URLhaus Database

You are currently viewing the URLhaus database entry for https://vnamazon.vn/genethliacs/14AMO33388/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984561
URL: https://vnamazon.vn/genethliacs/14AMO33388/?i=1
URL Status:Offline
Host: vnamazon.vn
Date added:2022-01-17 21:06:06 UTC
Last online:2022-01-18 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 21:07:12 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:13 hours, 18 minutes Good (down since 2022-01-18 10:25:38 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-183908431495.xlsxls ef7820c85bc6c3df2447132bbed914ed101aeb7baf6e6edf25026375f9df3980n/a Heodo
2022-01-1857816838663162814368.xlsxls b4a49e89e7852d569ea4a0d6abbfb489a53b392e38fb16270343b54b2cc34b00n/a SilentBuilder
2022-01-185076992406.xlsxls 96fb18491f6cf868e63171c4ba461b95b4b74d39b1ce4ea5e4e96373f97dde26n/a Heodo
2022-01-1897627333152364458.xlsxls 35da04ff2a62f8c0275a0e10151c69d9cfd7fd35dfc2ef154105492a517023d3n/a Heodo
2022-01-18051214797119.xlsxls fa10d4c1be08f4e283bdaaa42a1d800768187162e2d90bb494fa4367dcd494adn/aSilentBuilder
2022-01-184877332693912060534.xlsxls 0971b78a1fa100002ec0c3cd1d18af109e56369c4a52b4445f10c30ea8ade7fcn/a SilentBuilder
2022-01-18678965929981377365.xlsxls 0462fb1b5a8a7784bb9b1dc90185c6b031d6dbc1ca9256bc59a34bab1c87ab49n/a SilentBuilder
2022-01-18531959488839931.xlsxls 30ec22e5f956439cc697c71a92a8f806335253f5b692b8375cb4acad148b5cd2Virustotal results 16.67%Heodo
2022-01-18519351217966.xlsxls 4ad545641ce10800bcd2a75f03ae32b78d9fce1feb504c5353da50438959e3b0n/a SilentBuilder
2022-01-18458657466682.xlsxls 14e06e9395a20e63635c321d4e8f23e03da439bfd81766dab0a621ec1c4627aen/a SilentBuilder
2022-01-1802452576418229532.xlsxls 909cae6e044629c7d0356bc96ced029549d3a1572031da350ee6b96489664f31n/a SilentBuilder
2022-01-1804870549743167.xlsxls 7c92ba7d9752e651b0bf808e5bddbc3f107ccf9ef6ee0c272339621eb8908e04n/a Heodo
2022-01-18562674352771671326.xlsxls e07cb07d8a2b296d0f506a805e5721233820e0f8d4c9d552940f71fca7be7a8cn/a SilentBuilder
2022-01-1810894723426221816.xlsxls e64f53d96cf4624502733103a45f67cc0635e35e624610cbec57ea9844d43203n/a Heodo
2022-01-1848507330256.xlsxls 9b0a59dcae7eca85fa1088f429b85a4a491f79207a68cb7cb8925ef9d95f8ba4n/a SilentBuilder
2022-01-18307837227821948.xlsxls cce8350caeca1753a8904e4cbaaf763ceb8eac0445b3235b74a9635727d39118n/a SilentBuilder
2022-01-1869402499067392176.xlsxls 027a72970eec77e5214269c8f79a87f5f614a1ecee11257b3feac2fbf54740f2n/a SilentBuilder
2022-01-1813214571951930033205.xlsxls 92bf6d722708e0e9428275c7d0789a52e3fefca383f020e0b8a9cf32e01fb954Virustotal results 16.95%Heodo
2022-01-182806274208.xlsxls 853bf53e1de361a8c42c16b3a74dd673f990ca41f7f540ab98004a9a39e60725n/a SilentBuilder
2022-01-184036314944.xlsxls 321d80f76297387803acdb4fd4e6a4dc6073d515955445752390767e95884b67n/a SilentBuilder
2022-01-1893260740850135.xlsxls b933c6fc1ce4b9df0d65fae6724a3053c183cbdf921053873252181bf50ed7a0n/aSilentBuilder
2022-01-1828622907315687434494.xlsxls 6d894e2cd1eaad5f13a55f94de79b6dc01a1f37c48b884d488e46003c054eb8bn/a Heodo
2022-01-178027880911789617764.xlsxls 6c42a94654de5ebe226d285c0ad13e26b01ba97ec5f8faf8e2fb9411a2fc1380n/a Heodo
2022-01-1710034376824580456.xlsxls 5edfa18d54052256d62cd14523eee828be94dbd74b83296ece55b13122e94c56Virustotal results 13.56%SilentBuilder
2022-01-17197560469368011.xlsxls 6c45d08768b929c1e9e51c06e8e11e0f679c9a66a33415a427417ee1a3391ee0n/a Heodo
2022-01-178520141689701088251.xlsxls 24c794c4bff6d31e618de4a6fab59f41d7f55dc7cfaaf520728bdaa54cd4c0d3n/a SilentBuilder
2022-01-179751625308801263509.xlsxls 63ca712aa3ded137254262b9946785369c094b3e58b186e4ddaf34ba8b5d9e85n/aHeodo
2022-01-1720309532227797.xlsxls f6c6e2de6c48ffc623320a3b19ef24f8dc009d55b9d388b58847ef5008962cc3Virustotal results 16.67%SilentBuilder
2022-01-17rt_493997897.xlsxls e492f31ca20d99888b2434dcb4d9af1f93ed4c485b9bd2bc550ce8ae8021b9cdn/a SilentBuilder
2022-01-17VM_1847.xlsxls d786500c90a058e4f9fb3611f21c3c3854c9dd23c9a6925a21bcfd850cb8aa1cVirustotal results 20.34%Heodo
2022-01-17714TRCT-0735540.xlsxls 7ab8fdb32c73c5d578dfa7eb5fb86a309ba5aa7d830e43f7f3acbadc23eec71an/aHeodo
2022-01-1764-176079.xlsxls 1dd853714ff0b37fb99d633c608c2c58ca7ad897a8c728308da056706962298bVirustotal results 22.03% SilentBuilder
2022-01-1714233875NKZHPKF-7135.xlsxls abc4e0519d48cbf6a484cf91eb17ed6f206f0a84f0bc9cb7fe3567f0cbe004a4n/a SilentBuilder
2022-01-176972530612468.xlsxls ab5d55fb39f73d1da2f46b54b81c0f720e5c6585ac2f41d074ed77434fbf65e4Virustotal results 20.34%SilentBuilder