URLhaus Database

You are currently viewing the URLhaus database entry for http://www.bifangting.com/wp-content/f/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:948920
URL: http://www.bifangting.com/wp-content/f/
URL Status:Offline
Host: www.bifangting.com
Date added:2021-01-04 17:52:04 UTC
Last online:2021-01-05 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-04 18:28:03 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:8 hours, 47 minutes Good (down since 2021-01-05 03:15:30 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-04WTYl.dlldll b730a71f7d60d965bfbe401b04a31124a48cb31a04f40c626c98c4e2be013384n/a Heodo
2021-01-04Ji4.dlldll bcc3ea8bfcf80ded9f99fa3e63f284ff75ca32f3aa667b58a88743c5b99203b8n/a Heodo
2021-01-04X2zCL.dlldll cc70e868c7fa10ff148d684f9fba158c38cbeab858d101bb9fc77f3ff0fd816an/a Heodo
2021-01-04KBeMBPLLVgompVbxBt.dlldll e41e75b2318d567cea9438c24872203cc8226de1d92dc22baf5d97f7ea27c84bn/a 
2021-01-045P0fd8fcyOcPYpIeozh.dlldll eff47358c71c750700eb798a256d650cbe3c230e5a822fb35b8f9b17d2cd95aen/a 
2021-01-04t6c14jsXxUjW.dlldll 670860c81a636194a1d1edffd389656998fab3c8237faca81d13715a429ba7beVirustotal results 5.71% Heodo
2021-01-04lqAttsFEG.dlldll 31fad45949ced511d203d1d0805bf95108595c899fdab3ff5d4dbeef700b2034n/a Heodo
2021-01-04MWme7FcSI.dlldll 79c8c5e2834b2c596490e50736ededbf7e1446111aea3f4c1a334b8064d6b3baVirustotal results 5.80% Heodo
2021-01-04Lwwecr1OVF.dlldll 68637cac0acb9ec607a648defe58e68c6b031549f054843ed5628041da60182en/a 
2021-01-04scLXEV7hCqq9bNx3S6ScEVi.dlldll b7ae9905a4140af5302a23923cceede3254bd3c282e2433e4e7743432d4ea962Virustotal results 15.71% 
2021-01-04bwyEMz2xb5JPBAG6.dlldll 8e79f1c936d1fd85276914d35f5bef7b248ee897c31cc49f0920f609c4850d11n/a 
2021-01-04hSbkrDZZ.dlldll adc4e1d237f95ef12c4fda959167dac7284d16c5cfe9cb099785dbdafcf1ba8en/a 
2021-01-04CwK3r.dlldll 2439b041d664ceb7470e681c811bfaba84aa7265c3d770dfca4ca932e661332dn/a 
2021-01-04IrvXoQTqf.dlldll 528b4c0301fa2b4a39bf4f07494ba9e517e9ade116301ae2c8ba1a337a287ff8n/a 
2021-01-04vGoE1tV3Qc8tLhT.dlldll bcf9429968672587b4c1fe5d3c7723235d92727be090a702572870b6933a05d3n/a 
2021-01-04fEuvBlxEBDuAl7ZvK9nv9.dlldll 64428016104a501f88233dbdbfe0e02b5e5f89b06f6c228d0a9bd9e349451e8cn/a 
2021-01-04MPFYxyNa2LiU6Y0mOG.dlldll a4f85db0a25ace4d6fef3bac43108d381267f18339fcca5ef35b571cce5c49e7n/a 
2021-01-04qARYFtUzWgtG9s.dlldll 55b2f6b84140083ee1441df41ceaf9128d6a0d775772419f0361cc7308909bb0n/a 
2021-01-04isTONPl9Xsa7X.dlldll d276587769fb85aa4d4d7ac91ff38094c1df33f7f5fed457ae27d5895e48c686n/a