URLhaus Database

You are currently viewing the URLhaus database entry for https://phusonland.vn/wp-content/protected-33552-zHttvYgBpr2KoX/guarded-area/r8vDNZ-bahHLjM966Jwy9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288903
URL: https://phusonland.vn/wp-content/protected-33552-zHttvYgBpr2KoX/guarded-area/r8vDNZ-bahHLjM966Jwy9/
URL Status:Offline
Host: phusonland.vn
Date added:2020-01-15 09:05:40 UTC
Last online:2020-01-18 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-15 09:06:11 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 22 hours, 45 minutes Poor (down since 2020-01-18 07:51:28 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17Untitled 2897.docdoc 81c603712c753de8200c0cb6dd28d6b37ac2873b968bdf8929ca129d35195d4aVirustotal results 18.03% Heodo
2020-01-17Untitled 947707.docdoc e0ad47140e2313f3bfef8babb2fc62ac841aba00c47b310bdbbb53a1e6de73b0Virustotal results 42.62% Heodo
2020-01-176539.docdoc a0f17f80ce80691a533fe067a73e277790233ca5364620f6aa819e0f4e59b5d9Virustotal results 42.62% Heodo
2020-01-174690276718.docdoc 6869e0e17bfecfa73511915e8a93d1a0d31a2cc85fd41c15879dba1825fd0d0fVirustotal results 37.70% Heodo
2020-01-17Attachment 285115581.docdoc de8f84ced2a3a6a85aeb9ff016c38d519a51898a16fb059a6555f9df453c4595Virustotal results 36.21% Heodo
2020-01-1773307277_27487.docdoc 6d32e86fcbbae85b744c8882e200b3e0bc4c568c6c485cf579e77a912d5b2bb1Virustotal results 37.29% Heodo
2020-01-16892-533226008.docdoc d745ac31ffb2ab613d0ff90f9aae6bee492e6d2457e4460ede41711b9de6ab83Virustotal results 37.10% Heodo
2020-01-16587189-6611635622.docdoc 5b5fc12126eed77880537114373507d05bd137495a2a431d504b63de952c5851Virustotal results 36.07% Heodo
2020-01-16Untitled 079227448.docdoc 367beb7944831570410dcff59d7e8b2d5cf1074dd1ca52dee29f0dfc9785bfddVirustotal results 35.59% Heodo
2020-01-16UNTITLED 1075.docdoc c003bfc38b2835bca08341ebb6d0d462f52fb0844f5578aa4de3b987d6a34d36Virustotal results 27.42% Heodo
2020-01-161968408244.docdoc d02b63966a3196f6e35ed9a14209f9f9f718c608fd9b8fc21d190a00c971cb23Virustotal results 24.59% Heodo
2020-01-16Untitled 792-2027045527.docdoc 9d3d46a7f64b4f0e5d294c1d2560f9a51ac2dae6fe734243569e62d7161ae7f0Virustotal results 24.19% Heodo
2020-01-16Untitled 703569537.docdoc 058abfe0e47582efbe8082a02acb54eec587373096ba71b4f00150553e29a7faVirustotal results 24.59% Heodo
2020-01-161374.docdoc 1ea26ae156e50ac1ddc42b7759789c5aa40697112afc006a4eec2131a9057186Virustotal results 22.95% Heodo
2020-01-15Untitled-683088.docdoc 14eb51b1b82b22069010fd1d6b465c79bf9cfdd31c017fdeee6cc410dcf81485Virustotal results 36.07% Heodo
2020-01-15Untitled_file-72100.docdoc 78616833085cfea2eb679516f1d7f7a22c930463f5d32622b2b5f3af4474021bVirustotal results 35.00% Heodo
2020-01-15FILE 506.docdoc dba6e87c2a3ec66dcb501092196f225195379c1eb31cd986c01e0874f633966aVirustotal results 33.87% Heodo
2020-01-15attachments-724.docdoc 35a6c928ace899581d72bbb94aecb90fc54a9ef85b852a12cc77ec1a7fd4a239Virustotal results 32.26% Heodo
2020-01-15Untitled.docdoc 5a444bb7248957c2b190c22b974bb1d24c9d8c6b97f8467c1939c9addefaf35bVirustotal results 38.71% Heodo
2020-01-15UNTITLED.docdoc 6afde0f3c0ad0aa0e34970a9f286f30a542df5dce5da050ca824824e21f82ff9Virustotal results 18.03% Heodo