URLhaus Database

You are currently viewing the URLhaus database entry for http://demo.mku.edu.vn/htkh/bcrwjikl-jm-42/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417619
URL: http://demo.mku.edu.vn/htkh/bcrwjikl-jm-42/
URL Status:Offline
Host: demo.mku.edu.vn
Date added:2020-07-22 02:06:18 UTC
Last online:2020-07-28 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-22 02:08:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:6 days, 7 hours, 30 minutes Bad (down since 2020-07-28 09:38:09 UTC)
Tags:doc emotet link epoch3 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23Inv_1_443666.docdoc 548e4293f740ef77ecf074a7e8eb5ee8659eb565fd08db697ca873dc770c11b0Virustotal results 46.67%Heodo
2020-07-23Inv_XAW4130_127296.docdoc cf2ba9c49c359ebc0d9ce182b928db8e967b6720c8d531c8366b2420ce778d21Virustotal results 42.62% 
2020-07-23invoice_KG3_02472537.docdoc 49e8d0e91070520182b76f279d10dea2f17e87c7f69e61352db25d5acfcc0be7Virustotal results 43.33%Heodo
2020-07-23Invoice_8_35746710.docdoc 178044a701a9ec991aaa5694350ff4ee08ef6f723628b3277c9a24627c4c8d1bVirustotal results 44.26% Heodo
2020-07-23Inv-KBPR9_45783759.docdoc 0f606025efc6f971911340fc74c45fc88123d4339cddeb43ce0a1a019768e3c9n/a Heodo
2020-07-23Inv-YL0_15154440.docdoc df314d2431bc91e51d22c2f55c6b9de5577ac0129f93014698c3e17546ae0867Virustotal results 40.32%Heodo
2020-07-23Invoice-YHH345_410244.docdoc 7b25bdeb4bdd1095c4328d3726aaffb2b6b32fb4c28539786017e3d4f1016f52Virustotal results 40.98%Heodo
2020-07-23Invoice-YHH345_410244.docdoc 7b25bdeb4bdd1095c4328d3726aaffb2b6b32fb4c28539786017e3d4f1016f52Virustotal results 40.98%Heodo
2020-07-23INVOICE OF5594_881349943.docdoc 823bc611785f0ac57c609d89af04775d2555e96de7529cb5c367e4690c08f6eeVirustotal results 41.67% 
2020-07-23Invoice_423_167611095.docdoc c8974949fec3e295b7d7e7844cdb17d5931a697690a6be15b4863e787931d386Virustotal results 40.00% Heodo
2020-07-23invoice_TNCJ690_528853.docdoc e2796110338cf892ecb47cb8baeafa186dabd1403514af5d5a470c2561c59d11Virustotal results 37.70% Heodo
2020-07-23Invoice-ZEP062_9453370.docdoc cd246dc83c181223acbe8487d25a97d5c433c31b36f8fe625f2814ca8d28a6c3Virustotal results 44.07% Heodo
2020-07-23Invoice-ZEP062_9453370.docdoc cd246dc83c181223acbe8487d25a97d5c433c31b36f8fe625f2814ca8d28a6c3Virustotal results 44.07% Heodo
2020-07-23Invoice_PL27_384704115.docdoc eb8252a2dd0e7e0f44a6b26fb09abb04ef9a618d216f46a9c1525a55350766e9Virustotal results 41.67% Heodo
2020-07-23Inv T0_08194466.docdoc 3509f671940107c4ce10122e95808937ef8a81e9452812ee660cdd2df62af3b2Virustotal results 40.98% 
2020-07-23Invoice-NCFC225_703538.docdoc c8bc8587d3706f659ce2dbd1c22be268adad0f5f8c4c7be78ff6b4b17c3f1279Virustotal results 45.00% Heodo
2020-07-23INVOICE-RT023_9219426.docdoc e96a19dec04fc49f1360224fea7d16ee6c04d29b296500a3b7edc87d31a925fbVirustotal results 41.67% Heodo
2020-07-23INVOICE 016_215618.docdoc 8699c115f17ea8f5ff05ba03ec55c657a076e5dff4f23802b87fb9d012f179d8Virustotal results 41.38% Heodo
2020-07-23INVOICE-KCUT0_688567.docdoc 5ecb66cb399d319d7c2e24a9ae1e427ee2b10ccd3da9b2a2266dd764ba29cd16Virustotal results 41.67% Heodo
2020-07-23Inv_UB5193_03587127.docdoc fc138a4add108557757b357a4de2c8c2b60832c018e4ebabf099a4f63121dff6Virustotal results 40.98% Heodo
2020-07-23INVOICE Y8_371496.docdoc b84bcc1db705ebab3793f52dcf633d1ad8ad2a9b7c96dee5daee12d7d4be0375Virustotal results 37.70% Heodo
2020-07-23invoice-EG2785_7568189.docdoc f815f1d2c10f89e966e1637e1d1478a36c5c8c8ceb852eefaa2247c44f10b9fdVirustotal results 41.67%Heodo
2020-07-23INVOICE-TO52_8499557.docdoc ec054f61bce05bdbe5b35d954f9e1869d873b720b529dabb46a862550a0f0ba4Virustotal results 42.62% Heodo
2020-07-23INVOICE-KFZ0_969610790.docdoc d0386cd66debdb22584ec18ea9ea4d42d8d7ead5e0da33351cdaa7c4a8b2aa2dVirustotal results 40.98% Heodo
2020-07-23invoice-139_5969018.docdoc a3d1d2388010c1c76482dd7e13f9a74e0944e3cc5d4058aeaac35a55ae6226d0Virustotal results 40.00% Heodo
2020-07-23Inv ZGGR4_5250285.docdoc 3ca7f44149bb7302e4e24ee98c1720865e34416a3cc52d005b3a52fa51ff415bVirustotal results 39.34% 
2020-07-23invoice UPG18_03219821.docdoc 201e851d0a87ce253787d17e5263362eda13f891604567b19154f6edb7a18c00Virustotal results 40.00% 
2020-07-23Inv_SX03_023883410.docdoc 908cb95829b5e7219efcf041c922c2633fe8c1bd3b38a4ea6536d80dddef9a54n/a 
2020-07-23invoice_R53_81931578.docdoc c0689da51a6ac61c10510453b058273111d2eb315cf24c9233f055548e838d7fVirustotal results 40.32% Heodo
2020-07-23INVOICE V6_9277829.docdoc b236919208f57395e50a47cdf065b0c6d1be7f45dd4e4f837582d02498583ecdVirustotal results 42.62% Heodo
2020-07-23Invoice_UFXX289_2671472.docdoc 5da4ed7ce6e6938d87f5b5d3add5191ebefb861c31ad2d43146c8cba80302610n/a 
2020-07-23Inv_D02_031510472.docdoc f752b3c15c7f8300d70d3d0e9680892e4dc0c6ccc7b5cc1eff59e8568a4288ban/a 
2020-07-23Inv-QLQ1960_7042373.docdoc 83d89d7daf246921a8dde2e54e9e1ea505707f24f069a02034e2fe628c586239Virustotal results 44.83% 
2020-07-23Invoice-VGJX12_219337.docdoc 8e10c3f0dbd69fb4a1472eb81dc007ed1e172f9906a7fa4b63ee8afd494704e1Virustotal results 40.68% 
2020-07-23invoice-NHTG4_763328279.docdoc ece2505e3191bc554dbab52d9f76fc6f723acededca76a54df44a45efe065f8dVirustotal results 42.37% 
2020-07-23invoice 2_072464.docdoc a7eba5ce690c5078cfc8875f5a8a07cdf7b8fe15a427b22b2620462b04c4558cVirustotal results 40.98% Heodo
2020-07-23invoice-FSY89_1093170.docdoc 6e8bff5d060f35a5e75bd5b6772e3d5d52f71ec00665d6384beb8f30c8d80a07Virustotal results 40.98% Heodo
2020-07-23Inv YUEK47_44198813.docdoc 660c977559837c11b18b4131f3459734a2e160602bbed412b7892829fe0c0fb9Virustotal results 40.00% Heodo
2020-07-23INVOICE-LFL1_5149198.docdoc f9ec4de185e104c1bc417152e6146da999dada960c014f2b7b9eeefda33ab5b6Virustotal results 42.37% Heodo
2020-07-22Invoice-AAL4_1013759.docdoc 7e10a0e92fcdcd90d995ee6b0b0059e7a879145f512a34f8f80deb336c83fbcdVirustotal results 39.66% 
2020-07-22Invoice-DL02_76139204.docdoc 2dd5a90bf7f556f0c8a9a024f6ac592b4c6654f59b7d663c5b313e77757702efVirustotal results 39.34% Heodo
2020-07-22INVOICE PCKF673_69626130.docdoc e7e5b2bd8ae7a7a72ab0a1c83bf524664c11f0a69882e9b1a57afaf1e50a97b3Virustotal results 40.00% Heodo
2020-07-22invoice-KDG0066_3070181.docdoc 8838e7dc1e3c25e5b499354735a74fa697472421dba5896b535973b079380210Virustotal results 37.10% Heodo
2020-07-22Inv_SA99_464513.docdoc bfd7374a797a6c3e77d704c3ec20c246e532ab967cb7cec9f3f77f386bdd7455Virustotal results 38.71% 
2020-07-22Invoice-A8_074998288.docdoc 9906a5bee4b9e562812454fe546581f17dcea82db95ce7b846c50d1537cb8316Virustotal results 37.70%Heodo
2020-07-22Inv CWZ13_815634449.docdoc a8377439065663a204f302e8b1ae0aa1d880b86780a7a8ddf0c2569a8a78ef0eVirustotal results 37.70% 
2020-07-22Invoice_EIH5089_28415584.docdoc abb692721c19ff5f382ccfc5bd6ce5301433d4ff75f8745e73d8fa929b4ab1aeVirustotal results 40.98% 
2020-07-22Inv_IXCO5946_25100258.docdoc 81974e12641a56b689a90de529d306a53cc4570ae79cf6c7e34b4aa15345babdVirustotal results 38.33% Heodo
2020-07-22Inv-UH4_608245.docdoc 7757df52299b5b7d7d83f3b72cf1fc8415dd72f90ef93160a30e5270d9528d0cVirustotal results 38.33% 
2020-07-22INVOICE SNJQ1513_289039.docdoc 4ad523f8ede129fc5dcca2c0ea903e7cd1331de8838dc00c39907461a91d8241n/a 
2020-07-22Inv_BG9791_5449065.docdoc 16c6a9dd4a72829040a232b03b8dec183f1b62ba3a8fa829760e83ce534755aaVirustotal results 39.34%Heodo
2020-07-22invoice-LU5199_26402912.docdoc d8604cc57ed2635d1426b6baf81d79cd5b5a14e28bdb492c2349fe6652d74acbVirustotal results 39.34%Heodo
2020-07-22INVOICE-AN69_84066781.docdoc f4d6bd934ef834677a5ce5ec7204eeed8160c5898f51669c234b563c5ea13d7cVirustotal results 36.67% Heodo
2020-07-22INVOICE-GHTE7733_167114.docdoc 8d5403870d67fd083d92f1d72328054f16e6dc6d0bb546e03cbd7ae747b219e1Virustotal results 37.10% Heodo
2020-07-22Inv VBK33_8803516.docdoc f5edd4853a9bee8bfe075dfc71946ad2c183ebf260cb065f843190c91e30a913n/a 
2020-07-22invoice-U4_0187814.docdoc e09095837eb8aed55d515c792e0b53dc27997b561883f122d7aa2f1875b1a063Virustotal results 37.70% Heodo
2020-07-22Inv_OH3906_50171374.docdoc cd51ca27f85c3b99bce83221b135a984e5dc890b9f3080b11e8add5bdb4456f9Virustotal results 37.70% Heodo
2020-07-22invoice_HGVH150_501799.docdoc 5db70e20af4b8d11edea41ba303cadc90656548fc1d67af334821d29e1415756Virustotal results 37.10% Heodo
2020-07-22INVOICE T741_3067116.docdoc 563ac96605238befb0600be0cab8eeb129c10f801a2f85cbdc868ce1ab487462Virustotal results 36.07% 
2020-07-22Invoice_QJDF0_824358.docdoc 4ba900dd18d66271ab47157940947389df7558cfcf0bcb2d2907868ed430171fVirustotal results 36.67% 
2020-07-22Inv DGZ074_293761631.docdoc a5fb8475fd26e5f4bfc52a2d8cee048ee2e810a374067df326520c3a31eced4dVirustotal results 45.90% Heodo
2020-07-22Inv-RDS62_2340747.docdoc 7ee1b548ad88bdfbae29e66d5a1e9fa8da71ab726c3baca04e3167bf544c87c3Virustotal results 47.54% Heodo
2020-07-22invoice NFDF618_22858175.docdoc a673367d1b59b0dc8e2baadcc7b82bab3cd5366208e024034a3f982be198b3a3Virustotal results 46.67% Heodo
2020-07-22Invoice 8_153943.docdoc 8f693cea85026bd7f34d4c5d2684885ec3c54c17bdf61287ee946216b42d6d5dn/a Heodo
2020-07-22INVOICE_NLYE185_32907058.docdoc 917e149c839d6cd0a4a68b4a9618a808b51b1edb3c526720c7939e845b81cc86Virustotal results 45.90% Heodo
2020-07-22INVOICE-FRX586_83340779.docdoc 37a8b5c5329497b21a600a6f9f8f7f3473738d3223b61fcabf5adb9b8967b922Virustotal results 44.26% 
2020-07-22Invoice-LCV8_341881.docdoc 49d6ae813b058b68b4990fa96999b95c9bac06686eab7358e4d16c9bafc1d601Virustotal results 45.00% Heodo
2020-07-22Inv 754_2759676.docdoc ad3f9edca00ae86f0b1a643381116ecf1eb6bee87363422d50e4b348f5b5adc6n/a Heodo
2020-07-22invoice_U793_855769624.docdoc d1c90cc9ec1794107bee8f0ebeb6f3b8ee5e6b53f03c6cc5bc5e3abc4d8d9808Virustotal results 45.90% Heodo
2020-07-22Inv-19_5372668.docdoc 50d702efc9b1c24c7958be8fa37f14e8343d36ef16d5de67c4aee63bb6d00047Virustotal results 45.00% Heodo
2020-07-22Invoice_497_491799.docdoc 70c88e074aef925dd90c000e760c886df1a836abdc0d56d52407d98229f6fa43Virustotal results 45.61% 
2020-07-22invoice-BEPW959_1676547.docdoc 62ad8ba146bad8695793483ab3a14ff790cd87f9a35e5657f0ff7d124acfc3fdVirustotal results 45.16% 
2020-07-22invoice_FUD5356_5193445.docdoc 4866f8481b362767c8c58bb2ba099270e314d22c1d09df4e3afcf0d6038961d7Virustotal results 44.83% Heodo
2020-07-22invoice-P88_960810557.docdoc 7b1dc8d5f59e640c9cb2377a9b62ca2ab6b5ed3d86817d886d4652871065521dn/a 
2020-07-22INVOICE-G4727_529010804.docdoc 0a359651e943b30173415d91a0886f3c0bcbb1acded5dd7ab4333651f3c99687Virustotal results 37.70% Heodo
2020-07-22INVOICE Y5_85298355.docdoc 22e7ebd85759dfeb93f2368769a68205d61b272401227655676fcf4bb46f0been/a Heodo
2020-07-22invoice-B905_858556.docdoc 46f4bc23b97723b4e8c1acca6f9d425f7f832fb1ccd2c34c6e0b4cc8eaa4260dn/a Heodo
2020-07-22invoice 9141_887782.docdoc c2e63ea82a2d878192098e0d4a0b6509bb986254ad2f252bb49475e86982ebf7Virustotal results 37.70% 
2020-07-22Inv-XOK754_718456871.docdoc 2cb722c2b058a79fed6fba9442aa0b2d17c2460c71b9b3fd749b300772ce2c1bVirustotal results 35.00% Heodo
2020-07-22Invoice MI4230_09369585.docdoc 4362e6ba330f2fd89b96c0a2bd7407ca83f5c6678f765731244788aa490160cdVirustotal results 32.79% 
2020-07-22Inv_BEJ8216_286186196.docdoc ac88ce74a14a0b5a78e6bdf86ffa9bd0f2770cd7255210ffed47affc2f220dc7Virustotal results 30.00% 
2020-07-22Invoice_EV6_38230378.docdoc b7a4f4d8be523413a3c82837cdebb94f458ba431eef63244fba598a38afe6f98Virustotal results 30.65% 
2020-07-22INVOICE 8_044961.docdoc 7ff0263018fb67bcdd18c7b43f1b635db5983b85aabdefaf71b7d1e313f24fefVirustotal results 26.67% 
2020-07-22Inv-YLIQ10_34291198.docdoc 18fe339a03b33e6b2fbe0b44287c1a8869d8b21af3ce76b437a1243ab5601102Virustotal results 28.33% 
2020-07-22Inv_RPK6_26558667.docdoc 6734a3ae13c38e8fd44de930f8cf0da0bda0a3afec46ea9a8899e61b8762ecaaVirustotal results 27.87% Heodo
2020-07-22invoice_WSYL2411_118265.docdoc 861b65f983134a2bfdd08f1d9ab5e3d5be1767ec36bda8445d5f663ba79c82edVirustotal results 28.33% Heodo
2020-07-22Invoice-XGU134_0880813.docdoc 94471d47c57a7f90fe9b6c7d2784661dc321de17e8f498074f29943779764f6an/a 
2020-07-22Inv-ZUR0_917503438.docdoc aff7ea1878a6b5020301cebb920e91ba8ad84bbcd4d7312fe9c54188cbfc55cdn/a 
2020-07-22invoice FPUJ81_469930.docdoc 02c7fd8ed2ff395eb8c7eb3caca1e0cec299f4db7480e6d19829069ce541bc7dVirustotal results 27.42%ZLoader
2020-07-22Invoice-NA55_5385213.docdoc c679172a57262c3c69a11b8b2f0c2074c71f3a338be835c38c72557cefb2bc38n/a ZLoader
2020-07-22Invoice-0335_099618312.docdoc 962dfcf9dbe2a5f4e39e1ad1100caa0da7d50a87928be0985eb4014a51f3ebc5Virustotal results 26.67% ZLoader
2020-07-22invoice_BATI30_448044.docdoc 4859caa197be70c49719788cc836b4ce719613e177ba187b99c0a293227b8011Virustotal results 27.12% ZLoader