URLhaus Database

You are currently viewing the URLhaus database entry for http://www.dienlanhducthang.com/wp-admin/FILE/7dteuv0x-674726-4014996673-qeg54-fanf5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:266275
URL: http://www.dienlanhducthang.com/wp-admin/FILE/7dteuv0x-674726-4014996673-qeg54-fanf5/
URL Status:Offline
Host: www.dienlanhducthang.com
Date added:2019-12-10 17:57:08 UTC
Last online:2019-12-20 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-10 17:58:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:9 days, 14 hours, 11 minutes Bad (down since 2019-12-20 08:09:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-1293144108.docdoc e4ee3410ab7fc7a374ee9ebac3303c290ca46c432fde4e126d7a6bcfdd542f00Virustotal results 29.31% Heodo
2019-12-12IVL_120119_SEN_121219.docdoc 4c9f0afb404a5a1f1993f0bfe04951a984006161b56f7f5b429efca34118fe45Virustotal results 32.79% 
2019-12-12REP_50800861.docdoc 39fcdb6d9bfe5a2852d82896003591334b0dede609512340e876f275b4ff36ceVirustotal results 29.51% 
2019-12-12EPV_2I36BON1TLTBC.docdoc de6662c946d502bee251e2dabcd64f8c31f8a8f31898c3cce8cc80b78a138781Virustotal results 31.67% Heodo
2019-12-1227125754822792087688.docdoc 281353f5be1adab4b3bd5be93b4397edae5d9fc5a5595fa72dbf0d7967606d61Virustotal results 31.67% 
2019-12-12PO_ 12122019EX.docdoc 334e163e327ab933368bc0b747b32027adcceb1e2b6682b63311beba0b84036fVirustotal results 29.82% Heodo
2019-12-1241747560.docdoc cd9fafbae1765254701fe1ed8e741e933871c9982e881a17fca79bd8c40d8dcen/a 
2019-12-12T_PO_ 12122019EX.docdoc 7880cc42f78ce37e1603207a15bb0471e309eb5fedc7fa51abbefd09e357efcbVirustotal results 28.81% Heodo
2019-12-12REP_PO_ 12122019EX.docdoc 95a491fbae44170a02879e30177ea1a86fa8ed3fd454626c5b7f37204c3899a2Virustotal results 44.26% Heodo
2019-12-12R_PO_ 12122019EX.docdoc 4721a8055b657c23bd15975b8e48f48b896edb566b8ea44c7709df8967972522Virustotal results 41.94% Heodo
2019-12-12PO_ 12122019EX.docdoc 2fd85fa52671982c08cca426e4e3b61cd0362ee96fe2392b490243a86240ed78Virustotal results 45.00% Heodo
2019-12-1218736424.docdoc e29205e0a46f1fb69ba6e6c0ed8dbb12b195e7185583aea4e3eb76c88d441907Virustotal results 44.26% Heodo
2019-12-12YX0864076097PO.docdoc e0fd2fdc26869f285127622c05a135f251e83e589e2567e1aea88c55c4bb2723Virustotal results 42.62% Heodo
2019-12-11DOC_T7E38B1M6ZV5BBI.docdoc ba8a46dbbb037ccf3e0a61a8586f83dab16705872f382c5535d25789f4bfa0cdVirustotal results 42.62% Heodo
2019-12-11FILE_384657754041108.docdoc cbf131d113c303b32821907ab8e7196a8ee0c611f1d115ed5c1bc7e28df2ec12Virustotal results 42.37% Heodo
2019-12-11REP_REK_120119_YFH_121119.docdoc cedec09a05fcc90ba1bf5b84f0a2b0ea2f384029fb3d280a67442d359d3885efVirustotal results 38.71% Heodo
2019-12-11DOC_88419221.docdoc 9ffcb9df40f3dca973c3d2a9bf9fd23c595805dec86de8780ac115e6c09acef3Virustotal results 39.34% Heodo
2019-12-11JK_RT2051539885SM.docdoc ce74e6d5c2375c3da3081f688225762fc61ce5f3181d4cfc2b517ac4d991bfc8Virustotal results 39.34% 
2019-12-11REP_9428460247581611.docdoc ce9418b561864d7c255df7ad7d281a844d33343319a65aa4adc964b27c66cffbVirustotal results 33.87% 
2019-12-11REP_KPR_120119_ZFB_121119.docdoc e8afde57d7b0d7794e655f8002bc35b63017493094d9288cf228f54efffff092Virustotal results 30.00% Heodo
2019-12-11FILE_PO_ 12112019EX.docdoc 548224a38744ef108aa9d7a4d35d0f2df4a19cd8553530e0899bbe1e03eb09ccVirustotal results 29.51% 
2019-12-11FILE_24652161.docdoc 2e0838a8b30aefbe23c45954f5bc35d663e7be2ca00f246b6bf735a6d5efde21Virustotal results 25.00% Heodo
2019-12-11PO_ 12112019EX.docdoc 90348b4d3ac94dbc837178f28d608e0d5f841267ac43e98cfa355e8973c34896Virustotal results 49.18% Heodo
2019-12-11JFZ_120119_FBS_121119.docdoc f5611c378395ec709c8d53b044b5e5c7eb33eb9ee2c49363330618c368666532Virustotal results 46.77% 
2019-12-11DOC_WJ8587369929JA.docdoc 1a15dbb9573d4715318740a3d2a70ae5fd0d3ed5d3f349dd68ff15fc8f65d3f2Virustotal results 44.26% Heodo
2019-12-11REP_Z2UDVCB.docdoc 7dc82afc58fb81a256c24db77f61c5f95de8a9792502edc42fc84692572fcd97Virustotal results 40.00% Heodo
2019-12-11FILE_NYO_120119_STP_121119.docdoc 2f7dd66e97d56ae195b4ac8aa493d3730a49448ff27e92083687f4724f0493daVirustotal results 31.15% 
2019-12-11PM6697929401NL.docdoc d6243cd4386a6e018b061500ad3427b907875fe62b1277ca8f18e53c476ff57fVirustotal results 30.65% 
2019-12-11DOC_PO_ 12112019EX.docdoc 0468e10d3362f39cffe43fc460b6ed586f21bb27e3b267be268dff2811b96c3cVirustotal results 30.00% Heodo
2019-12-10DOC_J9RJI3GK0F.docdoc 95ea8af7b6daa10fb5d0b502c3ef0b00ebabe9dc3ea809fe677b9bead870b93cVirustotal results 30.00% 
2019-12-10FILE_TJ2753583686ED.docdoc 3c64c668b208cb182b2e97c2cb41404bb3502d512778b245cacc3cc2d9c62bedVirustotal results 29.51% Heodo
2019-12-10819446273865947224388107.docdoc 44fbf4ea9f5e37e0eb42081211baf00263af7403ebb3691ba77e977bc488da4cVirustotal results 26.23% Heodo
2019-12-1075223364.docdoc d2a37b2f1107177ff1ab49768e740e747144aedac86323f227b880201ba486c1Virustotal results 31.15% Heodo
2019-12-10PO_ 12102019EX.docdoc ad99c5c6a1b25fb1aa7e3803d11623a74abb080990d3dfe1e684397b77b019afn/a Heodo