URLhaus Database

You are currently viewing the URLhaus database entry for https://www.dienlanhducthang.com/bosp3r/8Nws/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307281
URL: https://www.dienlanhducthang.com/bosp3r/8Nws/
URL Status:Offline
Host: www.dienlanhducthang.com
Date added:2020-02-03 23:06:19 UTC
Last online:2020-02-04 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-03 23:08:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:12 hours, 45 minutes Good (down since 2020-02-04 11:53:43 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-04yK4Pl.exeexe 61ce85acaf8a5a0f3cdf29f7be3eb73822f20e98393a0cce3a52a316eb304721n/a Heodo
2020-02-04CFswhZgqUhcz8S.exeexe 2c6194be5c891439c36f38ee40c952b7a843e2511a1a0b0da1413cdc9979ee33Virustotal results 26.76% Heodo
2020-02-04n.exeexe 5478b02271938acbf4aa7de8182f519f65fee14feb4aaf4960377cbbc180f855Virustotal results 23.61% Heodo
2020-02-049UHIqxjmV206RB8aaRK.exeexe 1390cbebfb0dbe2c6c016d9de9300679c31b6eac66335f1679ca1b10e6202d86n/a Heodo
2020-02-04pGfbiW.exeexe 50c512e898ae994c5d800a4b4220642836a3477e328b9aaa04b5db0d3befda2cVirustotal results 27.78% 
2020-02-04O2TRfWd0.exeexe 4f4d973735920e26d078f4c7e35e55d985d69d57ac09304cb9549cbdda12a9dfn/a Heodo
2020-02-04iwsBhRKPykcFBejRK.exeexe 2ffae332e7d1f5ca2265a6a1ab8de5393d4bc96f13017ce209e970402f66d588Virustotal results 19.72% Heodo
2020-02-04auJ4trzMgM3OLC.exeexe 42fb197ba0f3df488d57f00ba4d1f5c22b15c103781c301cbdce7dcbd1a8b8cen/a 
2020-02-04HQ71fTOU0u9ZMPX9THS.exeexe 7f2914fb77548b11cee764dfe57f64744f1693235442974971932182113f478dVirustotal results 21.43% Heodo
2020-02-04Sk6.exeexe 4147e6c89c0c07a526fb26bd319da6db8d4116a715dcebc787e8c899c4156050Virustotal results 19.44% Heodo
2020-02-04ADjfRYne7jvG9Dcma4.exeexe c819ef6b36012a99544971f73f8056fb17fac868e431a898859418e85a6a30e5n/a Heodo
2020-02-03gJobyMjIW.exeexe eff9e615f227d4f2def647fbd517804c4636ebc65dad44ce5f358377973ecd59n/a