URLhaus Database

You are currently viewing the URLhaus database entry for http://vics.com.sg/aspnet_client/rzQm2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271389
URL: http://vics.com.sg/aspnet_client/rzQm2/
URL Status:Offline
Host: vics.com.sg
Date added:2019-12-18 07:04:03 UTC
Last online:2019-12-20 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 07:06:02 UTC to abuse{at}netdeploy[dot]com)
Takedown time:2 days, 1 hours, 2 minutes Poor (down since 2019-12-20 08:08:11 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20Bonus Payment Notification 05513.docdoc e8f4adbc33575dfdc6cc8046ec0478baee34237bda285c3e9fd4798aea4ea516Virustotal results 37.10% 
2019-12-19Pay k2462.docdoc 552af77ac95ce5628c16674c8a6498237f0c021ab47e565d94a129d30f22a397Virustotal results 29.51% Heodo
2019-12-19Bonus Payment Notification pFtd22563.docdoc 4b8f4e9e0e6a9ca5c821a4bc491193f24e255786a729d0a432a1ff564cb31923Virustotal results 29.51% 
2019-12-19Pay Payment dX0289.docdoc c164e422f15dce9bf73d9cae6925b5b7e28b7744189775bef9388a53fdc9c922Virustotal results 31.15% Heodo
2019-12-19Bonus Payment XT15728.docdoc c6b730a2a9e6484798ff301e377a0f5b5f11c6cb7c97be74845f05d9670f2dc9Virustotal results 26.23% 
2019-12-19Bonus Payment Notification riU99801.docdoc a52244e08c3b5c7804925e7ef04fb6193de190e0a972180939b7474c87b4355bVirustotal results 22.03% 
2019-12-19Bonus Sx944.docdoc 50502b1309e5510dc666c2dd81f978bacd097de74ad3839f00cf37bd162c193aVirustotal results 27.42% Heodo
2019-12-19Bonus Payment Notification 5731.docdoc eda653bc515936929de4699eab9f41c6f05e20f40daca6b35ba2a1c944745128Virustotal results 24.59% Heodo
2019-12-19Bonus Payment Notification pr326.docdoc cb885c05015cd9140df726050558ffd1275a7ec633a150bfa1cb49578e38c7b2Virustotal results 23.33% Heodo
2019-12-19Bonus uIz579765.docdoc 88309ab37467ce0976cfdeb37745b3b77e8cabdcd8a1ed1c452aa5521305b309Virustotal results 22.95% Heodo
2019-12-19Bonus Payment Notification 0242.docdoc 3eb0112fc7e50ef79bb7fc39261e350df130c51367da37f237c695b8dfd8514fVirustotal results 21.31% 
2019-12-19Bonus Payment Notification QK78128.docdoc e2f57934623f8177bce5dd944c918d436c13455b33473a6cc6bccae0442d3f37Virustotal results 21.31% 
2019-12-19Pay Payment Mc675002.docdoc 826145f8cd7d41889db4b1423dabac9725d7b7f665aac33dce2b1252cf1e6b43Virustotal results 27.42% 
2019-12-19Notify bF9058.docdoc dd6dbaf92436fd1b561163bb8bb78009936919cca557cdbdfb424a612487152bVirustotal results 27.87% 
2019-12-19Bonus Payment bs490367.docdoc a965ee113d84d529161ae5caa65579875f22fb18d3c196ff01c9b669e1e8adb8Virustotal results 27.87% 
2019-12-19Pay Y34.docdoc 6498abf932114928969209348226cedbd4c37937d65785064fd2e7f7e8d50e3fVirustotal results 22.58% 
2019-12-19Pay Payment OQA64975032.docdoc 4b69f6b3d9d0867579eb36dc0a44f084d94dc5653e9cbcdefcccea7ac7b84fccVirustotal results 26.23% 
2019-12-18Notify sT943067034.docdoc 4c5beeb1a2c9a08fc1d911bd78f887736d8af7f5d31a141d7ac3365dcddd54b5Virustotal results 25.81% Heodo
2019-12-18Bonus DcI39799411.docdoc 3bc3b07397a83978204b1f9cab8d76a3cfd2efdaa9eafba646099673cc115a13Virustotal results 26.23% Heodo
2019-12-18Bonus Payment Notification Xvo24497.docdoc 96379d96a2a9d327a545304b327690e99c5cf4b8708aa4376f485fa3f31dfa94Virustotal results 25.81% Heodo
2019-12-18Bonus Payment 2683.docdoc b3aecbc2cd52771e0954aaf0577098595ccf7d26a040a0186640e57f2f01ec2cVirustotal results 26.23% Heodo
2019-12-18Bonus Payment Notification rBA4244344.docdoc 53c6adc08ab2cd6d9703940211b6c6d1279755ebf27dc07d8311902605ba0180Virustotal results 22.58% Heodo
2019-12-18Bonus Payment Notification g016566058.docdoc 099d9114cf9b28c2283d5da4550cec51027a271f0773a2af0f45e9249ee2da81Virustotal results 26.67% Heodo
2019-12-18Bonus Payment Notification 24824.docdoc 716555dcacd0562368dce844f1d0b232cc3d222377fce2aa41cbd06e525f5a82n/a Heodo
2019-12-18Bonus Payment Notification S1818596.docdoc caea052571014ae79ddc7d8720243f57a53070161022adb754181f233d3756adVirustotal results 24.19% Heodo
2019-12-18Pay Dpq20242804.docdoc 564639aa681348e52501263c2b75e32d6374e4f45b01b2fe9f51d66a7c1f130aVirustotal results 21.31% Heodo
2019-12-18Bonus UUP878.docdoc 355d34cbd29e60fca01229b21c03e66d89144c9feacfcd7777ef15f136272339n/a Heodo
2019-12-18Bonus Payment 5081151.docdoc 7ecd418f499c379ce5e26a430ee6b3c012aba02686a78c7bb652336666fa8873Virustotal results 45.00% Heodo