URLhaus Database

You are currently viewing the URLhaus database entry for http://songdung.vn/4d4ixle/INC/XyoGxMSoAYq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:195640
URL: http://songdung.vn/4d4ixle/INC/XyoGxMSoAYq/
URL Status:Offline
Host: songdung.vn
Date added:2019-05-13 18:07:41 UTC
Last online:2019-05-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-13 18:08:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 19 hours, 39 minutes Poor (down since 2019-05-16 13:47:50 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-15SCAN_1395994237US_May_15_2019.docdoc 8df835a0bf2251c91d7c607742cd028f8a97a2dd9adb2c95643d6cff5b302e5fVirustotal results 11.48% 
2019-05-15INC_077972081372US_May_15_2019.docdoc 827608c8a4854bfc571b21271fb2b6311a05daa95f60b0cc69de8dcca02d1d64Virustotal results 12.28% 
2019-05-15Document_30636855476US_May_15_2019.docdoc b593b09f27224656a01d5aabf8cfa0ac8dc8dfc13fe8e307cc9bcc9c44fe9f7fVirustotal results 13.56% Heodo
2019-05-15SCAN_6276918473US_May_15_2019.docdoc 89d27d3e106583ef2e07d184e62702f5653f94454be7bef136968ab9b0f1570eVirustotal results 11.48% 
2019-05-15FILE_2011940109US_May_15_2019.docdoc 90e4c4d3e28cbb8079e45b77198bedfb25fa9dc5383277f2cbaf8bd0c7c7ce54Virustotal results 19.35% Heodo
2019-05-15SCAN_19880327600US_May_15_2019.docdoc 7a4881229ca767839e8b9995cbfcf443be9a032905dd8995ec5d6acb6ce050c4Virustotal results 15.00% Heodo
2019-05-15Document_4592389896US_May_15_2019.docdoc 2b7840500d88aec77c60b247cbaebda3b372b2a80584cccbcf33e4079ac5282fVirustotal results 15.25% Heodo
2019-05-15SCAN_0960085828US_May_15_2019.docdoc e3c0cd46f3b8a3d0eb6c333dcdcfe13c0f3c883c67905f40256be1368473f0ccVirustotal results 15.52% Heodo
2019-05-15DOC_6112562288US_May_15_2019.docdoc 5964373413861ea4771be9df789ec174d7931e41721993a21289b4549c566186Virustotal results 13.33% Heodo
2019-05-15SCAN_4142027420US_May_15_2019.docdoc 0e97304127079f3e4c6cc267f2f49eaf6e5a66736f8fd0e8ad73d6e4641243b7Virustotal results 13.11% Heodo
2019-05-15INC_598976750333US_May_15_2019.docdoc 769cc3e61d5656e37f834b89fec79ba90093a635e9fec85ae8d33164ba3d9149Virustotal results 11.67% 
2019-05-15LLC_88531985656US_May_15_2019.docdoc 3adbfbd11a5299f0f18788996d5d89720bf672ebbc1008fea02ef732f50017c0Virustotal results 11.67% Heodo
2019-05-15SCAN_9959392917US_May_15_2019.docdoc 5193eb38e48695aa084621411de74c0c61759e7dcc253ba2be0947a80c0b322eVirustotal results 11.48% Heodo
2019-05-15SCAN_394564473433US_May_15_2019.docdoc ccbf4c1d8d50c097b3d50b2211242670f8dfafa0f62411cc9fbf671ccbe5b5a5Virustotal results 11.67% Heodo
2019-05-14INC_7537925743US_May_14_2019.docdoc adc07b7378fe4151f14b3b95e74c2672265af06b3defc0d178101a4f3b471ef0Virustotal results 34.48% 
2019-05-14Document_46601766207US_May_14_2019.docdoc 7b24e6266c7a15da11ee8858bfd8bee5239e61321bbed785e7b59fb0e286a51dVirustotal results 13.33% Heodo
2019-05-14LLC_0769629723US_May_14_2019.docdoc 9047c8429ed9cd6ec6c564952494bef62b39f647eaf418c0c61bc8d708d5f806Virustotal results 15.79% 
2019-05-14DOC_176139354294US_May_14_2019.docdoc 28de789ced5a1db62ccda82fb878bd16127d8cc394c8e5d29195132805d7bfa6Virustotal results 35.71% Heodo
2019-05-14Document_2713085401US_May_14_2019.docdoc 13f192a309637a86007d05308e01d86ea441b3f82e3fe3cf4f0211e0b29ba459Virustotal results 16.67% Heodo
2019-05-14INC_3274897062US_May_14_2019.docdoc fc453bf2b437e194f0068004a58dccc68c58bea217aa03f8795153058eac1cb9Virustotal results 14.75% Heodo
2019-05-14INC_6420018215US_May_14_2019.docdoc 8d092f1d799b7cdfa8cd2a35ae350a31d9bc519eb7ad133728afbf1244e624d8Virustotal results 15.00% 
2019-05-14INC_9452591919US_May_14_2019.docdoc 46c6a318203f47e262dce8f6305af0ead6a8d65fde6f875a55ea7715f79c8b0aVirustotal results 15.00% Heodo
2019-05-14DOC_994101369004US_May_14_2019.docdoc 2c9f122d5878f5bbc1cd3dfbc554148fe975e94821b2aec857252e5f445bd5bcVirustotal results 14.75% 
2019-05-14INC_9281422353US_May_14_2019.docdoc 8185a3c6bd0396d6db4871f2490a38f8c4839f6f4819d9cc3b49ece842bcd273Virustotal results 14.52% Heodo
2019-05-14FILE_22359407055US_May_14_2019.docdoc 894005342c01da06b240c3b9fd27c23fe641c86a62733945142b53c2e92142afVirustotal results 14.52% Heodo
2019-05-14SCAN_6320720106US_May_14_2019.docdoc 56b9f6c0b0e06a06a9f25519343accdb00776206015feebbd8f2c7c2d35961f6Virustotal results 13.11% Heodo
2019-05-14Document_14607560241US_May_14_2019.docdoc 782aaa0063c02912db06d46780f6d95c60433aba4933874f5084287c8960a44dVirustotal results 16.67% Heodo
2019-05-14INC_28391981159US_May_14_2019.docdoc da81949e8612caf52635b73cde3d730d4fadc63bb05bf073106f79b2153877e9Virustotal results 14.75% Heodo
2019-05-14Document_2224058355US_May_14_2019.docdoc b23f739d582fd46ef2bebe99960e05dddc3558d8a637ff8a3270da961f563adaVirustotal results 26.67% Heodo
2019-05-14Document_7465614719US_May_14_2019.docdoc d99b584fac9d54fe0ee5bc3e48f1b7a353df8d55e26f32dce61676c69e7890f0n/a Heodo
2019-05-14INC_77310946453US_May_14_2019.docdoc 77151f28477ebd0f46573593dbe4073afa7bc1221908579a89d2183a3ca5c926Virustotal results 26.23% Heodo
2019-05-14INC_9218877287US_May_14_2019.docdoc 0ac02bafc7497a175e8b6321f393b4f4a07f60e1c16065cca1eeb27b00217b46Virustotal results 23.73% Heodo
2019-05-14Document_0059866886US_May_14_2019.docdoc 83d4128af5bfa64a5a011ee5435d26a0c744abf7fba4540a79320240fe3dee44n/a 
2019-05-14INC_59894569893US_May_14_2019.docdoc 130187838b015cbac791a2eb4a4cac0a07114b85e1a18a3352576cce2c5ae1aaVirustotal results 23.73% Heodo
2019-05-14INC_10195895621US_May_14_2019.docdoc 6e27b70e10089e9b815f7eab1b80e637e40733060f22a20e6b010b25287122acn/a Heodo
2019-05-14SCAN_559462194496US_May_14_2019.docdoc 5c4496cdd3ee86af8935d9e1f64e6337c732741df7824571cf15e426f7913923Virustotal results 23.33% Heodo
2019-05-13FILE_150742276093US_May_14_2019.docdoc 95b76cb37e2e3caa0e07f01c9aab219e128ea4ac3cab80aa48e9fc2733713343Virustotal results 21.67% 
2019-05-13FILE_1386111298US_May_14_2019.docdoc b583ba4c5790fa703f047ee77bb5562c7ba09d4ea3845ebc1d0225173dbecf0en/a Heodo
2019-05-13Document_5765541741US_May_14_2019.docdoc b0ba02974163d321b58322351c6ff306db87c9e1ce45a68e7558efc2f8303b82Virustotal results 16.67% Heodo
2019-05-13Document_06037496712US_May_14_2019.docdoc 2ee3c7107a9831e1b1d90d57365700c94ab4033e6515890204c82203e25c7808n/a Heodo
2019-05-13SCAN_27280748950US_May_13_2019.docdoc b311c5c0a459527071166668752e087223a3e5ca6a8c8319ec6ddb0f8ebb110eVirustotal results 14.75% 
2019-05-13FILE_108433171044US_May_13_2019.docdoc f69b477c18524ba73acae4f93ae321077aed3645fd473eaf75cef1314dfd887fVirustotal results 16.13% Heodo
2019-05-13Document_019794828634US_May_13_2019.docdoc 1595c376a6dbe775478a9595ad780829572095d3264e2ad8dd6e9710f9a18522Virustotal results 16.95% Heodo
2019-05-13DOC_2982352576US_May_13_2019.docdoc fee909ec35382c82297015f542c7975ae152623fd04b05a73f81266d44f817fdVirustotal results 16.39% Heodo
2019-05-13LLC_1663688009US_May_13_2019.docdoc 3081d8809d6e4dfddec906b6bc2fde8ea99ae2f2e6c96fc09ce6216ec413189dVirustotal results 22.03% Heodo
2019-05-13Document_958180735109US_May_13_2019.docdoc d1fe265dd306d12a23abe6fb309fb7a55df3cd5072b13e87f9441bfb27bd98b2Virustotal results 19.67% Heodo
2019-05-13Document_6239993641US_May_13_2019.docdoc 6c91e700f82440568c9bb8af07957861829be2801cda74f1634b68080007f492Virustotal results 18.03% Heodo
2019-05-13FILE_89547042860US_May_13_2019.docdoc cf0d3a4c0d0ee09b11d5d6d8a6cb8b36a32097ab9caf3756bdbaf68f5b6e8f7aVirustotal results 18.33% Heodo