URLhaus Database

You are currently viewing the URLhaus database entry for http://yoha.com.vn/css/personal-zone/special-Rli8HwKN9x-zhSu9RvG/wcm5nqN-v7Jn9IzIn37e/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:289345
URL: http://yoha.com.vn/css/personal-zone/special-Rli8HwKN9x-zhSu9RvG/wcm5nqN-v7Jn9IzIn37e/
URL Status:Offline
Host: yoha.com.vn
Date added:2020-01-15 19:42:08 UTC
Last online:2020-01-20 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-15 19:44:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:4 days, 17 hours, 40 minutes Bad (down since 2020-01-20 13:24:43 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17Untitled 707-464711598.docdoc 977b6ab643970ff435f76242e374c86412fe11b1f2b1893c3ab2674fedf61c4eVirustotal results 18.33% Heodo
2020-01-172519714319_654.docdoc d4b9eed17971faf2205e41562849762fb6d99a5e132d813998413d5093e76e71Virustotal results 20.00% 
2020-01-17Untitled 284418362_9359.docdoc 5672124ab6dafc9a7755b5f37ba940e698353b6fe166c42b0f10cd862d4a9430n/a Heodo
2020-01-17Untitled 489307.docdoc 9a44f03b0cf7865e2242449c94e2bd9e654e25b424ec07e7104ea84308cd163bVirustotal results 24.59% Heodo
2020-01-17Attachment 3750106.docdoc 86d440f588fbc52744ee8fd2c30e73f615d1f27b75b8351ba1b5cf8689033ffaVirustotal results 19.67% Heodo
2020-01-172623506-62607797.docdoc 2ad0521294bec243c52276586c33c9a742a4cc03f85eba377f60a18df2479f59Virustotal results 19.35% Heodo
2020-01-17320172284_36140.docdoc d58e3a873bc2d79ddd0d9449af813fecebe2fe92098d3e4c8b0197b09159aee0Virustotal results 19.35% Heodo
2020-01-173938346249_963.docdoc 142c2efda50596eb5d5e050338142a7c86a5030a0c4bd1095bb30cbe0f722e1eVirustotal results 40.98% 
2020-01-17Attachment 17623963_6581.docdoc 6869e0e17bfecfa73511915e8a93d1a0d31a2cc85fd41c15879dba1825fd0d0fVirustotal results 37.70% Heodo
2020-01-17Untitled 0078686909_69670.docdoc de8f84ced2a3a6a85aeb9ff016c38d519a51898a16fb059a6555f9df453c4595Virustotal results 36.21% Heodo
2020-01-1741866750.docdoc 6d32e86fcbbae85b744c8882e200b3e0bc4c568c6c485cf579e77a912d5b2bb1Virustotal results 37.29% Heodo
2020-01-16446.docdoc 0bb667859f35e9606b929fc129f045343481b1b7c72662a2b4e1d2a2dc778ec6Virustotal results 36.07% 
2020-01-16UNTITLED 9556725791.docdoc eaae7b7b5698c3222b2e1732f334dcf7b81a41dc9418fb078e83f5764ad9a8caVirustotal results 37.10% Heodo
2020-01-16UNTITLED 9244703_6661.docdoc 50c9656e9d815d21581aacde4941e794527b6764c8f0cbc5db0cffc94366b340Virustotal results 34.43% Heodo
2020-01-16Untitled 912.docdoc 5c7d1bb4615145100fa04561534873729b8e59bc84d8fa7850575d16e4c003f6Virustotal results 32.26% Heodo
2020-01-1617396-9244191286.docdoc f1e5b42b22dab179ac7b9c46059ff04fe15c50544021ef719c305f73d2f92c6cVirustotal results 32.26% Heodo
2020-01-16Attachments 6813268-703631384.docdoc 6ab08d34634ed795167bd4958ff7d1eb30025d103150d61406c1ae39394d4f76Virustotal results 27.87% Heodo
2020-01-16848129-8726767.docdoc d01121be7f7eb193a85d9ba14596730d3d33089f5c368501a15b89dd095b803bVirustotal results 24.59% Heodo
2020-01-16353357.docdoc 5336e06637246298e68fe542f172f3b859b61f913d7b1b1f402dd43b9eab0aeaVirustotal results 26.67% Heodo
2020-01-16492882.docdoc 8a74acae6e18e058cb6298684509848286c3dc19189bb9f64e01f582cc31b919Virustotal results 20.97% Heodo
2020-01-16Untitled 526-718406373.docdoc 08258403e9f6dedf233554f21865bd22b4aa6941973c9268e933bb39a335d1f3Virustotal results 45.16% Heodo
2020-01-16Untitled 10037-072846092.docdoc ced84ccc882a33b61611d227e8b21ca4b67d9970af737ed7f3a8c32e41ad835eVirustotal results 45.90% Heodo
2020-01-165056750479.docdoc 881b837b4f8b743627ade4703cf5e6fb97eeb788212f253c65db3ed2d097375fVirustotal results 47.46% Heodo
2020-01-16Untitled 80666.docdoc df5ac7938838d52c0cae9fba928e85535e98dad36ef70be26a592926c7291c50Virustotal results 44.26% Heodo
2020-01-16201866-86792943.docdoc e2a9d9016c8575cc113654642aa970a6f3e13381a5d2f57aa4974f5009d51ba0Virustotal results 44.07% Heodo
2020-01-156698.docdoc c5ede9120a7219c5db64d4bd1d28da88ecde710c606892fce486b6771b8f7e41Virustotal results 42.62% Heodo
2020-01-15FILE.docdoc 0dce7996d8fb1617ac09efd1125611ee679f96a6b1089fa6e2696a2ae84a726fVirustotal results 33.87% Heodo
2020-01-15Untitled 6939178.docdoc dba6e87c2a3ec66dcb501092196f225195379c1eb31cd986c01e0874f633966aVirustotal results 33.87% Heodo
2020-01-15Attachments.docdoc 2853b45864dd97b3be97f9acfcc6be83c6024d9b4e5b48d6b56a8c622e106b5eVirustotal results 32.26% Heodo
2020-01-15Untitled-82456190_1076.docdoc 35a6c928ace899581d72bbb94aecb90fc54a9ef85b852a12cc77ec1a7fd4a239Virustotal results 32.26% Heodo