URLhaus Database

You are currently viewing the URLhaus database entry for http://demo.ibig.vn/cgi-bin/69794017GOEZTTKWRH_0005/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968166
URL: http://demo.ibig.vn/cgi-bin/69794017GOEZTTKWRH_0005/?i=1
URL Status:Offline
Host: demo.ibig.vn
Date added:2022-01-11 19:22:06 UTC
Last online:2022-01-17 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 19:23:10 UTC to abuse{at}digitalocean[dot]com)
Takedown time:5 days, 17 hours, 59 minutes Bad (down since 2022-01-17 13:22:51 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-12876YAPWYXEVU1682686.xlsmxlsm 663ca3b8545e4e02572b5d348a1f77c7ef30d1810e8adbe25dd699b2cfb1792fVirustotal results 9.68% Heodo
2022-01-12ZPGZ_8798690.xlsmxlsm c95bf0dd160b7a12ab600aee9220e652b1b1cc3b006f264c324a0c0a9d5aa257n/a Heodo
2022-01-12831_05984.xlsmxlsm 978af74bf15d2a91d89790b36c10deb099346510e755e8915883f43401b3fe10n/a Heodo
2022-01-12tli844328.xlsmxlsm 947dc8d6c337a63466168a9efb2e42e692fad8da89af9c4c295fcd174a89c979n/aHeodo
2022-01-11xihjzzf_62.xlsmxlsm 1b8fafe40bc98e1d41a794e824ab4ca505634fe25fdea8a3e560be3938ba1b58n/a Heodo
2022-01-110018-66647.xlsmxlsm 427080f3d4da3ec0746fc297c0a922b5212a53ae04504f5efd17ff4f9208c662Virustotal results 10.17% Heodo
2022-01-117872-5111.xlsmxlsm 6ec9e504112744f9f07ce60fb9315cdcd427d27a16c248fbe9746477bfc851afn/a Heodo
2022-01-11UJW09.xlsmxlsm dd14be16e01e5fe53b7cf8199af830a979dbbbc33593606f3b25d7ea3b32697cn/a Heodo
2022-01-1142825202-20374842.xlsmxlsm b8662d7aff6b2489b65fd6ddc022a5a87c6adb0e1ed1f0286ccd80c0bc11471fVirustotal results 9.68% Heodo
2022-01-11Dx_567.xlsmxlsm 20be5590c08561d3a5be97621400daf8528533950a589089a00a259da40668d8Virustotal results 9.68% Heodo
2022-01-11I-81.xlsmxlsm 71da6e57fe5adfa0b06f8ba9525e6db95e7c25246179fa8563561d24e79e6c65n/a Heodo
2022-01-11XYQ86116.xlsmxlsm c4bc03a927a72a21be0b15c8c55124264c456a940a325d8071f5cbcb7032f1c8n/a Heodo
2022-01-11573241-1.xlsmxlsm c2cb81db208398e070c47e7d03e76709142dec85ddaa985883536283a0acbb14n/aHeodo
2022-01-11YLA_83054.xlsmxlsm 79a935edd516953713a4d4565e5dfcbbb08f17b9633f31d84e0e042a5de4c178Virustotal results 9.68% Heodo
2022-01-116610827_652.xlsmxlsm 270cb830f364c3927df68940e7fc558934d424996c1599fbcc9b95fde938f041Virustotal results 9.84% Heodo
2022-01-11YHP6990335.xlsmxlsm 95761ae4efbb60ee498b7d56d6c84e48753a21ab59a655f5439b47167baf6ea2Virustotal results 9.68%Heodo
2022-01-11ZCV3.xlsmxlsm c7361097a3fd04904faaab145a9e15e79e0a3f772aa9f0e374e8ecb7e2bca145Virustotal results 9.68% Heodo