URLhaus Database

You are currently viewing the URLhaus database entry for http://sensecity.vn/wp-content/OYl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:292952
URL: http://sensecity.vn/wp-content/OYl/
URL Status:Offline
Host: sensecity.vn
Date added:2020-01-20 20:24:12 UTC
Last online:2020-02-28 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-20 20:26:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 8 days, 8 hours, 40 minutes Bad (down since 2020-02-28 05:06:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24invoice-943_826944433.docdoc df476578ee7f5bcc90c4578a7737fffabc637ca583c3ff9d4b79822e68148179Virustotal results 25.00%Heodo
2020-01-24INVOICE WQF613_27818715.docdoc 21ed646e9c73d65b5355a50adb7b3a7b2f6d76b45d4248e2ad2480fd784ee8b5Virustotal results 25.40% Heodo
2020-01-24Invoice_GEYM1258_973588632.docdoc e6227f508ea8149469cf318e6939e1fd1d8b32b728997677e8220d7c4b827ac3Virustotal results 25.40% Heodo
2020-01-23invoice XA8757_315335.docdoc 7a407a5d5853fcad0d7872e8ae60b0471662cf83c0b5bd56dfbd474fe2e6036cVirustotal results 40.32% Heodo
2020-01-23invoice-GZ30_3088513.docdoc c178793508c9ec1955d363fa70ab41ca7a17928c7445a1594789904e320ce640Virustotal results 29.69% Heodo
2020-01-23Inv 5334_8871255.docdoc 6dbf308715c0b429e1b0e16054cdad388a7095462af98c1893432f3967836b53Virustotal results 32.26% Heodo
2020-01-21invoice-VQS4162_850048385.docdoc 8adf131ed321d6d3aab85250d292da1d638dd76087af7f59025f93ac6e795697Virustotal results 25.81% 
2020-01-21INVOICE-XM556_72159380.docdoc 72b5f5d539c7024db2283653690d00e74b38049afc4a620b85e63aeca3729e42Virustotal results 25.81% Heodo
2020-01-21INVOICE-G852_3524192.docdoc c9b288f025cd8dd448fc3b9a7315b5f54fd97d274d7c3716334e92b10c22bad9Virustotal results 33.33% 
2020-01-21invoice LR772_23022105.docdoc 7de65f0ca36e1c0c732118aa532a156908d9978eb1419e1738fdf68b3f6dcb06Virustotal results 30.00% 
2020-01-21Inv 0_741183.docdoc d4b4472880a0b42e7524b3a1ea5497b634384b490d5062985ca8dca6f486863eVirustotal results 27.87% 
2020-01-20INVOICE_OHM8603_6685002.docdoc ed708cc369c2cf912fb164dcda6acf7528547cdff0248e6a81a5f53418991be0Virustotal results 26.23% Heodo
2020-01-20Invoice-H8781_071304065.docdoc f0dc4d866a0d95adfa3c61d147c5b9f4099021454db050c8e680c51f889fe39aVirustotal results 30.65% Heodo
2020-01-20Invoice-RJDR790_70907680.docdoc 8a4f5b1a0e11cb8511619e03580e3aa8a8ff67e5c7971480b83776f78fefdaf3Virustotal results 27.42% Heodo
2020-01-20Invoice-12_03370220.docdoc 656e4239a79e7d79ea41e7edfc3cd075afe51f083e8c63bb82f6b345feaa0113Virustotal results 26.67% Heodo