URLhaus Database

You are currently viewing the URLhaus database entry for https://dacsandongthapmuoi.vn/system/cron/HwOtNCFo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2403292
URL: https://dacsandongthapmuoi.vn/system/cron/HwOtNCFo/
URL Status:Offline
Host: dacsandongthapmuoi.vn
Date added:2022-11-07 13:32:47 UTC
Last online:2024-05-03 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-07 15:34:10 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 year, 6 month, 2 days, 16 hours, 40 minutes Bad (down since 2024-05-03 08:14:30 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-09Q2DE5Sm.dlldll 77e8629423878a042c368984a1c567194b97b05bbd240f6be6fd0c4366f82b3bn/aHeodo
2022-11-08upXFqlsLqNfwN1c8.dlldll 7a692c077ef01a9a265af446eaef8a447478b3bdbedbafecedbb392e0bffbfdbn/a Heodo
2022-11-0889fsII.dlldll 48658aaceb2209ff369b66ab48ac1d3f207cb6d3179e3985ea8717ad5354843an/a Heodo
2022-11-08rEsPtxFjbTTLe8heb.dlldll 9089734b48d5ba744896cb85224c572f9033b16456928d3d9d339e86b763cc72Virustotal results 14.49%Heodo
2022-11-08Lav2uYVOMmiERN.dlldll c046b235b38836e5d9547ba6fe9098d9e095c1c8547e30ec7457a39d20381cddn/a Heodo
2022-11-08vO2SZgdVU3mWXBU2.dlldll 925e2631758fe1c51c2e222aca7eee60f0b36b6d836d60441d2ab77e1e1f12aan/a Heodo
2022-11-078OmskQ1fz.dlldll 75b0f156eb9cdc8f3372a4dbcb1d7a3171f50d8f7e7bfb94bb17fdd0c5099b13n/a Heodo
2022-11-07sVLZIIAugh985zsj.dlldll 523650df65cc1a893cac1b865aead63720f4c408eb4b19a8e53b7699e40d2624n/a Heodo
2022-11-07s77fvMnWtgWOekyt.dlldll 96132a47f35902bf3bee1848b0f42daf2fd6dbb68e01bfaffcdf05b78df8e33an/a Heodo
2022-11-079zq6WsAitZYaf.dlldll 277dbb407fc5c0f28172960e808ad2540315a26e18df0b10712c9d31bfac1f74n/a Heodo
2022-11-07QXo875j99ppQ8Z5LFF.dlldll 181b0576c7e8db60646a8c4c497b78e89b6caa336802de54339a4ade36f419cdVirustotal results 14.29% Heodo
2022-11-07oF2bu2wkujjnUgz.dlldll ca2de2b5e835d54e33c20b06ff6d959b9b4f72d4d56de9100707c603b7ac5b46n/a Heodo
2022-11-07n5kIH5H1fXHS6Mu.dlldll cec8fc26b08e21eb83f4a3d77a4a87614fe6ed3a55467f9ffda721e8f9acae52n/a Heodo