URLhaus Database

You are currently viewing the URLhaus database entry for https://chigaihoixuanvn.online/o4w5-dxan-6245/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:414226
URL: https://chigaihoixuanvn.online/o4w5-dxan-6245/
URL Status:Offline
Host: chigaihoixuanvn.online
Date added:2020-07-17 20:18:16 UTC
Last online:2020-07-19 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-17 20:20:04 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:2 days, 0 hours, 26 minutes Poor (down since 2020-07-19 20:46:08 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-18INVOICE FHE9_3217851.docdoc 169f03cee2b674a04eb777235895e2e6d94f82785fac8764ebb330df2bf2448dVirustotal results 40.32%Heodo
2020-07-18Invoice-K12_9994165.docdoc 81cd5ce6123449ba648b0d4e9e5b254c223fbec0959ca04f739d278bb49e0761Virustotal results 40.32% 
2020-07-18invoice ZUQ4_466434.docdoc 80e277e15058cc1c440200dfe3163744b701225ecedf6888dc08e9f77df37601Virustotal results 40.32% Heodo
2020-07-18INVOICE-WU00_9558591.docdoc a52dcc23d42ac16e8bd87fd521966710a1a74a4d761e5d2675745d3fa3b0829bVirustotal results 38.71% 
2020-07-18INVOICE_EM34_8952664.docdoc 1930614813330328ea07ab82811cdce5464d3cbde53b3f4efc556b6d710ea453n/a Heodo
2020-07-18Invoice-R776_996567.docdoc 7160087ac3e5c4d46b6584cbcbddcc6ec96376290a7361df015284b62cb3c2acVirustotal results 37.70% 
2020-07-18invoice-N2_411471.docdoc af0485ffa7cb3464b0918c518490268e427e3a768d194cedf1187eefec333104n/a Heodo
2020-07-17invoice_N7_044965646.docdoc 409ffe4576bacde509efa8e950c78e278332d37992587aa8699d6856cf62b119Virustotal results 35.48% 
2020-07-17Inv XY0933_721280093.docdoc ab19da6f740056f36197abf8845d9ccaefbce0a420ecc8c0c4576eb74a108ca9Virustotal results 36.07% 
2020-07-17Inv ZJ66_7927665.docdoc 61a437bbed8e3ac3a4641ce788de7880516f124ad0a3223f107e92fb0cf969eaVirustotal results 36.07% Heodo
2020-07-17invoice-FXUP234_613359321.docdoc f192914a628d9ce6a8a4773d7d61278df8838ff527c1afe97b403d4124a00aa8Virustotal results 34.43% Heodo
2020-07-17INVOICE_MCK6_261696164.docdoc 83f66d992e12fef5ce5f9bd4d34b909c05733fbc574d98eb9524003fd005d738Virustotal results 32.26% Heodo
2020-07-17invoice-VKCP5_034866.docdoc 1e1fb8134d9ede5ca2e5b740ff81ef5e76206eed5933c5c2786ecbfa2dccf624Virustotal results 30.65% 
2020-07-17INVOICE-P75_408110.docdoc f8c49170d4bb1c283994a9144581603bc6b9fe74cdb7f60b32806e6345ed035bn/a Heodo
2020-07-17Inv HMAS9395_797795.docdoc 69fda7852e8bb1536d60567e061a42139a071a604855852101bb0d4d3ffdaff8Virustotal results 27.42%Heodo
2020-07-17INVOICE SS612_602488960.docdoc 4bc9be17841664c17490eef267f70c56282b93df28e99ed18d9707915b7afbc9Virustotal results 26.23% Heodo
2020-07-17Inv_EV541_5818236.docdoc bb6b248bbf5fa806a85edd4cd5580e6d0f24bcda6e0271b88c236cd653601ee9Virustotal results 25.81% Heodo
2020-07-17INVOICE_ASEP77_69246201.docdoc 0c6fdbb83539fe76c8db143e036c4eca7464535d8b900318b5c0870b3b8024a7Virustotal results 25.81% Heodo
2020-07-17Invoice_AZL55_5927086.docdoc 82c401148abefde60b6f557d36ae313e40d65cb3902f6d0d4e94a14308a7e410Virustotal results 29.03% Heodo
2020-07-17Invoice-SPZC2445_058324065.docdoc e37ed35ad92d7f72dd82ba694d4ff1b2811ed68857e2402e20f46bbeebbf8b7aVirustotal results 25.81% 
2020-07-17Inv-DUQK4789_976855125.docdoc 11fbc2e9daf9c1bd1e9c72df539bd64ca9b4bf3c2915ca55b64757930b57266en/a Heodo
2020-07-17invoice-Z646_6000166.docdoc 30dbdd3a8b6d749b9e0c864af4e1fff0841372f4af156df052c1a55e17a5c8c3Virustotal results 25.81% 
2020-07-17INVOICE-K7_186075.docdoc d92cb1bdecd2ac46696a43f0a13682eddfdab906ae7430887a5dfbe33174b9d4Virustotal results 26.67% 
2020-07-17Inv-WRQ7_139926099.docdoc d0fd2d71c1267d3ad20bbc348b043e49ea7eda9acbfbc30e64dafb296a1a9011n/a 
2020-07-17Inv_619_641723.docdoc a0d3eeaae4f459d8f244b90d97b4b8a40bca8daae995e676e4a4307e98a8e2bbn/a Heodo
2020-07-17invoice_CO36_558073080.docdoc 2c7595169fd5112718de088c5732bbd01072fc38297c809cb782f5a5dbfd6a87Virustotal results 25.00% Heodo