URLhaus Database

You are currently viewing the URLhaus database entry for https://zhidong.store/wp-content/BDY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:770458
URL: https://zhidong.store/wp-content/BDY/
URL Status:Offline
Host: zhidong.store
Date added:2020-10-30 18:48:06 UTC
Last online:2020-10-31 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 18:50:37 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:8 hours, 30 minutes Good (down since 2020-10-31 03:21:08 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-315CEmO4aUosyc.exeexe 3d23ba14e4ad8f3c679c421f98aa407878f567ff67cc93f41e3c265c56b010c9n/aHeodo
2020-10-312GJ.exeexe 6d636fa2e60720a67358910481c15822aa4f75913b22a6bf82ac204073b0f042n/aHeodo
2020-10-31W169LgszaWo9762On.exeexe 69f034e6fa5f6c5e1965163a646bcdb608b3c7c82921044aa91b4400928347b8n/aHeodo
2020-10-31BesUwf4fglVgtk.exeexe ef5063f628a4913bd91536a593972406182c49a9576058b00b1ec26aceec4f7eVirustotal results 39.44%Heodo
2020-10-31hdC8LWj1HEh6z1.exeexe 6a0afe3da861312a457b7c208675e9dae1f2ca096956208e4ff57c265eb107d7n/aHeodo
2020-10-31cUozhgeOIIb5Wk.exeexe d49d08f631437df6409bf51a6397fabb5e48c6af2c752bbf1de136c6c9e14f76n/aHeodo
2020-10-31vZQmYu0cCXnBJxCLD.exeexe e50b8c74692580ca4f8dd346e12be4dae7c4054ecce6d7025581bdbbdece95c9n/aHeodo
2020-10-31Cs4A.exeexe 5decc7eb3840ac53b123255498159292fc6ecdb00b883030ed30820f257c35adn/aHeodo
2020-10-31zg0vI6ItuC9gQ4tZ.exeexe 08547cdf1abdefbf282a7324a7775dc5170c6881cdc471c294270ef51676efe4n/aHeodo
2020-10-30HMML6u6pGL5JVi.exeexe ba2e533fdb5b0f90c6567ec4b03a7e19e08206ff516ff63aa1ace2a3be3ea03dn/aHeodo
2020-10-30SIJZEhE.exeexe 4b9f9b676e02f28e1e3be05aedd157743297fa054f8a3117f8eeb9f16ad858a5n/aHeodo
2020-10-30SJQTAwox6QyO.exeexe 049d38b5f37cbb720cf5900dc7ea198f089cb9159c0f44ceb3f13696ceffdebcn/aHeodo
2020-10-30lwVBceRGlp0k9.exeexe 4ea248c74b86d3ee78bf4918fa8ceb844d110eaaea9128ab31d15c8e4731ac5cn/aHeodo
2020-10-300hBcAsL8I.exeexe 0bf74a68bcb7fd13dea3b5342a8ba5664882759b0679dc28c8d53d803634b392n/aHeodo
2020-10-30n59uj.exeexe 7e796d433396a2f77f1c250693d6c238bab15570e3937cb0e9b1fce4ebb9fdeen/aHeodo
2020-10-30lSjmpJWhJWj.exeexe 4280ffcb3a808078f523d35e3bbe265763ee443702a7984b0769040427061afan/aHeodo
2020-10-30V9ktNPWnmwRu8DbQ4DtKS.exeexe f60adacbc7ea1c9172869ebe1371d57d070be1128b58cc646c659585db178792n/aHeodo
2020-10-30pBCZ3WxWENK.exeexe c68d850b6e4aee1943044bee59f17a8d1b6d96fd38cd45f7bbb37d55c08fb071Virustotal results 34.72%Heodo
2020-10-305dkjIXNN.exeexe 2070a7c5ac09eea977bb9972f1c281635cd4695c6e2ae75120c31ded8fe6c96fn/aHeodo
2020-10-30CjtGs7BaqJKhv.exeexe c6aa247c15da2822ea4ed029693799c119830f0baa67dcd99092c4fa73bf0e0cn/aHeodo
2020-10-30D9NT6L.exeexe 3e69aac6f85b954f99223c38c462d20dcfeca479208ab49556173ee0fb18f3fbVirustotal results 33.33%Heodo
2020-10-30elNciNbvey8nDC2.exeexe 9f9768e3376a5539e53be05d8695304a5f3ce92a049a93dfc2957845da6d99f2n/aHeodo
2020-10-30OcJ.exeexe e44f56352fb0901bb4103448005bc05c6bb887e2fdf90bc9fca26e1cfd3a4c1fVirustotal results 29.17%Heodo
2020-10-30y98PM0aHBnV.exeexe 5e6849993cde76ded203649a44474011c2e7d08b1eabc030bc737d4254f5181cVirustotal results 27.78%Heodo
2020-10-30XXq8W9y3ciUwZmCMImA.exeexe 2a420c0eaf12f6c8a66bab8f798ee753e2e56194ce0ad604de83400b7a8a34b1n/aHeodo