URLhaus Database

You are currently viewing the URLhaus database entry for http://denmaytre.vn/wp-content/INC/ScpZVGKIz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:183050
URL: http://denmaytre.vn/wp-content/INC/ScpZVGKIz/
URL Status:Offline
Host: denmaytre.vn
Date added:2019-04-23 15:38:08 UTC
Last online:2019-04-24 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-04-23 15:40:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:10 hours, 5 minutes Good (down since 2019-04-24 01:45:30 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-24FILE_4503826304US_Apr_24_2019.zipzip 11105dbbd32ef6bae6430dd65674152b05863686fb9ffe82fdb5ee6366706ef1n/a 
2019-04-24Document_209778944707US_Apr_24_2019.zipzip 4404d9ec8de075388f19e1304e0f84b36544b85de50d99919c4efd2dd51260cfn/a 
2019-04-24DOC_54024744467US_Apr_24_2019.zipzip 2643db60621ed60cfc454979db406c7da3203a4356b187511fd9345cc3372f24n/a 
2019-04-23SCAN_561401051669US_Apr_24_2019.zipzip faca0a6608ac064a6181125cfb23ffd13a2d36ce20f011e3f72601d164e49f4bn/a 
2019-04-23SCAN_307729891203US_Apr_24_2019.zipzip 237eb01362c78605da5bcd5531184fd80a6ebc9c6257f59220b8b7191834a2adn/a 
2019-04-23DOC_28435936635US_Apr_24_2019.zipzip 159a730267b8a12f6dd90900d17030d4d4d557531e117fcc7ef3dd5703a76231n/a 
2019-04-23DOC_98777951728US_Apr_24_2019.zipzip 29e174ea4d20fce3fc2b5c9ccb4d3109b783f8f4e15a98a04aac922b7efd0566n/a 
2019-04-23DOC_0026957250US_Apr_23_2019.zipzip dbaabc398cdb8109bd6b568afebc0974cb5077b0d896ae873e3653855815c8efn/a 
2019-04-23INC_10062413616US_Apr_23_2019.zipzip b22343596e293386d5ef911a3cfc42c3c4466f4ec73c28addd1e9f74559291f9n/a 
2019-04-23SCAN_94714459975US_Apr_23_2019.zipzip 0b9c2a1dd0e38f9c0677811a006fef6711dd31603c31435c3c79123f598c44c8n/a 
2019-04-23DOC_02263594445US_Apr_23_2019.zipzip 255a613e9063b3aa8c8d8b0d79334b9da426f30de30c117599a48a602809b7cbn/a 
2019-04-23LLC_4968464129US_Apr_23_2019.zipzip baebe82f422b17e9ec8bca1cc6709c37829922b0c995399cd291de1c0acc5294n/a 
2019-04-23DOC_26261798841US_Apr_23_2019.zipzip 3b3039cf4f6d3cef0d85ce8814bc9a4d8be95d5e9b2d26f19747dbf3d4ec6436n/a 
2019-04-23LLC_92579850842US_Apr_23_2019.zipzip ff8c98addc980641f87c4e0b8a35cd7e5b1773bf29b43f84e41574a449f86c4an/a 
2019-04-23FILE_220207900458US_Apr_23_2019.zipzip 09ad9e1f19bab430a17b9816e811debb99cbe52e202f3902fbfa14eb3e6ff8a3Virustotal results 21.67% 
2019-04-23LLC_5558260612US_Apr_23_2019.docdoc 99e638f6c4aa79656fee7ce55d9006b0d32618e4ab7126a221f21c1145d6dafaVirustotal results 32.76% Heodo