URLhaus Database

You are currently viewing the URLhaus database entry for http://zhongsijiacheng.com/wp-content/jn5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972462
URL: http://zhongsijiacheng.com/wp-content/jn5/
URL Status:Offline
Host: zhongsijiacheng.com
Date added:2021-01-20 16:00:55 UTC
Last online:2021-02-02 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 16:20:06 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com,abuse{at}12321[dot]cn,abuse{at}alibaba-inc[dot]com)
Takedown time:13 days, 0 hours, 52 minutes Bad (down since 2021-02-02 17:12:07 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-28JJt55qvfN.dlldll ac5e8a91d2cabfca7612611a099036c39370d7be1ae62a595507bdf2f09a2accVirustotal results 67.14% 
2021-01-22cTRi.dlldll 3a01dd054895600b372a2280280ca77131fd9037f17897cc8fd35f906979163an/a Heodo
2021-01-22LJriJzvy.dlldll 3dc32b01c98965b3be1c044a55bad1a7668101042fa19497f3733d7790ba4c15n/a Heodo
2021-01-22iBJEB6OzWk.dlldll 4a09f1d7e17a776876531c181cd2378eee69dc4dbf396833d367f72a8e297cecn/a Heodo
2021-01-22XCOSvZyGQNISvTHmycYVE0o.dlldll f5a2ec7716664ae860577125e6e304b393e655a69cdd48c93387c0ec08cc98d5Virustotal results 31.34%Heodo
2021-01-22IJsgZ21eDp17bdz.dlldll 4f0aebbe2bd0308a5f20f96491a8c87875b2373da050bb36f8b9fc3200dc8215Virustotal results 30.43%Heodo
2021-01-20dP9.dlldll 06040e1406a3b99da60e639edcf14ddb1f3c812993b408a8164285f2a580caafVirustotal results 33.82%Heodo
2021-01-20zlDOAgKYV6EYtHiDaYO4j8h.dlldll ea2ca4c2cc5a2f9fbfb1d0635140ae9789af4e6fdd81c0475b73852b1e22bc88n/a Heodo
2021-01-20wq.dlldll cb50189893639b856fc2d88a10b7ea95c7e530c4841f4dcda37459adabcc1b86n/a Heodo
2021-01-20f88IOEIc6AsP.dlldll b3312235dca4aec1ce6fed1098ca64b7994e8018e02e1b8cd43192e9d21a41d8Virustotal results 45.45% Heodo
2021-01-20hIyFG01jAWvWkgNDPb.dlldll e3b13b2cfe284b449da75a906f89214c370f0c90a69b3c613bebce8e74c93238n/a Heodo
2021-01-20X4zrr6AZ5O1lRI.dlldll d5fc27ff6d629f0ca93048ff418959c993a3cf3d947164087fcb5585424f73cfn/a Heodo
2021-01-20U6cJ71GRu.dlldll 3cc58cd56443beb15d37aeb32f192d461e8acd7903ed27a23b09461f3130f510n/a Heodo
2021-01-20FHeVuejG.dlldll 063fb1f44ec310ef80221f4e85ed44f2ddc0c5f51ea072bdd5ec9614e19c23d0n/a Heodo
2021-01-20tER7CrKP114JxUroevFpkY.dlldll d3b5ac4e10362364ff4a158c9e89020cd72ad8eb7aa65685ef94ae97e93a3d0bn/a Heodo
2021-01-20R0.dlldll 8331b4905dc32b27afcf448617eeaf4e4031977bfd32e45c8312e68fd4bec94dn/a Heodo
2021-01-20EcK3mVDTpIHFfgnLr.dlldll f8b2a67dfc599fc482abbb2b3ff2712e07408bdc9d1e1ceab74a9549b8b517fdn/a Heodo
2021-01-20U0T.dlldll deaab0b2d11c38bb21df6e563533b55e975b4b31cca0a47ab3c56412a07eebfbn/a Heodo
2021-01-20h2rxLfpjoxeRnuhZrG.dlldll f6b85dbba37cf887f6f7b52d4ee0e510aec129ea5f7a150b9a4b136c74b9db90n/a Heodo
2021-01-205COU6Z1Jb.dlldll 06ac2fcc64d1a6f04b613948f9d647bf4046dea0903d02074be58b5646e61402n/a Heodo
2021-01-20J3ceMnuMvIuru.dlldll dc4ea913e26b2531c532d97191e325bb575f099fec2a14cd44a5b3f524c3f95en/a Heodo