URLhaus Database

You are currently viewing the URLhaus database entry for http://thithpt.edu.vn/wp-content/uploads/OCT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415959
URL: http://thithpt.edu.vn/wp-content/uploads/OCT/
URL Status:Offline
Host: thithpt.edu.vn
Date added:2020-07-21 10:49:34 UTC
Last online:2020-07-21 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-21 10:50:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 hours, 37 minutes Good (down since 2020-07-21 13:27:09 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21DOC_XRN_070120_WLT_072120.docdoc 9d29290a0e2c6f3801444df8141e4099b9d87d0d3d3ba984bbc9d9684fcb5511Virustotal results 24.59% Heodo
2020-07-21INV_SF6880099188YV.docdoc 9fae422f1e6eaf42b4164526f13a51a3f366b573b191fb013ed934bf90d4a436Virustotal results 24.14% Heodo
2020-07-21REP_XO8782296418MR.docdoc b4f865e3011a63a5b8a0da14876282d97d5144e153f8316025555d276602d335n/a Heodo
2020-07-2102665118.docdoc 76f26be5906a8e19f05aaeb83beb7822cd9f6dff18f4b66782023d320e84c36bn/a 
2020-07-21PO_07212020EX.docdoc 4501457e1fae31cb83a1d2818d169525f75627a017efc573932fd412e6e2c406Virustotal results 24.59% Heodo
2020-07-21W_66064499.docdoc a77f0d09a07d8f85b737d25216501b343e22c4e04a6f88b16dc1ab9ea1b2a222n/a