URLhaus Database

You are currently viewing the URLhaus database entry for http://goviet.co/wp-content/LLC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415506
URL: http://goviet.co/wp-content/LLC/
URL Status:Offline
Host: goviet.co
Date added:2020-07-20 20:20:46 UTC
Last online:2020-07-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-20 20:22:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:6 hours, 10 minutes Good (down since 2020-07-21 02:32:09 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21BAL_SA7OK97914FK.docdoc 926e68ce8e0ae5b9d2e935c1fe517533b3dc8cb4aa2250b0fa6ec86af0d78220Virustotal results 27.42% 
2020-07-21C_KN7999276624RB.docdoc 7e1aeb2be52594be4df58400922f10eb753ee56699771180bd21fed441171c2fVirustotal results 27.87% 
2020-07-21I_OKE_070120_CXL_072120.docdoc a6c8655af8c96aef402f4853f9c71b907adc45a533de7e3f9a9517aee1b43c0bn/a Heodo
2020-07-21INV_86291139.docdoc a7f4f8b9dddb70414bfdbbffd5c446c88b517c104a441be19151c8a711133686Virustotal results 27.42% 
2020-07-21N_NQ9834608086IZ.docdoc 229710df49bb17b78fae2414fe4ff138609fdbbe410dc297f49d8b7bf10ad109n/a 
2020-07-20FILE_03699288.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20J_577391588732028001740.docdoc 5ef34d47ef171a2b5cab01782a4a45d9a12f01d70dde381936b6975ca93dfad7Virustotal results 29.03% Heodo
2020-07-20BAL_TY3NAKAZV5SGRL.docdoc 49f90436f418a86b0f4e55e14bcf74793954cc90596ad08dfb6355a1e50a8f27n/a Heodo
2020-07-20Y_IUR_070120_QIL_072120.docdoc 80b27b3a7242ea8cdfbcc0d266c4fe489cc0b035fb614b755e2546c80cdfbed5n/a Heodo
2020-07-20VJ_WPW_070120_JKB_072120.docdoc 86dc2706e8cf0a78688e5a503d6e8db55275a7ec3de655ec33a9db2f6ffeef57Virustotal results 29.51% Heodo
2020-07-20PO_07212020EX.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-20GM0017801646QP.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255Virustotal results 29.03% 
2020-07-20PO_07212020EX.docdoc 53dfc48b5b049b05895bc4e2e5fca037946e69d083cdac2e6c222b76c86f4763Virustotal results 29.51%Heodo
2020-07-20REP_U646SEC9.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dVirustotal results 27.42% ZLoader
2020-07-20INV_ZSI_070120_OHB_072120.docdoc 7b6a3b4d5f51807fa19a536a4a2400dd3279b75a75ba37423ab27c6937aee30fVirustotal results 27.87% Heodo
2020-07-20RKZ_070120_NZC_072120.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20R_84064370.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20VT4763840157ZL.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-20JNUX_PO_07212020EX.docdoc e14b6fe3fd9316a62b7a645ffec63912c50fd312a1bec4536a5abc69d6b33ee7Virustotal results 27.42% Heodo
2020-07-20QUG_070120_OJX_072120.docdoc 4fdba539896383e37ec2383fb569df4f17395dd40115ba8caba62127b7ebe949Virustotal results 28.33% Heodo
2020-07-20DOC_CPN_070120_PPL_072020.docdoc a00bd0c41a60173a7d02bec198e21b3be8ce018289a2120a48b3cea32160de78Virustotal results 27.42% Heodo
2020-07-20BAL_88087349.docdoc 6f07729a0d38233363651ce3760f506ded756ffb5010218df70d03bba767e7d5Virustotal results 27.87%Heodo
2020-07-20INV_PO_07202020EX.docdoc 8811f4498f1b1d8729556a61a5683ce20c4270a64ee5ad0223185110adac5f2cn/a Heodo
2020-07-20X_PO_07202020EX.docdoc c91833370e416710aaca734577f6d2075baa3f204350fe48c155bfc67f6504aeVirustotal results 27.87% Heodo