URLhaus Database

You are currently viewing the URLhaus database entry for http://www.atfaexpo.vn/GREETING-ECARDS/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:27125
URL: http://www.atfaexpo.vn/GREETING-ECARDS/
URL Status:Offline
Host: www.atfaexpo.vn
Date added:2018-07-02 21:28:41 UTC
Last online:2018-09-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2018-07-02 21:36:36 UTC to hm-changed{at}vnnic[dot]vn)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-04Greeting-Card-July-4.docdoc 39f2648598fe0b9e05ce79b5a94ec933395c34a1d5a4e1d97037a79f882757f2Virustotal results 27.59% Heodo
2018-07-04wishes-4th-of-July.docdoc c2154d673b5ea62d09f7a2016e754c0a6cd005f98714f2360ae0685939193981Virustotal results 28.07% Heodo
2018-07-04The-fourth-of-July-Card.docdoc 9cacd78df40e6304fcbf7fa9e68b10cfd96f0af6c78665cb9bd9bd70ed9b9999Virustotal results 28.07% Heodo
2018-07-04greeting-card-July-4th.docdoc c1a21385dac4250624c22c71f3f3c19901a9e0117c333df6e74c66b9dfcba718Virustotal results 32.14% Heodo
2018-07-04The-fourth-of-July-Card.docdoc 8eda9d50c691997236e69ce72a59989906472514ad112733c6d2dd53c9f4e7b8n/a Heodo
2018-07-04The-fourth-of-July-eCard.docdoc 7c0f658e183839956a41404a1b2858165e5b2e5d20cd58cdb16b638bc7221fdfVirustotal results 29.82% Heodo
2018-07-04Greeting-Card-Fourth-of-July.docdoc 1e078cc6c49086e955cd9f60559788254a3c47c9da193df9a239946e71728b42Virustotal results 28.07% Heodo
2018-07-044th-of-July-eCard.docdoc b3c6a641fd966a5ffa0a9fa9241ea45be5c873f2523ca0b281467968a3a78137n/a Heodo
2018-07-04wishes-July-4th.docdoc b0e86f1360c4504e16112806d2c0bb81a3d0efdb965496fc34d85fd38f60e650Virustotal results 29.82% Heodo
2018-07-04wishes-July-4th.docdoc 17a393aa40b9d37c9f3cfa30ddfb12a963b95a18344de1eff7acc30393ef8be0Virustotal results 26.32% Heodo
2018-07-04Congtatulation-The-Fourth-of-July.docdoc fe044cfcaacfe61baba1b0bc028e556c88411c445e1d0a0cb635395e80f05945Virustotal results 27.12% Heodo
2018-07-04Independence-Day-eCard.docdoc 73061544ad772db504bd84ec6c6c00bb0c74ca2dc9e4fdcefc5bce1ea83bc544Virustotal results 21.67% Heodo
2018-07-04Congtatulation-The-Fourth-of-July.docdoc b3c605244df37f6519cb50f80a84f37241af3cceabd313dc51d1c8affa632f49Virustotal results 18.97% Heodo
2018-07-03Greeting-Card-July-4th.docdoc 999dbd2dc2682476713f460ef8231803dc0d0139170def2d962311348705b50aVirustotal results 20.34% Heodo
2018-07-03greeting-card-July-4th.docdoc 2d5cc3863d782799c71182dab1e7a76fefff47cb01237c0b6180c8d153cd06a1Virustotal results 17.54% Heodo
2018-07-03Greeting-Card.docdoc b2f01d51d3180e8142dabb01407b0e8b15c122ee7c552247764afc2ba1173855Virustotal results 15.79% Heodo
2018-07-03Greeting-Card-4th-of-July.docdoc 784002e476b3d2fc184e80317a7859bf27a3fbe225ccadc62cc3c81f83e935c6Virustotal results 22.81% Heodo
2018-07-03The-fourth-of-July-Card.docdoc eac608e5f2711a689b7c7ecc2b18bec0d29dcedb7281f1915cb18613459c488cVirustotal results 21.05% Heodo
2018-07-02The-fourth-of-July-Card.docdoc 2f27663116e9c98f65806d238fad640cee2bf3b182df80495359b36c9bb6aa76Virustotal results 15.25% Heodo
2018-07-02Card-Fourth-July.docdoc 4c371f084b810457d27249d8ad5640864a9e706a1c6fba646d52ccfe94cb52c7Virustotal results 15.25% Heodo