URLhaus Database

You are currently viewing the URLhaus database entry for http://irtech.com.vn/academy/invoice/2ah445o8m/p2kt112396-26241226-zyklyvsh7kltq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303147
URL: http://irtech.com.vn/academy/invoice/2ah445o8m/p2kt112396-26241226-zyklyvsh7kltq/
URL Status:Offline
Host: irtech.com.vn
Date added:2020-01-30 18:28:09 UTC
Last online:2020-02-16 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-30 18:30:06 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:16 days, 20 hours, 5 minutes Bad (down since 2020-02-16 14:35:27 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-16SW_752561977819.docmdocx c5d601f8ed9a1050d8f5f922cde7628d4d9a32d01edf8cd070fb6a3c745d3a52n/a 
2020-02-01XYBDDHGMY.docmdocx 8ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0Virustotal results 45.31%
2020-02-01DOC_DY3KWUOQCI23N.docmdocx da2dfdde77d319fa7d1a1326ca2ce99142a8d194e609eba08264875f442e240bVirustotal results 45.31% 
2020-02-01DOC_48473373.docdoc 12bc283594bd2540d46f51658970e354cadec045dd90a541cdfd238fdc096a52Virustotal results 41.38% 
2020-02-01REP_54KP1LO.docmdocx 33a89c876ed4c1f54ac3ebf60cd427562e652b39263734b693beb3be9e6c67ebVirustotal results 40.62% 
2020-02-0123534731916482027076537.docdoc ac59c732daa8085badba3321495b6415cec136aaceaf03e509380f2d2742866bVirustotal results 38.71% 
2020-02-01F_10026912.rtfdocx c117593f754a9dafdfb9c3bcaf46d70eda6bedf7ee811038f00aad85aa541355Virustotal results 37.50% Heodo
2020-02-01PAY_VHE_020120_BRL_020120.rtfdocx ad699aad87ae12d22c0e821eab25c18e747ac783cc024621bdd1853c6347ff0fVirustotal results 35.00% Heodo
2020-02-01SW_70496326.docdoc 00abab34cd75538d9fd580736dcde930d31c1c93209c7ba6fddaabbb2cef1382Virustotal results 35.94% 
2020-02-01OUZ_GO6147833259ZZ.rtfdocx 67014fca7bec38816b162f8568680c49b61d221b6f635322480b97f920b30e20Virustotal results 37.10% Heodo
2020-01-31PO_02012020EX.docdoc 6c30f2c3483bdcdb6544377812c9a3188ebba7111f6c59b5f2c2bcee90a0cdf3Virustotal results 37.10% Heodo
2020-01-31BAL_NPK8BAQARY6.rtfdocx cbf7c85d8c7352b91f6f1887014170afa27da025e20e1208b844e97302b5b5d1Virustotal results 29.03% Heodo
2020-01-31JLD_020120_HQG_020120.docmdocx 3f8f8f620cf256fc8c738bf6eb7cca17c556c295db6adbd62ce74649e37f555eVirustotal results 30.65% Heodo
2020-01-31RP_PO_02012020EX.docmdocx 09eb15df6edcea194754173e9b4df0628efc8aef6aba8aebd548582178c445a9Virustotal results 29.69% Heodo
2020-01-31NFS_010120_YKN_013120.docmdocx 2f76fbb18ce11d65b1b0e5929476bbdb89d5850d8cd2c1840da889700905d5e5Virustotal results 34.38% 
2020-01-31PO_01312020EX.docmdocx 60014812542949a195f1d7ff40509bcad41fd6141d0ef19c0a527fd553fe44b7Virustotal results 33.87% 
2020-01-31REP_984841011.docmdocx c65e54d8fe1847d0d081c3058842c5b0254a355c41756816944d2fb8fcf08a54Virustotal results 28.57% Heodo
2020-01-3132673485.rtfdocx dbbe1fec47e8d343db79a96fe58ee5a504609dbddad0587cb31c83d134d02972Virustotal results 25.00% Heodo
2020-01-31N_6000793828096493.docmdocx 1d15c420f5149dd31996e11e3d746188181be53557d7956237b8252c9630cd7aVirustotal results 22.41% Heodo
2020-01-31BAL_VT3144237395DC.docmdocx 6d437b0cf2e3835af4e92b39afa8b409ad01a51cb100e389f0217d4ea3573051Virustotal results 20.31% 
2020-01-31RP_PO_01312020EX.docdoc 32611bf81a7c08569474e590f6401621b66584f95d22d97226fd7e43a4b84365Virustotal results 20.63% Heodo
2020-01-3199984240.docmdocx 9461ef60143b1e7d0c4207f9b05ff639b9dd018b7163708203383efc2998df31Virustotal results 34.38% 
2020-01-30DWH_010120_IID_013020.docdoc 11850be3ffe56cc8d2b4dba455475beb00c90133752d3e329b2ce202a87bab7bn/a Heodo
2020-01-30QYC89Z7NJ.docdoc bfb07402a9c2d9bc220ccce8b230e81d4fc183715599b2aae3a17dfa3d9e8419Virustotal results 38.10% Heodo