URLhaus Database

You are currently viewing the URLhaus database entry for http://vaobong66.com/cgi-bin/multifunctional_array/verified_space/gwIhx_ebs4ysexs4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414206
URL: http://vaobong66.com/cgi-bin/multifunctional_array/verified_space/gwIhx_ebs4ysexs4/
URL Status:Offline
Host: vaobong66.com
Date added:2020-07-17 20:13:19 UTC
Last online:2020-07-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-17 20:14:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 day, 21 hours, 40 minutes Poor (down since 2020-07-19 17:54:30 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-18Dat_522281.docmdoc 8a20c5d41b0ea80165d9d900936696ea0d6e1aff5e22ec84913d2a8663f4c063Virustotal results 43.55%Heodo
2020-07-18DAT-20200718-VX7289.docmdoc 7368359446096f3aa39784197cf18662554a6ead0d4ff0938fc49f2b713dab51Virustotal results 43.55% 
2020-07-18ARC-2020_07_18-FGG951288.rtfdoc fdb43ef55c448c1ddfb8f3f4285691274726e0ebea7bb77329da28e47d9e9eb1Virustotal results 43.55% Heodo
2020-07-18MES 20200718 ZWD5942.rtfdoc d83dda004c1f5cc3b6af587c3ceace1bb5f2e76e8cdb013a30c0078e100b2e07Virustotal results 43.55% Heodo
2020-07-18dat-2020_07_18-MSP20620.docmdoc 49b1db3ab05041bbb1b9a2cd6c9b4e33f1c3dc4771d4e5b35ca7e19135c5006fVirustotal results 45.00% Heodo
2020-07-18arc_20200718_O140403.docdoc 54daaf4068cebea8b89ef3f816d0b551095429f8fdd6a5b579753c27b23be06bVirustotal results 44.26% Heodo
2020-07-18LIST-PL588001.docmdoc 0282a9682b4c3f016f4cd84847a3973d205972a75993feb753b575895a162a46Virustotal results 43.55% Heodo
2020-07-18INF 20200718 MRK2385.docdoc 0c3d714fca3f5deadd848d030e8a87bb073c39ffef3f849eed2d405f34b84408Virustotal results 43.55% 
2020-07-18Inf-20200718.docmdoc 0f62fa0eda89b4c7e9907ff92c9cbfcc2639c16eb162c40311c4bf40396c47e4Virustotal results 42.62% 
2020-07-18File.rtfdoc e4f83f5b3d38b5bbe3b2372980bdb5303c74b1938b66e40288e0ad6c2c79d9b7Virustotal results 41.94% 
2020-07-18Mes-20200718-8040.rtfdoc 3b1ddd73153ba5daf34cb2df5a5bf96b2868d8dbb014d9e9e09ff8c50d07ef99Virustotal results 41.94% Heodo
2020-07-18dat_2020_07_18_ABX924837.docmdoc 1b55ff8c9a01ff0ab2274f14de29f5173e799bfb1e8fe892673ca01c3d36df90Virustotal results 41.94% Heodo
2020-07-18Mes 2020_07_18 1070331.docdoc da9fd0cdce18f47eba96ea42f03affa9d564447325571b8a60ea9cb25fc4874eVirustotal results 41.94% Heodo
2020-07-18REP_2020_07_18_194.docmdoc e11da7c7c88a7a2a16b8f4c7581b1349658d2629b5876da8384e4d4b1e7ddb96Virustotal results 41.94% Heodo
2020-07-18Dat_NSL226.rtfdoc db7f888bc27f3625e1d2aa8dcd1f473d1b6c3f18425041aeb9d6317a5cf977c4Virustotal results 43.33% 
2020-07-18DAT 6813201.docmdoc 49163b028d55db6bb748928f543fc005282f09f209002ef17f6995f237498d4fVirustotal results 43.33% 
2020-07-18arc 91959.docmdoc 44737c7b4475fb2a259af5c0b23c7f14945dda0d119491a61f2004f59cce8105Virustotal results 41.94% Heodo
2020-07-18Rep_20200718_6834.docdoc fc56717cca4ae6fb3cd905dfed6ddfccb6be04778d169f06fd8dd832e05b5789Virustotal results 40.98% Heodo
2020-07-18file_20200718_3978324.rtfdoc b5e3dc0a53062058a2b13ef1d82f7c2b7ff5fe9452fe4cfd534eb6acc3844a26Virustotal results 40.32% 
2020-07-18arc-20200718-ESF4116.rtfdoc 0aa68db997d98b8133ee52c453e2c7b83a3eadbda9425b9ff2fc6e3ff283c48dVirustotal results 38.71% Heodo
2020-07-18Rep-20200718-NP5255.docmdoc f821386a84c5ca5ce96218b63990b6ef7ba0016e43aae95ebd78c9bda997b6f0Virustotal results 39.34% Heodo
2020-07-18REP_2020_07_18_EMJ67447.docmdoc 090635f92e151831194a070a79d3d0b04ecfe41b4dd19cc0fd66bf27a8ad4b85n/a Heodo
2020-07-17DAT_2020_07_18_67812.docdoc d0a6228f0457c0dab131d8c3cbcc69b48575c993d2c1e3745087337415144d9cVirustotal results 37.29% Heodo
2020-07-17File 2020_07_18 42683.docmdoc b89bd8bfdf7fd5c0068f3ce823eb1b563cbd691a3bc70b9080b36b611af5e27fVirustotal results 37.10% Heodo
2020-07-17DAT_2020_07_18_252531.rtfdoc 2fdb794642d195e0cf37d232ed02d37ed74b1b5ffa324fc9251b5cca3de8ed2fVirustotal results 37.10% 
2020-07-17Mes_XV21734.docdoc 6264e94597601ac38cf03e59970036714ef4047d46a6c16f2de4716a4aee449cVirustotal results 35.48% 
2020-07-17Dat-ETP75258.docmdoc 3f054364f4de6d79966887c8d95c9c4bbe25fbb622c1163ff73ac7d345f73731Virustotal results 33.87% 
2020-07-17Doc-2020_07_18-ZI600.docdoc 4f650fae13b2f497c92dd327ff98b5126875ea6741d5e9db7f7f74bb2e471f83n/a 
2020-07-17Inf_2020_07_18_M900.docdoc 4efb5eea71e20c735df86a96e1cc7d69fc118ba4e71b69c98811dbe49742b755Virustotal results 29.03% 
2020-07-17File_Q00148.docmdoc d0640e7359f66f9c86770b4974d8d9b8f7a03f83ace42e21d03229059766b1abVirustotal results 27.42% Heodo
2020-07-17inf 688173.rtfdoc 3f69f8a5d85615b90542b5460bd5298315e40c5e29978ab420bb67620f2422c1Virustotal results 27.42% Heodo
2020-07-17file_2020_07_18_CJA5097.rtfdoc e0dbd16c77a20262e645efb54ad25b76ebfd52caa1e6eebe10cd7e52a81119deVirustotal results 27.42% Heodo
2020-07-17list-20200718.docmdoc 0fcd9e5cdbfd7704545e03dd7c7a3deef28f11ae26911b0f86b20687fd46d2ddVirustotal results 27.42% Heodo
2020-07-17FILE AA834648.docdoc 7314748358ee31f8fdfdc7972cb282d8675c0e843b07383c52e124ae3b937a7fVirustotal results 27.42% 
2020-07-17rep-2020_07_18-9386953.docmdoc 328a1ddb0998b010e99d5314354fa47de97745a0e09b6682e043ffba500f19cfn/a Heodo
2020-07-17arc_BJP3104.rtfdoc 273b63046e85b9089957375db46fa53bdf6544588f42c68ac859af27aa61688cVirustotal results 27.42% Heodo
2020-07-17File_7297221.docmdoc deb9182b6e138520576458d85048d5069a4e20f11acf4938b081ba4e8765365cVirustotal results 27.42% 
2020-07-17FILE 7309530.docdoc 770fd6643c934cc3aa0fddf589d643b7b59e18a005ff89fc9113bd8181c21a2fVirustotal results 27.42% Heodo
2020-07-17Rep_2961999.docdoc cda9436fa557c4829240ea266b287d29715c5d9c9e706886a7755ef20de25ec0n/a Heodo
2020-07-17inf_2020_07_17_3572.docdoc 5e20f76a136e863a01416716795a90ee97d009b2ce86b33ad78019ee5ea647b5Virustotal results 27.42% Heodo