URLhaus Database

You are currently viewing the URLhaus database entry for http://dienlanhtayho.vn/wp-admin/closed_disk/security_portal/5136567_gO7WCpbEtTyN/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300667
URL: http://dienlanhtayho.vn/wp-admin/closed_disk/security_portal/5136567_gO7WCpbEtTyN/
URL Status:Offline
Host: dienlanhtayho.vn
Date added:2020-01-29 02:06:04 UTC
Last online:2020-01-31 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 02:08:01 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 17 hours, 43 minutes Poor (down since 2020-01-31 19:51:23 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29Doc-2020_01_29-OEY942.docdoc aeb3fa7a98498f9a7a195b2d0258eb122fbd23c23320a1f112894e9d6d1b964aVirustotal results 29.03% Heodo
2020-01-29Mes 20200129 EE455.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29Mes-2020_01_29-39654.docdoc 94e0d6de6118c26179d6f05dd39b5583f1fe79c66151f666734b93a655a71930Virustotal results 23.81% Heodo
2020-01-29DAT 975.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29arc_36804.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29FILE-2020_01_29-CR294656.docdoc b7cb7ac3c2e6b877b9893ed5651e3dfe2937135d7a2bc612ee70c3abf4a8d654n/a Heodo
2020-01-29dat_20200129_55750.docdoc f5c5c5efd56a06272577f6aa8fde6fe22660095ec9332d7449f3e0769fa11b8eVirustotal results 42.86% Heodo
2020-01-29Doc-2020_01_29-8141.docdoc 6a23106b558df36e6d88bb5b5dd187430087eff0c8a2ca1586f8538e8259e01dn/a Heodo
2020-01-29inf_054545.docdoc 5ed01ecc76724ef8dff654d4ef2b359c600c6dd3da2481677304b851d0c752b7Virustotal results 43.75% Heodo