URLhaus Database

You are currently viewing the URLhaus database entry for http://anhungled.vn/cgi-bin/invoice/3s-645624579-66344-pcn8ee9-fvgy7wtpx7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288451
URL: http://anhungled.vn/cgi-bin/invoice/3s-645624579-66344-pcn8ee9-fvgy7wtpx7/
URL Status:Offline
Host: anhungled.vn
Date added:2020-01-14 19:10:06 UTC
Threat:Malware download Malware download
Google Safe Browsing:Clean
Spamhaus DBL :Not listed
SURBL :Not listed
Quad9 :Not blocked
AdGuard :Not blocked
Reporter:@spamhaus
Abuse complaint sent (?): Yes (2020-01-14 19:12:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:5 days, 18 hours, 58 minutes Bad (down since 2020-01-20 14:10:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTSignature
2020-01-16FILE_PO_01162020EX.docdoc 08b9c1eb2eb20d4f3a806b25f841be93dcc64b923a65a5ebd0c3c7c0f3329e4cVirustotal results 32.79%Heodo
2020-01-161850842069695.docdoc e314c8b472db81404961016b49758c54595600e83fa2801d5cba0089cb8b2223Virustotal results 32.79%Heodo
2020-01-16PO_01162020EX.docdoc 67e4ad463f707098e9dd3aa9ef44543687de41237cb6bd15500e428aa17c34c7Virustotal results 31.15%Heodo
2020-01-16LK3893224624PV.docdoc d2ce1838da599f490397183272a746696999155f408cdd5da5d82c3ae1df24faVirustotal results 29.51%Heodo
2020-01-16DOC_PO_01162020EX.docdoc 3c99ebde95d760948c4ff5db925c0272ec89b8409d698aab26e5785a42c88243Virustotal results 26.83%
2020-01-16RP_2WB22R5U14HBX063.docdoc 9aa8f08a047314cbf2c0a541131a486282da8e2657c69fd731624e2823ada6c2Virustotal results 27.87%Heodo
2020-01-16QR_WHZ_010120_NLE_011620.docdoc 95c0c04d9077e6700cdae6bd1f365a488cacb9ad029a7db67bcc29e9992331e7Virustotal results 26.23%Heodo
2020-01-16SW_PO_01162020EX.docdoc 743632f16eaf4dffd8109a5ea7c14e341db9af20a96f44838a046b9c6b183fdcVirustotal results 25.86%Heodo
2020-01-16PAY_UV9232901043DV.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42%Heodo
2020-01-16RP_PO_01162020EX.docdoc 9b114f67484468604da8e6d028500f9e0fb32be159dc5dba550cd295be425b1eVirustotal results 24.59%Heodo
2020-01-16PO_01162020EX.docdoc 0524eb39455f37b42182c06c755ef5bd2f83f28b3878fb53d663aba6a6a9f780Virustotal results 22.95%
2020-01-16RP_PO_01162020EX.docdoc 8cf507a5d6fd40526c9419ace90c17b9d91a6949229cd0f5c8afa750836dcf62Virustotal results 24.14%Heodo
2020-01-16WT6135838180GW.docdoc 771ad3b2889d51eae42be0c3c53f7ab24667105d94fcd6e6dc93bca8ebbfcd85Virustotal results 44.26%Heodo
2020-01-16RP_PO_01162020EX.docdoc bc1ee7ea69d36c03a940c29cfce159c7e7225fbe58610eb697e091e0b242c08cVirustotal results 41.94%Heodo
2020-01-16EM0129230796LR.docdoc 54572874c5ba5d58e3c48380738c9001b672b0536489e2c9beeec54acdfb59a6Virustotal results 39.66%Heodo
2020-01-16REP_PO_01162020EX.docdoc 70ee982c6329ff7d11fa89375a100f4d2845d56be48ae8e61afe703324fd9950Virustotal results 40.32%
2020-01-16SW_G66IOZJ.docdoc 01d706d0a5e27c62abe9a72200925c5e23ed3c309ea88354dfcb55b36437c3eaVirustotal results 40.98%Heodo
2020-01-1538309157.docdoc e763d67d538e1928f4e54ed83171e2b9495156d4c51598d1ef77162faecac2d8Virustotal results 40.98%Heodo
2020-01-15F_23734086.docdoc c1c7fc8ee76da4f1696fa2d918472cacd777e5fe281acbaec5d12a85d98fcab5Virustotal results 33.87%Heodo
2020-01-15PAY_BL8595812244RO.docdoc 5cef7f012587358911420986b0a10b3afc376e71cbcb62ae2369409a2949e714Virustotal results 34.43%Heodo
2020-01-15DOC_RRA_010120_FOX_011520.docdoc 746e56dfeb31eb76ca54c4260082c53e799a6cb532561b12c98ee1496f3055f4Virustotal results 32.79%Heodo
2020-01-1585922458.docdoc d497afabc9f95e52de2b44e62a03de53764ad772a44b5435500de43e92434a9fVirustotal results 32.20%Heodo
2020-01-15E_PPC_010120_OCL_011520.docdoc 003119d202e9e45b9c325e5d4d6ff289eb61595a77b2dded10f5e041b66cf088Virustotal results 22.95%Heodo
2020-01-15PAY_RP7156401400LP.docdoc ae23c3284230d31527a8b2f8a4721cfa9d31535c93604fcd9be10894eeffc01bVirustotal results 18.33%Heodo
2020-01-15REP_UTA_010120_BEX_011520.docdoc 9982b18660c6aa9b8419bd84843d2d578fd2afb2516782ac69f0e7f8eee4efb9Virustotal results 18.33%
2020-01-15INV_KTD_010120_VWT_011520.docdoc 5ce93c3671dfbeae75d738d2ffd0204b72b6628c8aea98ccda37891eb1414614Virustotal results 18.03%Heodo
2020-01-15PAY_PO_01152020EX.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10%Heodo
2020-01-15VXX_BZ5847899681XT.docdoc 632e28a523c920e3035782ad086e6d3f0e39445486e86e7ce6a05c0e4f337292Virustotal results 31.03%Heodo
2020-01-15760280534917655.docdoc 17cbb232fc64e8c775b7ed47a28ec7a2cfaf6cca790994fad3c41fb60a648062Virustotal results 33.90%Heodo
2020-01-15SW_RGNM17GP8RTVPR0.docdoc 958b22bd337775f2226fecdcadf9125b8bbcad2518c23d026fd87b0714af1b63Virustotal results 31.67%
2020-01-15PO_01152020EX.docdoc 556f0f62580588094bb0d595bdbb880b58a48148af61569258c9a84653374cbbVirustotal results 30.65%Heodo
2020-01-14INV_5424792646.docdoc bbf79cb4aa35f097ee65fbf27c2808626e53c4460eeec58c2a828aa669b50b74Virustotal results 26.23%Heodo
2020-01-1422QPNDPLQXX1GN.docdoc 6ea68ce4d24f0f499b02dc10acfa5ba8a428ce1eef46e6423899ce4be5f31b4cVirustotal results 20.34%Heodo
2020-01-14ST_00340712.docdoc e3cd5ab045097c55bcb00a1cdc84e11c8d7214e15f536baffd899dfb8e0a3149Virustotal results 17.74%Heodo
2020-01-14REP_PQ5701386641XJ.docdoc e52fdf167dc53bfc66eaf13ebd5672aa0c302ad36b48a0581240dd9cc713fa77Virustotal results 18.64%Heodo