URLhaus Database

You are currently viewing the URLhaus database entry for http://nhathepkhangthinh.vn/70hof/private-resource/individual-cloud/kkin-93w1sy3uw/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308449
URL: http://nhathepkhangthinh.vn/70hof/private-resource/individual-cloud/kkin-93w1sy3uw/
URL Status:Offline
Host: nhathepkhangthinh.vn
Date added:2020-02-04 22:19:08 UTC
Last online:2020-03-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-04 22:20:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 month, 13 days, 12 hours, 7 minutes Bad (down since 2020-03-19 10:27:28 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06LIST_ENX549.docmdoc 398d5447b00e2439bf8e9a1d639fe45ea0221d040339e8780cb6388a9e403383Virustotal results 27.87% 
2020-02-06Inf_2020_02_07_1447.docmdoc 49d7cc27c44c30413b244e4b09b23f447b31f1b529d5ccd618e5271c7a6ad92aVirustotal results 27.42% 
2020-02-06doc-20200206-W6301.docdoc edb22c027998953f21cfc35ed2512552476f6a94efce379639c1237ad8ddd663Virustotal results 29.03% 
2020-02-06List-1059812.rtfdoc 3e2e9332429ca46e97d6d5b2d39864b216599b31498ebda448a3fc2adfc78a0dVirustotal results 29.03% Heodo
2020-02-06ARC 20200206 9701110.rtfdoc 33b5e2a31a3000b7a3251be5436e451986568c1a93ace24fab40817786f5a2e5Virustotal results 27.12% 
2020-02-06List 20200206 OR0002.rtfdoc 6c68e77608fb195d36beea95bdaa462975655333c6d0eaff45c88df54deb58a0Virustotal results 21.31% Heodo
2020-02-06inf-20200206-Q02806.docdoc 36303bac61e900a80525ee3b4fe2a968c27e6b8984ab03750f1c638fa75a8ccaVirustotal results 30.51% Heodo
2020-02-05mes-FZ5123.docmdoc 335e92129e141d12928fdc17fbb6c1dfe8b6fa59b2ff2a4ad0c60f4f0637ee83Virustotal results 27.42% Heodo
2020-02-05MES 2020_02_05 LX23572.docmdoc 394d15209f21b6df3e6df0bedcf76ccc1e08f8f31adf7b035d83a35e5b2af2c3Virustotal results 26.67% 
2020-02-05INF_07371.docdoc 4bda34084014e21ceb2db8fb9003f36f4b3a7bd5a8bcfb9b1badbf13529a6d84Virustotal results 26.67% Heodo
2020-02-05file_20200205_Y043.rtfdoc e9de053b8046e662771b320b25a49cd709591ac896fb6bd4c324ba0b13f37b35Virustotal results 25.00% 
2020-02-05ARC-725256.docdoc 1d71db32310de6088f008bda0c652b8a1715c3b98c549cfca90601bdc70c59a8Virustotal results 25.00% 
2020-02-05rep-20200205-FJQ05726.docmdoc 8da9b64f05685802f69618feda838a3f4331363e5e7ad48cc004353b8a4dac2cVirustotal results 25.00% Heodo
2020-02-04inf 20200205.rtfdocx 2ce39aa57a54745392223bf7ae5614994cfda8880555c4d6b5fba47dd3242298Virustotal results 30.16% Heodo
2020-02-04inf_Z1009.docdoc 3f872ff400f00e55750ec80b287d27f8ddfaa2ede0a0421b99b935c24206e325Virustotal results 34.43% Heodo