URLhaus Database

You are currently viewing the URLhaus database entry for http://ngoctai.com/media/FILE/h03f0h354683936577kp5kfcf82yrxdf7vx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308421
URL: http://ngoctai.com/media/FILE/h03f0h354683936577kp5kfcf82yrxdf7vx/
URL Status:Offline
Host: ngoctai.com
Date added:2020-02-04 21:59:08 UTC
Last online:2020-02-07 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 22:00:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 8 hours, 31 minutes Poor (down since 2020-02-07 06:31:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06BAL_38193912617022.docdoc 3d0ab070c93f643756430b9996c1133e5a5fcbc448094cdff5e5700213a2b0ecVirustotal results 24.59% Heodo
2020-02-06FILE_ON0169800530SC.docdoc 0e360c50b84f0b6abb11bffa18dc5f314d22b2209eaca15062eb36558d386bf3Virustotal results 24.59% 
2020-02-06YG_45446019342803841608.docdoc 4da3454acbd16e098661adc2171e3bf19bc40f55e9a416617d6aaa1e573ccb17Virustotal results 32.76% Heodo
2020-02-05REP_PV1FI969G.docdoc c4e17f776a0a5ed3eb244c0e0523317c245d5df82305e40e044c0a7b429aaf41Virustotal results 27.87% Heodo
2020-02-05NZV23HVOZE3VE.docdoc 81e8254cef67384e3e328c32105ffa10417e9b0f50d2279d0d635a485fa03a3cVirustotal results 27.42% Heodo
2020-02-05J_06010307.docdoc 79da70ae05972300222ed445660fe2fca665639d47725e15c5d599cbe63761b7Virustotal results 27.87% 
2020-02-05INV_52261418.docdoc fb3a4f60f442a053e1d10374dfc474b43f272bfa864b86a07b64c3d449bc0566n/a 
2020-02-05KO6531761016FB.docdoc 1c96dc2ca50755af8de45649f800c5bc8afe690dec831035e2c9c004447e2e63Virustotal results 35.94%
2020-02-04BAL_31646665.docdoc efb70c6c587c286aca5c30beadca0b9221476cdee048b566543fe6c98647b08an/a Heodo