SX.docdoc 00f960f2c4dc8abaf471b3c55c877aad66b636338bd2d67a565393058b78c125Virustotal results 34.92%Heodo
2020-10-29HKV_100120_TXR_103020.docdoc e100b5d71867c3b5968c32b026533a0ff7cb8ece201cced23b63fc7c65bb2cb5Virustotal results 34.38%Heodo
2020-10-29Doc_OY5759293599XG.docdoc 37ce904c25d97f1199866c304c053e85219d0b201d3015981963506a9a65e327n/a 
2020-10-29FILE_142425308115719103.docdoc 1aa45bfd6fa4890726daf11261b2aa4a7a23e9506d1845fc62edac1734669c26n/aHeodo
2020-10-29Arc_PO_10292020EX.docdoc aebaaa277983fed939f7025cfb03b61ff9a049ff8288077360593f4a3dbb8563Virustotal results 30.65% Heodo
2020-10-29REP_08061940635398.docdoc 2d94f5620906f353b2bda6b6eb984695737cdecd6ddc88ca747fad5bc457d090Virustotal results 31.25% Heodo
2020-10-29LIST_68191591.docdoc c864f510cfcaca5ca5acb2a8ef66706e173195d47f0bc0956f1757e9f74325d1Virustotal results 32.26%Heodo
2020-10-29inf_2QAIABK1QP9.docdoc af09d9b10580277dc290b458dfb6b85501ce39d6e430f87ee3fd349c3f672860Virustotal results 31.25%Heodo
2020-10-29arc_21415300.docdoc 413b38a8a1796a27fb2b85f7a6fbb12b86499a131a2f86a75862afcf9b4c8ce7n/aHeodo
2020-10-29UNTITLED_LM7072392491JA.docdoc 66f21ad9f94f3926c870736b3a33af58b00eea538ae8da9b7cd71ad1eb5614d6n/aHeodo
2020-10-29Arc_5032191644126565983118.docdoc 97c76ac78999951c70f47dc20b137d6a5f843fbd9597f8a62e977d4b463e2c79Virustotal results 26.56%Heodo
2020-10-29dat_BHP4AXE83VKI6Z2.docdoc 5a586d16a655c4b142b0d419a75c12e385b6f96a2eb46e966663b8b820556f3an/aHeodo
2020-10-29REP_GT6193524643HR.docdoc e71176f87f966b10a6770fcfffe18e9e8ffd08139967c62d7ff50e63ece6b72fVirustotal results 22.81%Heodo
2020-10-29KAZ_QM1184018459PX.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-28Rep_48557704.docdoc cb10354a6aff051fe7ae1c2cfb38b40e5ed1c8fd1a4c4b1a35724efed4885995Virustotal results 17.46%Heodo
2020-10-28KKG_100120_CFR_102820.docdoc f557390768f97bbb354c11917ec9e1ae3447832fbc09b34625656d8cb3db0931n/aHeodo
2020-10-28list_PO_10282020EX.docdoc c88a8bfd26b88fe11810b85a6ced566f6ecd9c06b535f98d8c7451c66c1716d2Virustotal results 28.57%Heodo
2020-10-28rep_TXZ_100120_CHC_102820.docdoc b2fd50c9b74180bf57162267feec075ce16b9d37ead25cca5f97840e44e61a1en/aHeodo
2020-10-2817802910.docdoc a2b3de3e6d67d8b984e20da13e2338fb10bb97088378f08537ed93228f6850e1Virustotal results 28.57%Heodo
2020-10-28ARC_907609459337868225207706.docdoc 5acee595ee1bc75adea710f92e969aa5c62d0a2693b6dc8c678b2bff8a4a7e51n/aHeodo
2020-10-28UNTITLED_1458816712.docdoc 0fdb302c3db79d7ed89244d7adf4c56d5cc9e4643c3e5bac39c3e82cff3834e7n/aHeodo
2020-10-28Rep_06216684.docdoc 2964b5d28a8d65a8477f44ee1cc2b6859302f4e76e07a48217e9d948772ecb36Virustotal results 28.33%Heodo
2020-10-28LIST_PO_10282020EX.docdoc 520ca27ad3a13618d306b397f83a91daf238997358520459895991c6285328e5n/aHeodo
2020-10-28inf_PO_10282020EX.docdoc 06472f9f7853e0506b85ea1db0bb693aacedee79ad413c1ca0839a322f834df8n/aHeodo
2020-10-28DOC_E898ZJE8OOB3.docdoc 95d0a6acc83d661cf2f495f1e9b4c465b64f5fcfdfa6a75c0ad72beac8e31b19Virustotal results 28.57%Heodo
2020-10-28Doc_4LXBNLBL0OSY.docdoc 4da551741b2fdd1985b8f8dd865cbc2ee100a8d82d80a39e33f56dbda25b4f1en/aHeodo
2020-10-28file_PO_10282020EX.docdoc 86cdca7c9ac7ecd5defa0fb8c374cd773aad5df00d6678e7f5addc0268a097e3Virustotal results 28.57%Heodo
2020-10-28Untitled_523290479.docdoc 68cb170125b6d8fe85e4573f3324f27ca595e8a2a2f0d624742c817590b42765n/aHeodo
2020-10-28List_PO_10282020EX.docdoc b10f4a4b46a88d8bd137cb2d76eb827b89f16acd953490d55b6161aa0e99b7aan/aHeodo
2020-10-28FILE_AA3460949927ZF.docdoc 101fcc93c33f4a28332bd09291db3501b3d13ef433719cbf7750e9f6a73b88f2n/aHeodo
2020-10-28Mes_6BDS1L488PI.docdoc 1d6286cbe99db0f75e74a7ce7e77a50699b075af54aca64f8d2fb9c235f5d094n/aHeodo
2020-10-28Rep_64113840.docdoc 0b62b154422aa927a6906a75fdc8edfd4c143365e4b5e4a8ffd58badd6fdb0d4Virustotal results 38.89%Heodo
2020-10-28rep_227731749803.docdoc 2a46f3f595f2eea533b556a67f2558d85d955f1784d1d48cbe78b2e5fae35f34n/aHeodo
2020-10-28MES_LO2771184587IY.docdoc a04a9caeaaab58a3e7ba0ca98fe001e59df299a8f34f3c86994128170c74b5ffVirustotal results 27.78%Heodo
2020-10-28UU7328841643QN.docdoc 1371c2d34a1e3ad727d60804b08ef021e7568a841acc95ce5cf1773149657ea7n/aHeodo
2020-10-28967260445.docdoc 3120df1e06f01820a9e9aaf64e33f5ff4b4e39647ef7552f6f98535a9c17e68dn/aHeodo
2020-10-28BP_PO_10282020EX.docdoc 95d5a2d7dcee12209de69b8db569c01e68322524257ca16c36f43ac546532c95Virustotal results 25.00%Heodo
2020-10-28LIST_47868495.docdoc c3e8b7bf6e9c96cf2335ab8c491d537cf81a2c322e9b305fd0545d051c613a83n/aHeodo
2020-10-28FILE_40910619.docdoc a9dab3a7ee17c4e9ebd90271c21ba1f27a69094147e4f37b14e8b584ef3bf74cn/aHeodo
2020-10-28Rep_YMR_100120_UIH_102820.docdoc 384f0ac6af41ed895424d29854b510286d7b1c075150dbd313f8682f26eb4249n/aHeodo
2020-10-28dat_BK0941760800WE.docdoc 43159cae0059060554e0c283a577d48c0b825e44856b3afcf24ac2f6ef831334n/aHeodo
2020-10-28doc_62054343.docdoc 5e692d0f6341638d540a0dd0458062a4852cdc65dd6551956aaa28c4d417416an/aHeodo
2020-10-28Inf_74817249.docdoc 42437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17n/aHeodo
2020-10-28DOC_2721192315810531.docdoc ef87afc95689c73759bee33f83ee37d3a46dcdd5dcd498921e9cc06eb3f02455Virustotal results 22.95%Heodo
2020-10-28FILE_592040411860148051683375.docdoc f6fd4d78eaf23a55319eb3b14344a592bfe7d542cf1f7e45a9ff6fb8ad9f90c7Virustotal results 23.33%Heodo
2020-10-28UFC0H4M5QKP.docdoc 4d2065b87b5e9b6d1f4bc0bb53b3244c9d61eb3fd8c95d64757935758065ff29Virustotal results 22.58%Heodo
2020-10-28Untitled_SI8631599744FG.docdoc 6310463115ebc704a66281738da24d3ddc5e2b7142db330ffc61d25899c74869Virustotal results 22.22%Heodo
2020-10-27Arc_SB1827801428SS.docdoc 90f1f20d90c0a5c6c32d6eca01833ff1db7b1325a5db427d7c5871fe3d5096f3n/aHeodo
2020-10-27FILE_PO_10282020EX.docdoc bab42b7ee6d4b385f15274f7900f7f2a4d5d68d7f527d20b0bfac926752f9b3an/aHeodo
2020-10-27list_G2CEKPCQ5V1.docdoc bfc255c1fae47d22c3a502329ae24b49b0fc4169c49c13a4b1091cb686e3ccedn/aHeodo
2020-10-27REP_6618724297256275778871.docdoc d63d4a763ad9df9bb9fa87fece48df3f857bcd1e1aa9a3f37a472c4b7394c500n/aHeodo
2020-10-27list_PO_10282020EX.docdoc 4791b5ee50085457d0dce59a52da9717357b5112a9138b69ff60bc3003f32e25n/aHeodo
2020-10-27inf_29983994573303506704.docdoc 45130c5318fcc42b669d0caaf4357938d1f8ec66f9d5f96b8790e6f08f05e13dn/aHeodo
2020-10-27mes_2CTXUXWBFHAIGUAA.docdoc fc7ce8ff56832fc6cd1bdb013de966cae38ff1e593a06e22f0e9764e09528a01n/aHeodo
2020-10-27Inf_QF6937466234NF.docdoc 6f039cda124b3110f8548e74ec351aa886366ae495da7fbada087f175a56e6c1n/aHeodo