🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for https://www.dunlopillo.com.vn/wp-content/plugins/advanced-custom-fields-pro/vzs-sh2o-413/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:266812
URL: https://www.dunlopillo.com.vn/wp-content/plugins/advanced-custom-fields-pro/vzs-sh2o-413/
URL Status:Offline
Host: www.dunlopillo.com.vn
Date added:2019-12-11 08:14:10 UTC
Last online:2019-12-12 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-11 08:16:06 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:21 hours, 2 minutes Good (down since 2019-12-12 05:18:59 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-12INVOICE_AMS03_3486.docdoc c765ecf47cc4ba7c01f89d2a7349570cd9ffe689498c807227fadcc78f291da2Virustotal results 40.98% Heodo
2019-12-12Invoice-DNK881_52584.docdoc af3725be37619634485bd50516b39b02161c673df78d26c346b95f490e6266a7n/a 
2019-12-12Invoice C130_9565.docdoc 699dfaa6f502bc577250c8307983c757cec5bc1a0f672621e92cb60b1a07ef02n/a 
2019-12-11Invoice-Y74_943.docdoc eccd29d2064d11af26b58ed3ae7824a0ddb2c2ab4c86c3ab1f030dd94cabbdc4Virustotal results 40.00% 
2019-12-11invoice B86_95268.docdoc 0b9c7c15749d62bdcdd31e0bf15550a714cc57d67f126a065077a7566cd5a36dn/a Heodo
2019-12-11invoice_GVG33_50777.docdoc d9b513c8517f073760bdb577d2e9051c91c709852d48961117d5dffe7976ca36Virustotal results 45.90% Heodo
2019-12-11Invoice-GDC186_2295.docdoc ca69295f8e6ad8320cf5570698d81e892554fc621cb18bac3e837b9323314bdfVirustotal results 40.98% Heodo
2019-12-11Invoice-M18_4992.docdoc 1921b22728517cbad3fed6c147b88f13f808ca146fd6e880312cde2285e5eb87Virustotal results 40.98% Heodo
2019-12-11INVOICE-SE041_87.docdoc fd39f0c4feca6bbc2bc72df5b1abf1266ea1a7bfd76caa5d1803e00096c19018n/a Heodo
2019-12-11invoice H549_04.docdoc e1f315e16cea5360492223af2d3b47da3f3b3d250882552371d5578b0f319ba0Virustotal results 29.03% Heodo
2019-12-11invoice Z29_7332.docdoc a35159c00b94c5350d0e7d35fcdab2c15ede89d612654c740942f68bcd8b9c87n/a Heodo
2019-12-11Inv_SIK292_49666.docdoc ed4a6f0b261f09d7b89c7adf9623e1c541ccddf5baf40ad35681f1e8e6c06dc4n/a 
2019-12-11Inv KO440_0672.docdoc bb07690a0393693c7abd6f2e60ad61e01c86484f597a1f6aec72b27b55c01d47n/a Heodo