URLhaus Database

You are currently viewing the URLhaus database entry for http://yoha.com.vn/css/abierto_sector/9rdoghzw27mt_w3re9h_9rdoghzw27mt_w3re9h/4322200756_9O96uGv3QWcv0S/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:309868
URL: http://yoha.com.vn/css/abierto_sector/9rdoghzw27mt_w3re9h_9rdoghzw27mt_w3re9h/4322200756_9O96uGv3QWcv0S/
URL Status:Offline
Host: yoha.com.vn
Date added:2020-02-06 08:25:19 UTC
Last online:2020-02-07 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-02-06 08:26:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:19 hours, 28 minutes Good (down since 2020-02-07 03:54:46 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-07OFERTA 02_07_2020 40847465534187.docdoc 951c41a81d18a2577f97934a32f1a28463dc7cdf7b4118ed040c35ae62864843Virustotal results 35.48% 
2020-02-07OFRT-02_07_2020_GF437862732968.rtfdoc 9707abd47ef72798f3d0aa3c5f58c076f401350bb34bef7d5c7660108eab8e42Virustotal results 32.79% 
2020-02-07oferta 5508698152.docdoc 0b77f417fffce47f34544803d4fd268dff1609253941fc9281331f4366e54de6Virustotal results 30.00% 
2020-02-06oferta HV42178174478.docmdoc 0b878e218014a87bc4674a3f8c7113b207cf3e3203ba565c9e3fcf62cb5f18d6Virustotal results 29.51% 
2020-02-06Oferta-P6M7916333580.docmdoc 76ed65f4166ab70a504fa0c58b5fa4d5afbbdf92c3b7770185b137ac87aa37edVirustotal results 29.03% 
2020-02-06Contrato_q13qqq7q6q41156.docdoc 69caf04e8e1e56614bea23015c10066190147415d1c1699accdc79c49531cedbVirustotal results 29.03% Heodo
2020-02-06OFRT_02_06_2020 958245503614.rtfdoc 0395137796e0f9fe7c273562138c7e5f0c988214841e6ed4cda2e3978a98f1bbVirustotal results 29.03% Heodo
2020-02-06CONTRAT_p51625o9602nn3.rtfdoc 548c32e1f7c11d658a1b45cc341ea2480b28c86e352baf366289aaa70a9e9292Virustotal results 29.03% 
2020-02-06oferta-7HR61702944-12717440.docdoc 7f536bbea678ea8894392854b2929ca6860dece9b1acc42df0913613035b682cVirustotal results 29.51% 
2020-02-06OFRT 02062020.docdoc e2242f427a47cdd239a61505c64bb7956f2c451a95ae9dfcf44f845fafeab46aVirustotal results 25.81% Heodo
2020-02-06CONTRATO_02_06_2020-896381.rtfdoc 3c9d9f7c089af3d74e37371950a676a966f7160c531930a218fcefda342beee9Virustotal results 26.23% 
2020-02-06CONTRAT-02_06_2020_E078828.docdoc a2a0d4396733a29e832691fef191647fea4230db515ac8274376ac423becb5f0n/a Heodo
2020-02-06OFERTA Q26211038.rtfdoc 6975ed31fcf619923b119bc26d0f005ef935aaa2e20b25553b47389844f6005dVirustotal results 23.73% Heodo
2020-02-06contrato_02_06_2020_D9527724.docdoc 426f5a4910e1d8c7973f947554016a2945b0997ec5d7bbf3756cef42d9dbbfa9Virustotal results 23.73% 
2020-02-06CONTRAT TD7769094680069 0896404847.rtfdoc 6359275fa65b551a691c324e03fa5c3c73ace835ca4f3d90087dc3332f76ececVirustotal results 22.58% 
2020-02-06CONTRAT-87q01o90n7q5.docdoc d0ba1020328bfa59129c6d94b6bfd8979bd652574b24407bcfdadc75fcf28fb4n/a 
2020-02-06OFERTA-02062020.docmdoc e3c641852888716a100c336fc633f903847dbbec9011a06c98f45d5c5edcff0fVirustotal results 20.97%