URLhaus Database

You are currently viewing the URLhaus database entry for https://mesi.edu.vn/wp-includes/GurqITB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290996
URL: https://mesi.edu.vn/wp-includes/GurqITB/
URL Status:Offline
Host: mesi.edu.vn
Date added:2020-01-17 14:45:14 UTC
Last online:2020-02-04 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-17 14:46:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:18 days, 1 hours, 17 minutes Bad (down since 2020-02-04 16:03:34 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18INVOICE H51_109999.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18invoice-ZK467_0626783.docdoc 3a1ce995c61d4ac7178764dae104f237f94a0815a0dc673942241d73000193ddn/a Heodo
2020-01-18Inv-ICMJ322_612017210.docdoc d4d29c6cfffdf351ad541d65a634554e0a99a4486477bb307f318499af87904bVirustotal results 24.56% Heodo
2020-01-18Invoice_NLX4_2627042.docdoc e4def16e9897c04029e960d9ba6d20e17757ac6084e0e9ecc6cab31c90669e8dVirustotal results 22.95% Heodo
2020-01-17invoice-I986_16088759.docdoc b601c7e893dce2a6584a2d1df22631f10bf61b946a3dcde0f2986d1bfc6d0b52n/a Heodo
2020-01-17Invoice AMHP97_561275.docdoc a8c4e3f1c16e9ff3857699615d8f6bd392a4d88dfdc6f9dd9b43b523ac3158ebVirustotal results 19.35% Heodo
2020-01-17invoice-BFZF479_87670166.docdoc 040930dcb6516ec19aa7e830246bd05a7df2479b23c3b9e23add649f38469c1dn/a Heodo
2020-01-17invoice J648_2440765.docdoc 612232f5fbbd7e962ff9a576f1a32be4fe4dc541a1bf7dad094becace6e2443dn/a Heodo
2020-01-17Inv O4424_014932721.docdoc 44a7800af970884939e0d1e420aa3f140610c62a0a1e7d207cc020b9971c6c2aVirustotal results 21.31% 
2020-01-17Invoice OB20_61353373.docdoc 5b5d276c15b051d7bd90d0a94065b9989ff8678436c073df253abb3dc9d5f2c1Virustotal results 22.58% Heodo
2020-01-17Inv-UGP988_363487952.docdoc 4bccfd69e2d0f9968b1a8471e9d094226f9ca6cad0fb4681943bfe1cf459a706Virustotal results 20.00% Heodo
2020-01-17INVOICE_B8_95740612.docdoc 298a10ce8a9fe8dcc5947d02585a549d1c9d0609c7d11473ff4c8dfbb3a9f801Virustotal results 21.31%