URLhaus Database

You are currently viewing the URLhaus database entry for https://nbiyan.vn/u2enjmwr/Overview/zjkd911-06-6643hqttpf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:304040
URL: https://nbiyan.vn/u2enjmwr/Overview/zjkd911-06-6643hqttpf/
URL Status:Offline
Host: nbiyan.vn
Date added:2020-01-31 13:54:26 UTC
Last online:2020-02-03 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-31 13:56:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 19 hours, 40 minutes Poor (down since 2020-02-03 09:36:34 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01R_60772178.rtfdocx 8ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0Virustotal results 45.31%
2020-02-01HLEK1HD.docdoc c117593f754a9dafdfb9c3bcaf46d70eda6bedf7ee811038f00aad85aa541355Virustotal results 37.50% Heodo
2020-01-31FILE_401382824249496692.docdoc 3b3f1ac07d07a870c0875efa8819d440ab3b620d1590f0422fac10182ff1ba29Virustotal results 32.81% 
2020-01-31PO_01312020EX.docdoc 5154e5b81a62e4af7b1dcdccc0c619e28717bb7bf899713e72f9480ac704e5b5Virustotal results 33.33% 
2020-01-31C_E36BZ7BH6.rtfdocx 9ca9749660569bd45851774becb4204394ea2ab1cb510d28d7bc77060aee9c20n/a 
2020-01-31YK_25884352.docmdocx c65e54d8fe1847d0d081c3058842c5b0254a355c41756816944d2fb8fcf08a54Virustotal results 28.57% Heodo
2020-01-31REP_DSE_010120_GKP_013120.docdoc dd7ffb73c534ea606a7282f2d2126ed0feac359939a237270440750165714eecVirustotal results 29.03% 
2020-01-31C_VQ1044013598TF.docmdocx fde981959b6b1118d50bf879509945fcdd62384654c0c29ebc296529e153210bVirustotal results 20.31% Heodo
2020-01-31G_VFU_010120_EEX_013120.rtfdocx 8733de6d4b6d637e2bbe3928dfeae5cd7838708d9ab3f70799f4440d5757614aVirustotal results 20.31% Heodo