URLhaus Database

You are currently viewing the URLhaus database entry for https://buygreen.vn/wp-content/xNstv-CRWKqfiIKKypFSK_MCUjOOEfp-lf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:175097
URL: https://buygreen.vn/wp-content/xNstv-CRWKqfiIKKypFSK_MCUjOOEfp-lf/
URL Status:Offline
Host: buygreen.vn
Date added:2019-04-10 20:46:06 UTC
Last online:2019-04-16 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-04-10 20:48:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:5 days, 7 hours, 30 minutes Bad (down since 2019-04-16 04:19:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-128442304057_Apr_12_2019.docdoc ee352220a6fe55fc2855a34e07505e798ba259d12679f600ad009be75abc6c02Virustotal results 29.31% Heodo
2019-04-1202935322358_Apr_12_2019.docdoc 7b8e0e43c6fc604494de61789257c020a623d8da87965b427cba5d3ae0afe170Virustotal results 31.15% Heodo
2019-04-1206763523414_Apr_12_2019.docdoc aeab1bafd4daa9f9655d052a981f79fd02cca0b34d141d73c2eb37dc0257f9c7Virustotal results 27.42% Heodo
2019-04-12353965987068_Apr_12_2019.docdoc 661f7d9aea272c78f3b9ce42bcafe6062e48e5ff803b1dfd9c11b3c8053b2ea6Virustotal results 25.86% Heodo
2019-04-12527640198274_Apr_12_2019.docdoc a3cfd0e6eca49517a28f5b354291312c2781d3517a17b7002281d043e60d66a4Virustotal results 24.14% Heodo
2019-04-1275315687617_Apr_12_2019.docdoc d19dd9c5a067773621a5f7843f74300f9a394d28917fa03e76a09589a0ef7d16n/a Heodo
2019-04-1219122293215_Apr_12_2019.docdoc f72c5e3b61465f474ca5e06389723a8369df133def8469cbea058135c0a38662Virustotal results 23.73% Heodo
2019-04-1245483059450_Apr_12_2019.jsjs 1f18a298cc1cdd9527f5345e3ac6438cadffdbf62a1f2a4dc69a22a626980c41Virustotal results 6.90% Heodo
2019-04-10522629040704_Apr_10_2019.jsjs 26b5d6c8934dbf593f2cc541bacac6e7812d71ddec256eb7bb4e9dd61b9c13b4Virustotal results 8.77%Heodo