URLhaus Database

You are currently viewing the URLhaus database entry for http://phusonland.vn/viewcart/personal-box/verifiable-profile/ivpf5e-7051z9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:308900
URL: http://phusonland.vn/viewcart/personal-box/verifiable-profile/ivpf5e-7051z9/
URL Status:Offline
Host: phusonland.vn
Date added:2020-02-05 10:41:12 UTC
Last online:2020-02-06 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-05 10:42:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:18 hours, 4 minutes Good (down since 2020-02-06 04:46:38 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-06Dat-20200206-RR988028.docmdoc dd358c929669211675afa0aa1b402084ed256d8a36ef877ef52fa342235358d7Virustotal results 30.00% 
2020-02-05arc 9671459.rtfdoc 335e92129e141d12928fdc17fbb6c1dfe8b6fa59b2ff2a4ad0c60f4f0637ee83Virustotal results 27.42% Heodo
2020-02-05Dat 20200206 HEF209.docmdoc c1d36e9aab2030f23a10178cc432f92255b74c7e2382840bbae1ad7c099e97a9Virustotal results 26.67% Heodo
2020-02-05FILE_20200205_Q597505.docmdoc 1566745273aeac5249400c456f82b70e870825a50ee2457479f734c7686dfb54Virustotal results 26.23% 
2020-02-05FILE-20200205-659.docmdoc 79b3a51440b181671112045cb234739a360169bc4c6ccdb30a3907a50a055963Virustotal results 26.67% 
2020-02-05File_2020_02_05_1387842.docdoc c0b9c90ce017a4e5196e744c7948464ff57431da4a1d820793c5aea57cc0a095n/a Heodo
2020-02-05INF_20200205_JB95453.rtfdoc 59b1973230dffbe699193f1b10773d0e327fdde500ae9ce1a1af2024c5f38140Virustotal results 26.67% 
2020-02-05dat-20200205-D628.docmdoc 20b603562ad65e466c27733e3ba8368c3ed83caeec165555f4a935ed0cc6d4b1Virustotal results 26.67% Heodo
2020-02-05List-714094.docmdoc 65378d1cf3c1fe445cf463661c3e099593c251052d490aa2b3198b7218187725n/a 
2020-02-05Rep_2020_02_05.docmdoc 6228be42f808ff1c2d59dc6df839b24c07a9e9640fffea33d21e69f3b2765a69n/a Heodo
2020-02-05rep-6906631.docdoc ab556aef3f7baf74127e682541cd5bb674af38a62c4c1f89ff43f09388894af2Virustotal results 25.00% Heodo
2020-02-05Mes-3506087.rtfdoc 6b95c7839354ae0b69e74737d37864c5c78048aab4fdbf7a4916221d675dc9d1Virustotal results 25.42% Heodo
2020-02-05file_CIB7006.docmdoc 1c936bf571a3cd6deb6e4c3a2f6e49abc2c37cdcf843f955fe7f002b5ad49776n/a Heodo
2020-02-05Inf Y0259.docdoc ef74202276aee43dca3327e29e3f7444583c342da59aa5f7ef01e6be1dccfeb6n/a Heodo