URLhaus Database

You are currently viewing the URLhaus database entry for http://gdtsolutions.vn/wp-admin/fPatzvm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417748
URL: http://gdtsolutions.vn/wp-admin/fPatzvm/
URL Status:Offline
Host: gdtsolutions.vn
Date added:2020-07-22 10:49:12 UTC
Last online:2020-08-08 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-22 10:50:03 UTC to abuse{at}a2hosting[dot]com)
Takedown time:16 days, 22 hours, 22 minutes Bad (down since 2020-08-08 09:12:39 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-23INVOICE 258_079029718.docdoc 548e4293f740ef77ecf074a7e8eb5ee8659eb565fd08db697ca873dc770c11b0Virustotal results 46.67%Heodo
2020-07-23Inv-FX773_218141.docdoc 49e8d0e91070520182b76f279d10dea2f17e87c7f69e61352db25d5acfcc0be7Virustotal results 41.94%Heodo
2020-07-23INVOICE-UCG3639_7975726.docdoc fd1b363068e21fa7a3e86cc0aa6134bfa46a640d70bcef686f19f57f54340f6bVirustotal results 44.26%Heodo
2020-07-23Invoice_YO302_616458.docdoc a7eba5ce690c5078cfc8875f5a8a07cdf7b8fe15a427b22b2620462b04c4558cVirustotal results 42.62% Heodo
2020-07-23Invoice-T66_571188.docdoc df314d2431bc91e51d22c2f55c6b9de5577ac0129f93014698c3e17546ae0867Virustotal results 40.32%Heodo
2020-07-23INVOICE_EDHP4405_328774822.docdoc 7b25bdeb4bdd1095c4328d3726aaffb2b6b32fb4c28539786017e3d4f1016f52Virustotal results 40.98%Heodo
2020-07-23INVOICE_EDHP4405_328774822.docdoc 7b25bdeb4bdd1095c4328d3726aaffb2b6b32fb4c28539786017e3d4f1016f52Virustotal results 40.98%Heodo
2020-07-23INVOICE-Z22_8900325.docdoc 823bc611785f0ac57c609d89af04775d2555e96de7529cb5c367e4690c08f6eeVirustotal results 41.67% 
2020-07-23invoice XLO1416_100992.docdoc e2796110338cf892ecb47cb8baeafa186dabd1403514af5d5a470c2561c59d11Virustotal results 44.07% Heodo
2020-07-23Inv-YSMY4710_35020219.docdoc affd22130c658e33e153da21dacd828359afe4c1bee7d621def53e3c7fb5a712Virustotal results 42.37% Heodo
2020-07-23Invoice TDR6_608954.docdoc 88cca8fc8a65b95ca50edf7f8f1bc19f7c7d91935a589e7a4a88b42ea443b603Virustotal results 40.32% 
2020-07-23invoice P2855_4165344.docdoc 3509f671940107c4ce10122e95808937ef8a81e9452812ee660cdd2df62af3b2Virustotal results 40.98% 
2020-07-23invoice-ZBBI899_272265509.docdoc e96a19dec04fc49f1360224fea7d16ee6c04d29b296500a3b7edc87d31a925fbVirustotal results 41.67% Heodo
2020-07-23Invoice-6_077664.docdoc 8699c115f17ea8f5ff05ba03ec55c657a076e5dff4f23802b87fb9d012f179d8Virustotal results 41.38% Heodo
2020-07-23Invoice ST94_83894815.docdoc fcdbd1df2994aa81348459cba048cb91f2d0c779911d4abd1ac45bd540eae640Virustotal results 40.98% 
2020-07-23Inv_80_973384950.docdoc f815f1d2c10f89e966e1637e1d1478a36c5c8c8ceb852eefaa2247c44f10b9fdVirustotal results 41.67%Heodo
2020-07-23Invoice_3634_9590633.docdoc ec054f61bce05bdbe5b35d954f9e1869d873b720b529dabb46a862550a0f0ba4Virustotal results 42.62% Heodo
2020-07-23Invoice-LGGV03_91812538.docdoc cd39e541197218472f3e09dd2b1ba14076247e64e439a47cdc2824aae02f6f66Virustotal results 40.98% 
2020-07-23Invoice-KATZ06_007001.docdoc ec08cea8c07370a30ceaf1877b95d6a4e45728f9f915dfe0e5572c632fdf3331Virustotal results 39.34% Heodo
2020-07-23Invoice-MH52_681006799.docdoc 3ca7f44149bb7302e4e24ee98c1720865e34416a3cc52d005b3a52fa51ff415bVirustotal results 39.34% 
2020-07-23invoice-GP976_771455849.docdoc 201e851d0a87ce253787d17e5263362eda13f891604567b19154f6edb7a18c00Virustotal results 40.00% 
2020-07-23INVOICE-OSCX1_03654804.docdoc 908cb95829b5e7219efcf041c922c2633fe8c1bd3b38a4ea6536d80dddef9a54n/a 
2020-07-23Invoice-KHX105_500805222.docdoc abbc35112edb6b5259ca0c4d807e75f7faf0e59f60b86ba07082acefd30a9f82n/a 
2020-07-23INVOICE-7_204300327.docdoc 5da4ed7ce6e6938d87f5b5d3add5191ebefb861c31ad2d43146c8cba80302610Virustotal results 40.68% 
2020-07-23Inv-YS8_851765518.docdoc f752b3c15c7f8300d70d3d0e9680892e4dc0c6ccc7b5cc1eff59e8568a4288baVirustotal results 41.67% 
2020-07-23invoice Y73_75277369.docdoc 9ca51f73dcdb08b4450ae42c0c1a49859ec30c989c6c32c7cf70cfdac515e687Virustotal results 41.38% 
2020-07-23Invoice-EQA27_7489229.docdoc 83d89d7daf246921a8dde2e54e9e1ea505707f24f069a02034e2fe628c586239Virustotal results 44.83% 
2020-07-23invoice-0_1672971.docdoc ece2505e3191bc554dbab52d9f76fc6f723acededca76a54df44a45efe065f8dVirustotal results 42.37% 
2020-07-23Inv_W3797_1565889.docdoc 1d786d897347069b1e0ba3ad92c8fff6d7258a2599cfc50445250478e2c1e65aVirustotal results 41.67% 
2020-07-23Inv-8879_107929.docdoc 6e8bff5d060f35a5e75bd5b6772e3d5d52f71ec00665d6384beb8f30c8d80a07Virustotal results 40.98% Heodo
2020-07-23INVOICE_6_465597.docdoc 660c977559837c11b18b4131f3459734a2e160602bbed412b7892829fe0c0fb9Virustotal results 40.00% Heodo
2020-07-23invoice-466_234026739.docdoc 85f78e5396e9bdcf5a8132a8a816093d283c992e100583f4d53dd02e4aeba0e5n/a 
2020-07-22INVOICE_U10_119169.docdoc 7e10a0e92fcdcd90d995ee6b0b0059e7a879145f512a34f8f80deb336c83fbcdn/a 
2020-07-22invoice_C2_258506.docdoc 99800fcb85d6728c00375fdb6dd54114e6673d809fbf90d537c261b287a599eeVirustotal results 38.71% 
2020-07-22Invoice_3_2884400.docdoc 2dd5a90bf7f556f0c8a9a024f6ac592b4c6654f59b7d663c5b313e77757702efVirustotal results 39.34% Heodo
2020-07-22invoice_369_4300461.docdoc 121ed8988b04cd935a814c1721a9f0d568268c9771e9a54104e9d603bfb63735Virustotal results 40.98% 
2020-07-22invoice_ABHR6221_416386.docdoc e7e5b2bd8ae7a7a72ab0a1c83bf524664c11f0a69882e9b1a57afaf1e50a97b3Virustotal results 40.00% Heodo
2020-07-22invoice CN638_6892057.docdoc 8838e7dc1e3c25e5b499354735a74fa697472421dba5896b535973b079380210Virustotal results 37.10% Heodo
2020-07-22invoice-TPO31_0642827.docdoc bfd7374a797a6c3e77d704c3ec20c246e532ab967cb7cec9f3f77f386bdd7455Virustotal results 38.71% 
2020-07-22Invoice-334_0043157.docdoc cfc85cd85d337fa57852443be31264f9ca2cb5805099faf22026ca29baeffb12Virustotal results 37.70% 
2020-07-22Inv-PTR8_48725692.docdoc 95f36b53d2e8d7c4fb0b0eceb4901dfa8b31a624e2d26fabaacfcde9ab31be06Virustotal results 40.98% Heodo
2020-07-22invoice-IGJI8_5903912.docdoc a8377439065663a204f302e8b1ae0aa1d880b86780a7a8ddf0c2569a8a78ef0eVirustotal results 37.70% 
2020-07-22Inv-URB7848_20637287.docdoc abb692721c19ff5f382ccfc5bd6ce5301433d4ff75f8745e73d8fa929b4ab1aen/a 
2020-07-22Invoice_YISP2691_086566.docdoc 81974e12641a56b689a90de529d306a53cc4570ae79cf6c7e34b4aa15345babdn/a Heodo
2020-07-22Invoice_GVC0391_344500.docdoc 4ad523f8ede129fc5dcca2c0ea903e7cd1331de8838dc00c39907461a91d8241n/a 
2020-07-22invoice-XP88_6388389.docdoc 16c6a9dd4a72829040a232b03b8dec183f1b62ba3a8fa829760e83ce534755aaVirustotal results 39.34%Heodo
2020-07-22invoice-D4019_5682984.docdoc 73ca49f367f9ccc5d7afeb6979409e1e116a8ff24d143b7cda1482204e8a12c2Virustotal results 41.67% Heodo
2020-07-22Inv-Q81_347746552.docdoc d8604cc57ed2635d1426b6baf81d79cd5b5a14e28bdb492c2349fe6652d74acbVirustotal results 39.34%Heodo
2020-07-22Inv-RWR1519_248609.docdoc f4d6bd934ef834677a5ce5ec7204eeed8160c5898f51669c234b563c5ea13d7cVirustotal results 36.67% Heodo
2020-07-22Invoice L0_569652713.docdoc f5edd4853a9bee8bfe075dfc71946ad2c183ebf260cb065f843190c91e30a913Virustotal results 40.68% 
2020-07-22invoice-KR528_07655765.docdoc dba1fb0199bb0442107b66f5a8b4b1ce64d7ad603276a129789620d58eb4607cVirustotal results 37.10% Heodo
2020-07-22INVOICE FAQ8752_24287895.docdoc 8dfca61cebea589f6fb698dc042cc4e98c14f5aeebc8ab10c8a8ae02882073a0Virustotal results 37.10% 
2020-07-22INVOICE_YM0639_396718.docdoc e09095837eb8aed55d515c792e0b53dc27997b561883f122d7aa2f1875b1a063Virustotal results 37.70% Heodo
2020-07-22Invoice-WXO7_91096419.docdoc cd51ca27f85c3b99bce83221b135a984e5dc890b9f3080b11e8add5bdb4456f9Virustotal results 37.70% Heodo
2020-07-22Inv-ARKO5_664804326.docdoc 502e60db49d073ac974289badb5c93a067667aedba768f5ad734a28f0bfce643n/a Heodo
2020-07-22invoice-YLW5_820345.docdoc 3b0668d557cfedcfb944c24245f1dcd5bde35c04ffa17d9b93a14d2b7c443768Virustotal results 36.67% 
2020-07-22Invoice PLBI847_30017430.docdoc dd78f1cb130d5925aeb8807db5ab75a25c6da9a6a549faad6a777bf8123fdf2en/a 
2020-07-22Inv K768_8387480.docdoc a5fb8475fd26e5f4bfc52a2d8cee048ee2e810a374067df326520c3a31eced4dVirustotal results 45.90% Heodo
2020-07-22invoice_EDWC980_484235.docdoc 26f3e277ea85db3dec692fde12c546a1d30d7a4e69ea6058d44afd3d5007af5fVirustotal results 47.46% 
2020-07-22Inv-GUO8742_939343.docdoc a673367d1b59b0dc8e2baadcc7b82bab3cd5366208e024034a3f982be198b3a3Virustotal results 46.67% Heodo
2020-07-22invoice-803_123823.docdoc b668f3bb2053f6f4f3f086872f01062151d9f3b3b57b5d57607a783f729069c1n/a Heodo
2020-07-22Inv_PIOZ476_097198.docdoc 917e149c839d6cd0a4a68b4a9618a808b51b1edb3c526720c7939e845b81cc86Virustotal results 45.90% Heodo
2020-07-22INVOICE_VM6_9637143.docdoc fe367bec6dccd72f2750717e199f6ad3b77770d93898cfaa3ccc1371d351cb31Virustotal results 46.55% 
2020-07-22Inv LPO1687_0820687.docdoc 49d6ae813b058b68b4990fa96999b95c9bac06686eab7358e4d16c9bafc1d601Virustotal results 45.00% Heodo
2020-07-22INVOICE-5800_3071212.docdoc ad3f9edca00ae86f0b1a643381116ecf1eb6bee87363422d50e4b348f5b5adc6n/a Heodo
2020-07-22Invoice 297_3125029.docdoc 8aaea2227bcc24ea490c2eb6d0ab20fee60990d4c9e86fbf7b2b9d669d2c2629n/a Heodo
2020-07-22Inv_S7486_775561338.docdoc d91be34190b9b89643df001c84f53e81f31f141643b13090479ad89306a4fae0n/a 
2020-07-22Invoice_QBO8817_140029.docdoc 70c88e074aef925dd90c000e760c886df1a836abdc0d56d52407d98229f6fa43Virustotal results 45.61% 
2020-07-22invoice-NTL81_914295066.docdoc 12fedc0198239168dddc2f3f0f3f43434c39e6531145a23f7342a261cae4f0e5n/a Heodo
2020-07-22invoice_454_800830481.docdoc 4866f8481b362767c8c58bb2ba099270e314d22c1d09df4e3afcf0d6038961d7Virustotal results 44.83% Heodo
2020-07-22INVOICE-RZH077_633685.docdoc c89b170fea78126847d599a493f18d47d967ca36d121d9e9ed71fb87e37172e2Virustotal results 44.26% Heodo
2020-07-22INVOICE-HPM013_468640.docdoc 47be8acdf14103a9c4f2b0e6b620ee5740669dd045e17a688e2480097be809b0Virustotal results 40.98% 
2020-07-22invoice DFFQ889_6173020.docdoc 9f61c634155e4c4c25cda79ab4da536afe7bfeeb879754985ea6bb196ee0272dVirustotal results 38.33% Heodo
2020-07-22Invoice ALC8314_9277664.docdoc 393ac27aa81e021260be2c3de9507d953b3d57f2dfd0ebee96d4a18af210b982Virustotal results 28.33%Heodo
2020-07-22invoice_G7_2485539.docdoc ff44b1d144fb3343d7d7580652077fadeb72bcac55733df8fad986203c3e15a4Virustotal results 35.00% 
2020-07-22Inv 6_603275035.docdoc 2cb722c2b058a79fed6fba9442aa0b2d17c2460c71b9b3fd749b300772ce2c1bVirustotal results 35.00% Heodo
2020-07-22Inv D3_36344673.docdoc 8bf0f63918707260860836fd1bae7c3366cd110c8a1299c064475020d837311bn/a 
2020-07-22Invoice_EFZA613_344068756.docdoc ac88ce74a14a0b5a78e6bdf86ffa9bd0f2770cd7255210ffed47affc2f220dc7Virustotal results 30.00% 
2020-07-22Invoice-ETU872_6548397.docdoc b7a4f4d8be523413a3c82837cdebb94f458ba431eef63244fba598a38afe6f98Virustotal results 30.65% 
2020-07-22invoice-63_783565314.docdoc 7ff0263018fb67bcdd18c7b43f1b635db5983b85aabdefaf71b7d1e313f24fefVirustotal results 26.67% 
2020-07-22Inv-E45_841915473.docdoc 957cebb6f6751d4233f9c5ee7a4f3c1bd643257070d4bd13eae482daf82dece6Virustotal results 29.51% Heodo
2020-07-22Inv-T0_27545583.docdoc a69ea13a804925a2c446c80a8a9ee6b20385313190c2a8f84083ee75dc3c961en/a Heodo
2020-07-22Invoice-RQZF5_159626.docdoc 6734a3ae13c38e8fd44de930f8cf0da0bda0a3afec46ea9a8899e61b8762ecaan/a Heodo