URLhaus Database

You are currently viewing the URLhaus database entry for http://myphamvietnam.net/wp-includes/g74e5554-71-095/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415822
URL: http://myphamvietnam.net/wp-includes/g74e5554-71-095/
URL Status:Offline
Host: myphamvietnam.net
Date added:2020-07-21 08:32:09 UTC
Last online:2020-07-22 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-21 08:34:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 day, 1 hours, 26 minutes Poor (down since 2020-07-22 10:00:27 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22invoice_XVM9_092731.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22INVOICE LXQ977_276688832.docdoc 17848a980123cfbb8869e7859b37b1f0e06e992a2ad751fde0a355d4eb377920Virustotal results 29.51% ZLoader
2020-07-22Inv RRF837_9222822.docdoc 639bdf650ed2329ccbe33f471cc8e6e8e24bc3a1147d446ff0ce5ea0e28ae9ebVirustotal results 28.33% 
2020-07-22Inv_ZCG314_032847212.docdoc 982b974a8a615a1e12c407d581f14151a8e9ba50cff41bd400e8be525e66b506Virustotal results 26.67% 
2020-07-22Invoice QDJ9382_361311.docdoc 4a77f876b6d9a044b69944ac284abd8838dfac4208cdefc8de51907727421d46Virustotal results 25.81% ZLoader
2020-07-22Invoice-LY9_77928329.docdoc 915ef2dcbb13060e972f99c4e495f50d5fb9144271000603ebb86db379223840n/a 
2020-07-22INVOICE OLGH53_664783468.docdoc 26af1552f2b88eccd42e79c091d65086151aa9a26779c42b2d0084e33ca2681bn/a 
2020-07-22INVOICE_TQ24_3508063.docdoc ebec7284e20fdc5a633b8f505fd018ebfdb512a595eaf179e5d77b60d33970b8n/a 
2020-07-22invoice_PWO3_413661.docdoc 840db3615ee06847a75a52b7ca20cb4149291512ac4f268a627f9a8c3379c1bfVirustotal results 27.12% 
2020-07-22invoice NV646_013235979.docdoc 0e544f6935b9f889755f2920a690cfa00909e4ac8c9732ad5735151f2490b407Virustotal results 26.23% 
2020-07-22invoice-AOGH1_221464.docdoc 41a0f5eacd46efb4fbcb759125506684df90da34071ae4ea585b5d15ccd3b25aVirustotal results 26.23% 
2020-07-22invoice WD1302_073208729.docdoc 7476dba24b28d2a074d7e75aea79591f98fbb95b065c91870b5a8198ab615f19Virustotal results 26.23% 
2020-07-22Inv RQZ5_2434330.docdoc f615f977969d02231be115ed31cc86bd74d0348b382f6da944231f573468b960Virustotal results 26.67% 
2020-07-21Invoice-P856_51550149.docdoc 062c45cd22faf032486fa920e68f639cfd2a7b640c0d36d297e6490118729c69Virustotal results 26.23% 
2020-07-21invoice-IIJ81_245075599.docdoc 112aa4be04d85780875343365b40f2fe9351e69dd4756d26a01f923251e17a49Virustotal results 25.81% 
2020-07-21Invoice-LTH46_557461.docdoc bdebdf81b9c2645e41964a4d14720c68258ea89382b1cee103369b6fb9a77103Virustotal results 26.23% ZLoader
2020-07-21INVOICE-QUY5518_96338450.docdoc d9238e5af649fe7ea0572f9699144985895a4c4576ebb77e0e198ea5120f4c20Virustotal results 26.67% 
2020-07-21Inv VCOV2537_533146795.docdoc 29fd633ba82c884e342db1c88a40a28984b2cb2fc5cbb4fdd901a3c6e5850817Virustotal results 26.23% ZLoader
2020-07-21Inv-TF18_038147.docdoc b4e3c557317004de4b83d941a7dbd81648b8383245a1b95806b736eda61b53baVirustotal results 25.81% ZLoader
2020-07-21INVOICE_HX9549_02190311.docdoc fa107254b6f843bb079661702c64654bcdffb1fe41fdcdd125d5d99437e15106Virustotal results 26.23% ZLoader
2020-07-21invoice-415_7031562.docdoc 9f9d6e57c9e3398ca955952e4fcf58321a7f235e18eaafe6aab3b3ddd4e88c7cn/a ZLoader
2020-07-21Invoice-ALUD0489_721727.docdoc 72a76d3c5a30ccf7584528d7bd29ac47062d468d56a417063c19573496089d56n/a ZLoader
2020-07-21INVOICE-VOE54_414119126.docdoc eac069c2098e2a08afb43c1f5aae5878d557e5cef94096cefa93bbe0d04c236bVirustotal results 25.00% 
2020-07-21invoice-N919_836848694.docdoc 3363f1375d1705778c34f83818742724c75fa3c3b13bc2fc131fd95b2d03c8c8Virustotal results 25.81% 
2020-07-21invoice-UJR5890_9928210.docdoc 56508ca86a568105ecfe6df473dd0a40bbb40f66270edb514d83e99e1e6ef0d3Virustotal results 26.23% ZLoader
2020-07-21Invoice PMX5_499463.docdoc 69f98944d3760e294ea601defa72bf8b0ac0c8105267a560426f3c2f3888aff3n/aZLoader
2020-07-21Inv-ZH1_927668.docdoc ebf8a9a8c38f94a2fbf651cb07ad59f7f6be921f637492b72d966c0ba1b359a8Virustotal results 25.81% ZLoader
2020-07-21Invoice REAL7492_51948608.docdoc c7f1f379555ef08082a617234440aebf2a68fe7c55bf8280d333518d22adbb4eVirustotal results 31.15% Heodo
2020-07-21Invoice REAL7492_51948608.docdoc c7f1f379555ef08082a617234440aebf2a68fe7c55bf8280d333518d22adbb4eVirustotal results 31.15% Heodo
2020-07-21INVOICE-B5384_1852080.docdoc 9bd09fd88355a1b20c3268d29be2308057a659c4b96c85a618409ec4b57bd45fVirustotal results 31.67% 
2020-07-21invoice-JY726_9603702.docdoc 9ed17331261676ac56f81432fd0de1293bdc48863867eac50012dff696d69439Virustotal results 32.76% Heodo
2020-07-21Invoice_DP8141_889560.docdoc 33c53ca7807a817b61ed5b3a0a7e0ffe44059f5aac7475b14df784384aba5308Virustotal results 29.03% Heodo
2020-07-21INVOICE_JRA094_0591205.docdoc 5aa42a51f985e6af1419f2043fb37f51a7a1189fda28293d47fed2abb130c86bVirustotal results 30.00% 
2020-07-21Inv GKOZ6063_539350800.docdoc 4de9b5d8be922ee6f95a85aa378d4b78596a0df19e25a0388096ba0831feebb4Virustotal results 29.03% Heodo
2020-07-21Invoice-W382_750527.docdoc 11d9013218c3cfdd117b399765af57f2714a07774b29ab7a0a2b54c48284cbc2Virustotal results 27.87% 
2020-07-21invoice_GGJ5_3236860.docdoc a15083f68d55c92228c997e26d8596bb25b5cf8129f45e98d3c78ded130081f9Virustotal results 27.87% Heodo
2020-07-21Invoice_IWNW97_96769326.docdoc be14def968a7a7ba9caaac07b0784bf90fcc93c6917657fa2aae18ebc3813563Virustotal results 28.33%Heodo
2020-07-21INVOICE_O269_94830584.docdoc 05b1f0822783aa9419a3b13424fb6d31e224e8dad2c84ace8cafa7c1b42a1f3eVirustotal results 28.33% Heodo
2020-07-21Invoice ZEHS100_9011240.docdoc 029bef505d5de699740a1814cba0b6abb685f46d053dea79fd95ba6769e40a6fVirustotal results 27.87% Heodo
2020-07-21INVOICE-169_85796538.docdoc 369c8a3d8a6c68c6b0521061d8b81bdd6a24e898ebef804e811359220d51c31aVirustotal results 25.00% 
2020-07-21Invoice-16_49619170.docdoc 2a76ed46e142b56dacc929cf3fabf2287c2023d0e06e9f5842b23102f584c373Virustotal results 25.81%Heodo
2020-07-21Invoice DUG87_9077298.docdoc ee50b9e1ff6d4b77d99dded74e7e4383725809ffbc7f72c7071ef29911e69e0eVirustotal results 27.12%Heodo
2020-07-21INVOICE-QZF0_659668.docdoc 8f32874205c29ff499e75943e0f6c9b298417cca9166bee485e13f791d6cc4c3Virustotal results 26.67%Heodo
2020-07-21Inv NQ8_93810140.docdoc 6cb24de3cb231233f9a3fd81c726f49ff835992f50c34efc9419c8f2c7fa1d82Virustotal results 27.87% 
2020-07-21Inv-EOTD4_912955.docdoc 4526b97cee7e97d38575c3ccf35f4dbbdbb3b4acf4bc89a5d8afb139c28f7f30Virustotal results 26.67% Heodo
2020-07-21Inv-BH2_37190770.docdoc aa31041b4dcd03e3ad1818d6ca5ac597b999aa6725212a9dfecec97c68100a27Virustotal results 26.67% 
2020-07-21Invoice-QPC0887_080896.docdoc 969b9fcc13e520a48a60d7e65714c495c99ac1a90075aef31a7486070b8bb171Virustotal results 26.23% Heodo
2020-07-21Inv-QBD8_3543455.docdoc 85eb4f995c6972a6e9cf041dda832b20a4b6125403e01e978390d32863a4967dn/a Heodo
2020-07-21Invoice-WQL634_977673.docdoc 2c45f3ecfe38e8675ea0ae2db824e82e654e82aaac7dcb957df5b0b95034730fn/a Heodo
2020-07-21Inv 8709_605280.docdoc f37d602c2d14ef7dade7cd13740d744939c846704065c8d20367a677ce0ad095n/a 
2020-07-21Inv VPG570_718868082.docdoc b7c0c24f3f9f552c499937cca5dcb7a8fbb7bbf600dc1ad43256647401ca3d04Virustotal results 22.95% Heodo
2020-07-21INVOICE UL5_517250.docdoc 7f53ea4c64012caad27163ff00c2aefd9e2dff6a4c5fe488955be018c8af4362Virustotal results 22.58%Heodo
2020-07-21Invoice-P0625_799052.docdoc e25d6ec52f1ed0b91dca39b33e9dd848d324c38938a9d5801490e71d7db15fadVirustotal results 22.95% 
2020-07-21INVOICE-IGNW19_111869089.docdoc eb0997857baec37d1cddca0ae3c7b6c59fb78566eb5faf16035fef12063a3a2aVirustotal results 23.33% 
2020-07-21Invoice-VFQU0_89753046.docdoc e0b1f74edfc82851cded4dcd2efe9482c8272105eb6853b36947bc7ef8510145Virustotal results 22.58% Heodo
2020-07-21invoice-L52_136496215.docdoc e41c70d31b0de9b543804face14735e0e40236bd3f45dd6561f2ab2f37bf44f5Virustotal results 22.95% Heodo
2020-07-21invoice_59_1383144.docdoc 391cf59d4b78c8ae4b705489a8806b14bd1e0e78a977ff7be86e69b6d7b76fbdVirustotal results 23.33% Heodo
2020-07-21Inv-PSHM738_03777394.docdoc 20e4dc6141f8e92848a4f49ae43ac4dfddc7b2f54ac7b257f20539afd9438539n/a Heodo
2020-07-21Invoice_ADX08_816131.docdoc badf4060ed3d5a8f760803d237a17ca4f7d135d25661f96314c2ff92bca1e58dn/a Heodo
2020-07-21Invoice-8_735573.docdoc 7c96c1803f8860f0ecafb733376ee2fd8fffdb3313a7b4dfeab712ff27242d1bVirustotal results 22.95% Heodo
2020-07-21Inv O4877_643715.docdoc 59fdc24661735c738aea0c5ce35581112339c50c9a16a48bdc26694fcc2aec0en/a Heodo