URLhaus Database

You are currently viewing the URLhaus database entry for http://nguyenquocltd.com/wp-content/closed_resource/security_profile/4zskjhw_v3yz0ts586s9us/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:270903
URL: http://nguyenquocltd.com/wp-content/closed_resource/security_profile/4zskjhw_v3yz0ts586s9us/
URL Status:Offline
Host: nguyenquocltd.com
Date added:2019-12-17 18:03:12 UTC
Last online:2019-12-27 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-17 18:04:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:9 days, 15 hours, 13 minutes Bad (down since 2019-12-27 09:17:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-19Christmas_Congratulation_Card.docdoc 02d28a0e8f94dea2e7eee7d7d292af1489c3bdc23fa23e02cb6f9b32ebb3698bVirustotal results 24.59% Heodo
2019-12-19ChristmasCard.docdoc 05d6a9aee095f8567bf1afed98b7e64505bb0bf9dc87c61644f32c8f63bc26f1Virustotal results 24.59% Heodo
2019-12-19Christmas_wishes.docdoc e4a6b6d906f970b2963c433b1cf85895a9c9f060eedc982f011c3199b7c9df7dVirustotal results 24.59% Heodo
2019-12-19copy 12192019.docdoc 2c122baed94846843fce1113133b49bd5bb711328ba94ff02f397031fe9b6393Virustotal results 22.95% 
2019-12-190k530rr2u4p5qk7.docdoc 9f8ebcb75801c7ae8d18f034893759901eccdd2e3e18c83b038edcd4df072f8bVirustotal results 21.31% Heodo
2019-12-19PART_12_19_2019_9162083.docdoc 61fe55be0a1c2a52426f90abfa9778eef565c849a24ae59e31c6c8ba403462e8Virustotal results 21.67% Heodo
2019-12-1912192019.docdoc 6a876e7d6136471f30899b8264a1c1ba02bdcbc3213d35d8eebeee9f4d210805Virustotal results 21.67% Heodo
2019-12-1912_19_2019 A47558109.docdoc f958e5ef1f89a03267c2d99256d791d61ee8cb151111e21b2686ebee09292dcdVirustotal results 24.59% Heodo
2019-12-19info-12_19_2019 GAG53781.docdoc 3cb1650cac5770870949aeb67823e4c9f1b8bebc56fdec50beff5eac826f98feVirustotal results 21.67% 
2019-12-19k0rks8ut.docdoc 746485abf564bd23adc65a36749ea9b54368e444a0e6b5167fae083fdb180f2eVirustotal results 22.58% Heodo
2019-12-19W4516887 315194.docdoc c15e005ca7af90c7fddc7fe79b646e5b520fa94946e4f62f4ace5de94b37887aVirustotal results 22.03% 
2019-12-19list_12_19_2019-299636832.docdoc 8a375c796318cfaf7c7ac3c524f9c401ded50195b94059176d97992ec3832da2Virustotal results 21.31% 
2019-12-19UNTITLED-TCY95876403-5703838.docdoc d9c0dd65766e2d2c84672023f2b4e3103ca5d7a686bc06c84488092de91ff1e3Virustotal results 30.65% Heodo
2019-12-19Doc_XJ1154347902.docdoc cf65b38b2650623e1361a482d1e8e8781019d7a29cb757cf79c1e276583838a8Virustotal results 30.65% Heodo
2019-12-19PART_XB6185191-34804861.docdoc 72ce3df7bd7da4208c97989fe0b93c23a8f3c4348ddd24adf59fa6539cd148ebVirustotal results 31.67% Heodo
2019-12-19INFO_EYW83323054393 264258.docdoc 0c45e14f368d59e03d4881e280642933dd8287a088108931f5c4f1425c442300Virustotal results 24.59% Heodo
2019-12-19list_kq47lnoq.docdoc 39c1d85d9122a432fc48e0162b6720734ab8b31d97fad0dcac4d0d6f6517b6a5Virustotal results 24.59% Heodo
2019-12-18doc-12_19_2019-2C65692.docdoc 14431f1c5a3c66befb90b519ffdd0824f1f13e5521823c31a679a5fe6dc58c46Virustotal results 24.14% Heodo
2019-12-18PART-PF06142 101583185530.docdoc b1470fd56dc1adaf558a75b6ed75c32cfb5bd8d78e2280d9ec9df85512d9b7b3Virustotal results 26.23% Heodo
2019-12-18list unrv21ss8.docdoc 3be9f66ef6e3feb291bca66c44fd8651d392ab19807b9bce1a7fad00d4a518a6Virustotal results 25.00% 
2019-12-18UNTITLED_4k0n4m6rn3q.docdoc 6998c2f955541d5a517fd68d96604f2ea2efa83d0d1c0a04fa3d09c629bf3e18Virustotal results 24.59% Heodo
2019-12-18J93703338349.docdoc 5badf79d2041f3f0cc65f49685e0fd05803d25cfc00bcf33a7bd02df10a5ca61Virustotal results 20.97% 
2019-12-18release LCD67898466.docdoc 661c6e38c4c0089068eec2d5b60d67887e4ddd4c374706a0af0544e726b68160Virustotal results 24.19% Heodo
2019-12-18DOC 6qlntuss4ou8q.docdoc 43c08049eabb097bd65da44392027b6626e52a6bd358485346f0517aa921806fVirustotal results 24.19% 
2019-12-1812182019.docdoc 11b0ed5fd91147500dc80ea454121eb3a38bc73a789ff7ab2517eaeaa98adec1Virustotal results 22.58% Heodo
2019-12-18Untitled-WDJ09844.docdoc a5c388ebbee623f26938d67427170bb063976b1dd0524f6ea18b402809afed4cVirustotal results 21.67% Heodo
2019-12-1812182019.docdoc 235a1b8259c33245014cce467f619a2eac184be4c09a020850e4106170388f3eVirustotal results 21.31% Heodo
2019-12-18release_ZQ121337903.docdoc a9b41646ad51dd5bc762a07a0efce3c6f5d6f372281699b1ba4747ad29e74c9fn/a Heodo
2019-12-18doc-12_18_2019_61548861500888.docdoc 561126bfb39ff16fe82c097bf9150a1e4b4f4e5674359c8c07bd900befb3378cVirustotal results 45.16% 
2019-12-18uuvqs9u0.docdoc 96eeaeda0e8075bdc21431cfa17b07d5ebdedcd515b5073c4074b64202419735n/a Heodo
2019-12-18info 6VD251255344.docdoc 992d05921516c9f141fca70dfe31a45a23b8eb4a1ed260bac73a3b5aa4c78638Virustotal results 41.38% Heodo
2019-12-17info 5400.docdoc c5d5567a19f89c15c6f550ae1d8470b6b6d777dd2e8086d4aae4fbc8f63376ceVirustotal results 40.00% 
2019-12-17Untitled_1EI95626369353 74807.docdoc 5eeb8f8625be1a807a4cdbceb5d5bf167158ad4643e679d5b37f4b9abf87eb4cn/a Heodo
2019-12-17SP6289371-2805620.docdoc babd2db09be571cf6283d08571375e65df5560d5af2bc50fe50621284f4b951en/a 
2019-12-17Untitled file 12_17_2019-09B8152007588.docdoc ceae4c14841343d702281180491e9442cbd7d06234492418f059381af8b54d21n/a Heodo
2019-12-17rep_2442.docdoc b7c5359912e1c89f19135f60e2df6d473fa8a3b32c7dde466b65245bf8e20682n/a Heodo
2019-12-17COPY-Z81646993.docdoc 46a66f010f62de62c733a35ca049071db334beb17019ae8532117fc59b1a47ebn/a Heodo