URLhaus Database

You are currently viewing the URLhaus database entry for http://thedot.vn/wp-includes/multifunctional-array/guarded-area/1xdyYyGTUu-4mjxpc270ygiy/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294152
URL: http://thedot.vn/wp-includes/multifunctional-array/guarded-area/1xdyYyGTUu-4mjxpc270ygiy/
URL Status:Offline
Host: thedot.vn
Date added:2020-01-21 21:38:06 UTC
Last online:2020-01-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 21:40:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:5 days, 10 hours, 52 minutes Bad (down since 2020-01-27 08:32:59 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24File_20200123_3325.docdoc 44bcf15f4888850c235f6e5e7b88bb357a3be71e4b8b22cf9cbaa7ecadbce81cVirustotal results 28.57% 
2020-01-23Rep_2020_01_23_B8727.docdoc e64e311b594718ab849cdf6a3379d11774932a94c3498135f107d659174adb40Virustotal results 28.12% Heodo
2020-01-23doc-8180.docdoc 935442d00e5e51d838e5a2a3651c249aa15fc5ffc106b3fa9414973e11dd8d08Virustotal results 27.42% 
2020-01-23Dat_2020_01_23_3073.docdoc afe09e292b9823a2d28f0c6b6c795b2e3f9d1758d53e30d1eaafd8dd29b2d0a4Virustotal results 26.23% Heodo
2020-01-23MES_PW233.docdoc 9dc63628bbba4305f4e20d32f24bf0416a92edafee60d293788bdc8e81c0455bVirustotal results 28.57% Heodo
2020-01-23Arc-379863.docdoc fa356cafd2c2edc009a85933b576ce9298a6fb4638ee0a1b792402e225913215Virustotal results 28.12% Heodo
2020-01-23doc_20200123_97259.docdoc b63585f5efab051c9a793dac78be7af0a7bb002f803b2d67a828065ee6ce54fdVirustotal results 27.42% Heodo
2020-01-23List 04363.docdoc 4b10f942d9197454cbd1e18eb87d18ab77fab4e78186b0157e96404d3ae11a3cVirustotal results 20.97% Heodo
2020-01-23mes 2020_01_23 RG759.docdoc cd0198b82476b890c4adb94b65b55245c7a7a375e809a127ee20f1a01cc26c1bVirustotal results 20.63% Heodo
2020-01-23Mes_882.docdoc 476a96fc934924101f12b1f1e3548a9688c25bf0eb1c67ef835bc657244b0835Virustotal results 20.97% Heodo
2020-01-23Doc_20200123_861.docdoc 6c2d471a2f006e30296c8dd0e9f7eaae3742e6031681e94d1808dfbecf86c57fVirustotal results 20.63% Heodo
2020-01-23file_2020_01_23_9499255.docdoc dd46168d7017d454d5b01dcb489a4fefe457957a8b0ea67e4bec9678a91cff94Virustotal results 32.81% Heodo
2020-01-23Inf 20200123 OZ77258.docdoc 391cdfda17669f8646d016ccbed5a280386e0ee0d329337ceea01aec817a30edVirustotal results 33.33% 
2020-01-23List-20200123-XE8952.docdoc a5b40116b0e7fcee6fbf05e3425ae17e7812e5a1bfa387e8588f0002fff8911eVirustotal results 35.48% Heodo
2020-01-23ARC 2020_01_23 U971.docdoc 35e9ccfe2fb736ab494d113297f3c7069e131c28b9996efe0623d6f6fa2e2644Virustotal results 34.38% Heodo
2020-01-23mes_4054032.docdoc 88ff8c8ef536a4e8b31a9600abf42ca11d5082fbbfaf8838707b37877b3c38c5Virustotal results 32.26% Heodo
2020-01-23Arc-20200123-515970.docdoc 184e990a522473877e090d94d604888ffc86d75830faaa9858c5131b8e03adaaVirustotal results 31.75% Heodo
2020-01-22File_N366432.docdoc 4f75ef9736ddc508f70ea5da489948d950de61b352fe2497e3c5c87e322597e6Virustotal results 29.69% Heodo
2020-01-22ARC 20200123.docdoc b3a1cdb8288e369fec04ec55e099c9bd7e8593d24da31870c3a782a351d98ba0n/a Heodo
2020-01-22Arc-2020_01_22-783.docdoc 50999d99ad66e0b196084e0b6f483db32ba133c85e2a4ecb7065b5fdb4053e8aVirustotal results 28.57% Heodo
2020-01-22Dat.docdoc 346b0ba9684b9fdc8dde08af0ab486c86cbea5347a32be77aaafb0dc9034f2e2Virustotal results 28.57% Heodo
2020-01-22Arc-2020_01_22-I179.docdoc d11ac96224df72410e7801b55a880897f814ba64e954d6b43069cf114fdb5248Virustotal results 28.12% Heodo
2020-01-22Dat_APZ30699.docdoc 6eb3a1de5779c87ba943671cbe8f29213ae390f189e8bd35f9520393e1edf6deVirustotal results 26.56% Heodo
2020-01-22Arc_20200122_665685.docdoc dad1b60c001deb55fd561c435e1825db93fd1dc33d40fcf6d99a469e56d0f6e0Virustotal results 27.69% Heodo
2020-01-22Inv 20200122 3037911.docdoc 2ad3eac84cebb1c035141e43e0b9a5cf7ef8defb6dc62580737446cc39f9f7f7Virustotal results 30.65% Heodo
2020-01-22Bl_2020_01_22_G750670.docdoc 6dab6d9bdad5fb8c6564493c3c06f10835f916e3980e4937d8c55f4c2f1f1a01Virustotal results 30.16% Heodo
2020-01-22St_2020_01_22.docdoc d51bc288487e5fdcfc17a5ec6e0fa384a022cb77f0474947a0d2059faa19446bVirustotal results 31.75% Heodo
2020-01-22DOC-435.docdoc d5d9a7450867f6c951b33c65e5c363becf43297041b078e61259006714be9da2n/a Heodo
2020-01-22DOC-20200122-Z134995.docdoc 26ac645d768ef953ca314613e2aac462564b0da14de887c1fbee5d2b83a8de94Virustotal results 27.87% Heodo
2020-01-22MES.docdoc 51eee3e4a7660d4f56645b90486fff90496b798f882585f6bce988615624167bVirustotal results 26.67% Heodo
2020-01-22Pay TY023626.docdoc f215874c38b91208764829b0950f3658cbed0e5931060ec4d658ff212f019642Virustotal results 19.67% Heodo
2020-01-22INV 20200122 DZO08515.docdoc f57549b2d5b329a8c83b05e2a6ea4f288e4215882c24d2650cc818e65fcd6239n/a Heodo
2020-01-22BL-2020_01_22-172925.docdoc e32b84c7d967bd21ca4def6c66ed1441afca25b720e896b926f4c01906891918Virustotal results 19.67% Heodo
2020-01-22ST_2020_01_22_1700335.docdoc 822cab01673ebcd4b1d6de1afd0e2cba9d227f59b4be13c5df84c1427ef64389Virustotal results 20.00% Heodo
2020-01-22PAY_20200122_FR148.docdoc 474fcaf12188753f639d6990c5e3e532932b1fe5580fc823f01a7ae6593291beVirustotal results 20.97% Heodo
2020-01-22INF 2020_01_22.docdoc a6d88c45a2db468584d02f98537fa9948fb89553ecdb4a9ed46bd92cbc43d863Virustotal results 21.31% Heodo
2020-01-21dat_2020_01_22_F911.docdoc 2119f3e51c12625d689a0d06dbbbf6d19fc6555e7f33b67a54e3df778f1a09fdVirustotal results 20.00% Heodo
2020-01-21dat_20200122_VF0442.docdoc 9694a4c6d10eb061dd240367cc5d98afa97954e04e12427d65332c4de96887fdn/a Heodo
2020-01-21Arc ILC584119.docdoc 053f8aa722cb6b921c25cdf4e020bc1272f3869f35f9eb9ac4e1314906f9451dVirustotal results 20.00% Heodo
2020-01-21list-2020_01_22-S7680.docdoc 0b9aa4d20188ffd303b57dc404ab310c65f1481bd47e1444de1fd45251d3ca28Virustotal results 20.34% Heodo