URLhaus Database

You are currently viewing the URLhaus database entry for https://ruttiendaohan247.vn/iijxFWI/dIHfYbSbG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:307959
URL: https://ruttiendaohan247.vn/iijxFWI/dIHfYbSbG/
URL Status:Offline
Host: ruttiendaohan247.vn
Date added:2020-02-04 11:46:37 UTC
Last online:2020-02-17 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 11:48:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:13 days, 4 hours, 1 minutes Bad (down since 2020-02-17 15:49:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06Inv PAT0479_574790.docdoc c7b6f46f5a55f557c829d3a1e6d171b7fc2577517bd72b3219b805304f56a2fdVirustotal results 33.33% 
2020-02-06Inv-5215_614858387.docdoc 7eac21ec4810b17ae186a7cb7619660833006d22ffdd25ffa44769a9474a13b9Virustotal results 31.15% Heodo
2020-02-05invoice-O6943_53801335.docdoc 23bfb58c53002a4c03a4931e057316564e8ccab64975f93e2d66ceca6c73f7afn/a Heodo
2020-02-05Inv QPK32_140801.docdoc fbc7e227ec8bd45144bdd33ac13c8a9b563282ce2c47bed6f613e71ed22dea4bVirustotal results 26.23% Heodo
2020-02-05INVOICE XT61_153234.docdoc 4c81ae4043b5ebb941a22c4511a4757a6a0ca5a842660b5c1ea31c57955800c5Virustotal results 26.23% Heodo
2020-02-05Inv_WH5674_60571514.docdoc 4152d52f1411482170163f5c1a548319cf7bf6b6e3b95a2d5dce87a21ef76708Virustotal results 26.23% 
2020-02-05INVOICE HJ60_52435468.docdoc 0730eae02471503c7ab9c5f470a916f7f1578c78676c2c401ecd562214e25d37n/a Heodo
2020-02-05INVOICE-FV5_24940990.docdoc bac64a981e3fddb119868ac4b6c14005db9b3c64f608849911d6c08947267dcan/a Heodo
2020-02-05invoice UAI9_09125373.docdoc 2592177b8fc2dad7890e1d568a33bde6b00c015fc0c96dbccf47299f5f0953b2Virustotal results 27.87% Heodo
2020-02-05INVOICE NZ3_980570684.docdoc 553bb18cdd7ff56366cb6f9509373cc5c6e58e24d1056bafe7e9bde95f6817d7Virustotal results 26.67% Heodo
2020-02-05Inv_KHXG1544_492216628.docdoc a2193d72f5be38cd1689028f15e885dafd9baef0923a1c1e761c88b8fd3e5ed3Virustotal results 26.67% Heodo
2020-02-05invoice_W4939_010121.docdoc ee932045a6cc0928256f9fd9792fb685acd23e47fc4147eb4795a6e009be1942Virustotal results 27.12% Heodo
2020-02-05Invoice-HG0_01006795.docdoc fa5927f2181dbeaef9cab75616169a02fe02b41df92e598cabad444619c3befcVirustotal results 26.23% Heodo
2020-02-05INVOICE SHDQ662_545414652.docdoc 6e6b6b51d4a9dd7f74e82c53490f95ead4a4d2a9a4adb06f1cbd991bc2b225a7Virustotal results 33.33% Heodo
2020-02-05INVOICE-PE2622_921378372.docdoc 4cdac2f4d63304355834be949d3daa22b6de9607436c0f5cbe758f86c05c5b72Virustotal results 33.33% Heodo
2020-02-05Inv_7790_4277046.docdoc 471942cfd9aa93923bc0f054e64201217913ae24a3e192919207202918c628fcVirustotal results 32.26% Heodo
2020-02-05INVOICE_OMRG84_85080558.docdoc 50ed2de7492f944d8a34c9d454c3757a58d26078f91dd5de90ac595eb6279dc7Virustotal results 42.86% Heodo
2020-02-05invoice_WZFR2480_44381317.docdoc 25d98e7b0341be2da85f8fbbe279863673a1b0744c9773c8f6bcaa0c0666c935Virustotal results 34.92% Heodo
2020-02-05INVOICE-PB1603_328459807.docdoc fe95a5f68fe689f22c1ba6e479febd867fbb29760f0063700ad27d7d8b482d67Virustotal results 34.92% Heodo
2020-02-04invoice-5557_92418340.docdoc d0787010e140c3d4c833ba70fcd573e0eb42df65c29756cf65d0239b4374f915Virustotal results 33.33% Heodo
2020-02-04invoice 88_629583.docdoc 0b2ca06ad6086c411fe61f2b5a791d8fa9336d920a8c39214db4c4b05e69a3acn/a Heodo
2020-02-04INVOICE JD849_620079005.docdoc 41aea47e36728ef17f91fb0ed0239001ef742699f4e187e54d4e107680725a5eVirustotal results 34.43% Heodo
2020-02-04INVOICE-A79_916005186.docdoc 1d1ad37018649607913264ef75cad7bc63005b2432b9b27e41f41b574d4d7989Virustotal results 33.87% Heodo
2020-02-04Inv P1_3701459.docdoc e5ae49a0cbc1438936c3763dcf9b743797c549d9f67bc7cc0034505a845f132cn/a 
2020-02-04Invoice 804_517794464.docdoc b4c3990e73035881f982534ee5ccc3a30f80b58c625e28b6f68067c223589fc1Virustotal results 31.75% Heodo
2020-02-04INVOICE-ED5_707768416.docdoc 40c57139f9fe475f5e06542c48aac3476cd943f3530f73ef44a60db380bf9e04Virustotal results 38.10% Heodo
2020-02-04Invoice-GSM22_26191411.docdoc 904f34e3a638e5d981f17dc0728844c41378c8b8ee1f9bb7e85b614af0478739Virustotal results 39.34% Heodo
2020-02-04invoice-MCP2310_690758.docdoc 1173cf1516a39c758a543aa77e5efb97ae7c0405e4d4921939f774fe9a48be41Virustotal results 38.71% Heodo
2020-02-04Inv_QLK868_54550536.docdoc b38620f90ec6f200c3c194fb6ec3444c55f50151f4a47cd6ff0eba0bc12a03can/a Heodo
2020-02-04Invoice-PSJ648_274376.docdoc c6f67345d51de31d968f542885d815a518e46ae16c2629694893cceceb18ff3cn/a Heodo
2020-02-04INVOICE-XE865_210958792.docdoc 8e66d9957e16b357616a30285cc04951088836af1778c63ca72ed2f7f0b48f41Virustotal results 33.87% Heodo
2020-02-04INVOICE-BD9_76660863.docdoc eacfda7cff958601644640117ada58257c29f124a9f64df75f0f01b0976711aaVirustotal results 35.48% Heodo