URLhaus Database

You are currently viewing the URLhaus database entry for http://denmaytre.vn/wp-content/W_e/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:168362
URL: http://denmaytre.vn/wp-content/W_e/
URL Status:Offline
Host: denmaytre.vn
Date added:2019-03-29 12:20:56 UTC
Last online:2019-03-30 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-29 12:22:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:15 hours, 17 minutes Good (down since 2019-03-30 03:39:24 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-30R_Wu.exeexe 244994a6224897de613d7785fbee090435f4c3ffbe583d9af33a92fb8d9a27b8n/a Heodo
2019-03-30Q_W2M.exeexe f932918287d591d361996dd56cfc51fa5bc1c40426d8cd02bdfb82c5a6db6196Virustotal results 32.31% Heodo
2019-03-30O_sv6.exeexe ba9522d7b4900d65a468725120e931e7dd3f628aa6ff03d9856f35dc88ac2b23n/a Heodo
2019-03-30dW_t.exeexe a0a0ca1268f2355b0b6d2555b57d12b43ec1858037f66ea3798a25543bf1ae3dn/a Heodo
2019-03-30K_DFU.exeexe e76effdc1b79a2a952083a68021e0dab8b754b4706b0c36e2ea90c88fdfc8381n/a Heodo
2019-03-30Fn9_ujz.exeexe 417847d001b34ab4eadf2bd03f5b19ad6299d1d349413b5574b3b15eac035653n/a Heodo
2019-03-30Op_14y.exeexe b625568d62bcb64fe0a751c614e9910a0b5f269e8ad961a8c65afe0222d34c60n/a Heodo
2019-03-30Ld_Da.exeexe e8b110698a34558f73dad937aa8861d862489b8b7f15e86d909df744990a4c48n/a Heodo
2019-03-29vF_raA.exeexe a78f2cd467dd9c3003ca8369642a28cc1ceded04b05e317773df86d530ccaf82Virustotal results 26.15% Heodo
2019-03-297_Q.exeexe 865305a3de5efe1b98e1e00f2b7ab69e01a524a224b66034b547f5c61d8263dcn/a Heodo
2019-03-29F_5.exeexe efb2487c29a283c6d69609676ecdc4d27e3c3c721e56af095508b3c2d45e299bn/a Heodo
2019-03-29iY_42V.exeexe 357a7e97f5d1c3ae530f56def699c7352f37bced254b1a33b409a0d9790b968eVirustotal results 19.72% Heodo
2019-03-29UE_9.exeexe e88249055702c863040b1ea0595d13fb033008dc4e467b84739ed871fcf73810Virustotal results 19.70% Heodo
2019-03-29h_RX6.exeexe 32f19e4ea4e9c4bd658f01425eed8255de8ac780e8d93321c266c002119b74b5n/a Heodo