URLhaus Database

You are currently viewing the URLhaus database entry for http://gdcgroup.vn/wp-admin/0ipWMQYggLOD8Waf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2580190
URL: http://gdcgroup.vn/wp-admin/0ipWMQYggLOD8Waf/
URL Status:Offline
Host: gdcgroup.vn
Date added:2023-03-21 22:08:08 UTC
Last online:2023-04-03 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2023-03-21 22:09:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:12 days, 4 hours, 23 minutes Bad (down since 2023-04-03 02:33:08 UTC)
Tags:dll emotet link epoch4 heodo link zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-03-23rmY1YU5e4iNMZt22aot5qXA.zipzip a851f1ef377b9e8090aea7becd698e0bd8172b79889adb2f8fb72d1fb587fc96n/a Heodo
2023-03-23YI4IowHsVwa6kPXy96vu5jtx7kSTG5.zipzip 4b36fc534a0dca5c20f559ba22228183d3b3bb460549a71e425ffb0e778735bdn/a Heodo
2023-03-23WPKViji5KQypCqiQd8ati3mhzcvNtyuM.zipzip e76e8092b2486d3bf98b585972018778bbfdd653d6868b5110dfe40b9309fdf1n/a Heodo
2023-03-23mQ9hB0cWcpW7BkLVyj6PhmE.zipzip 4876af5b884a181998ffe23fbd4dfbff2eefa40f3e8bfe1651115efe2615b449n/a Heodo
2023-03-23JMtMq72MuZ1.zipzip 2ef3845aecc2434d44a8c639bd8688aaf143a53d65b5588a0674c3c915a1dab3n/a 
2023-03-23AxUjTmwG6.zipzip 4727497f6d03a2e2dfaef86683fcd909e9d75c7101176cf15b17724e26a766cbn/a Heodo
2023-03-23HUKYUixUnITjs.zipzip e8be0bf2cdba9852d530b309a7f0e27e89e07afb3fc3b5ac6fcd887fe8ad2c86n/a Heodo
2023-03-239fDEcS3V1eN9MwWQHU3rXx6hsBx.zipzip e6275faa1b9c032cc7d1df4a44ecd9fcdc92751048940c9e79b7b6f84933ddadn/a Heodo
2023-03-237FZ5Zkf3EHjb.zipzip efa4593f7020f569712e8150e73a3b14b3247c5771bb6b11058682ca066bf6b9n/a Heodo
2023-03-23sWJVX7m49rtKkEvXTGc0Mx2F5v.zipzip 8451e6c24f691ca5fbb81587caf3a1a7496560d2c8c1382baa5ac464bd6d02f3n/a Heodo
2023-03-22oc2Mwh4GFK.zipzip 52b701da99e5e228ba72db97e38458ef611d897f5b7519c93a0d0dca64af44e7n/a Heodo
2023-03-22pdziIG2Hh1EpVlfbI1JBvyG.zipzip 7c26e7b171ed1d3831ab2836460ecf633cebd0043f0d495c251d54158844812eVirustotal results 13.33% Heodo
2023-03-22W1MI6iqetTKom.zipzip 8c0aff472bffb948ea236bdc9ae8972c81d9b81a9e9365f62e1c055a6a00f9cbn/a Heodo
2023-03-22XdQh11.zipzip bcd96d332a01819232e8423d5d52431eda112f5d39462b6303a5acbd64a76c12n/a Heodo
2023-03-22D9uUi0sA1wiK7ZdaMHsSemgl8CUXjQ57fp1.zipzip 68e36860b301530ea38441c9c3233b877917f269a05a5424ac40cbbf7c629449n/a Heodo
2023-03-22GxTe4eynmvcGObdgXz9aaJIWuTlf57LoZC.zipzip 6389274eaaa892a33fe09fbf6bc85a08aab3577bbeb48ca0afb66a93eb5f68d7n/a Heodo
2023-03-22aQccqy622vvSmaHfbaUcdpB6pY.zipzip 8bda787264afb5ee3dff44601a336aec4eb788bac8f4f3cb6767f37d75cef57an/a Heodo
2023-03-22hZssnZzMPOdYwGV8R2OFkVdL.zipzip a305ef364383baceee4808260d15784fb7a2a5a787e390138d9266aaa5e0ff23n/a Heodo
2023-03-215fA67jONRQn.zipzip 7c92a1613c16ae9c2d401d18e1b13a58a7c96e85ee48ff3a68250ca2e35f00d1Virustotal results 9.84% Heodo
2023-03-21v4cWttVG4O2zdaOxshOaU6GMG28kgA7ucv.zipzip 9dcf4ee48d9b986ad1c8e55ea10f51c3ce8067ca99daca0ab7d0b37f3106e1b6n/a Heodo