URLhaus Database

You are currently viewing the URLhaus database entry for http://fivace.com.vn/nk6tx/jnigOnPTq3RVgyOyhY1opL0yk/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993027
URL: http://fivace.com.vn/nk6tx/jnigOnPTq3RVgyOyhY1opL0yk/?i=1
URL Status:Offline
Host: fivace.com.vn
Date added:2022-01-20 15:47:11 UTC
Last online:2022-01-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 15:48:44 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 hours, 27 minutes Good (down since 2022-01-20 19:16:32 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20957816281175590.xlsxls 4e012706695112b7e19ba7cb073f14b4858bbe382890106a21cadf220bcd050fVirustotal results 27.12%Heodo
2022-01-200663116841.xlsxls 40dd74fb1fba55980387dff7f457cfee8778be09fd503bc397f747bd97d82ffcVirustotal results 43.33%Heodo
2022-01-2083177505028181.xlsxls 3d702c221263341fa14edf51b4d239cc665e2db56c4d1a7c5dbaa80065f182ecn/aHeodo
2022-01-20361916152719.xlsxls d507a6a85d0f208c8662e6cde4d1bd419daefd9b5644146e4a51546fa37131abVirustotal results 24.14% Heodo
2022-01-2056369865218401090.xlsxls ca1baf60faa9486403587e0fac3c548db3aa5b6fb42897e1569020682499e319Virustotal results 25.42%SilentBuilder
2022-01-207694453789736144.xlsxls d16d836fa1d7bcd99b7a2b65ca2d4deb2a54b552ecac9141c735e793c23a2a3fn/a Heodo
2022-01-206586753633189.xlsxls da69822f904bfa19d91103dea07f20d35d09cf37a2c76f4d45317d26728de3edVirustotal results 28.81% Heodo
2022-01-20544875285061.xlsxls 61edf37e9c8e80e6ef365ddc3e366b079e027dc74c22230adc8dc709f293600bn/a Heodo
2022-01-209776397966888389996.xlsxls b7c12da037688c432bf94d80c88811b29b1a4d379a84ff3d6e6ac95eecf15680Virustotal results 25.86%Heodo
2022-01-20404641213952953.xlsxls b3973d991b4f3e3870404c40bf59257bd40f4207f10dd5a6c34a8d4e29e0f7eaVirustotal results 24.14%SilentBuilder
2022-01-20267066552751808.xlsxls 4b90a0d2855800baf3485d8e0c38ec0e5aea83050ceeb38061af07eca0d16febVirustotal results 34.48%Heodo
2022-01-20886272292599.xlsxls f8df5c1460204b9a00c575ec537837a007f7e09f3c16b2525e119476eb8f9316n/a Heodo
2022-01-207053478993487.xlsxls e7fa5a535aaa83921ba3f69b0965a6a20697916ec4e0896c29a684ef1f5850ebn/a Heodo
2022-01-201322554592713372239.xlsxls b9528394574eccc85daaac7ef8f647b72b48d2e0a13fd681e3727291a2c2885bn/a Heodo