URLhaus Database

You are currently viewing the URLhaus database entry for https://viettellogistics.com.vn/wordpress/browse/80l3o4947434501330phpls454uhkviqqagth/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431217
URL: https://viettellogistics.com.vn/wordpress/browse/80l3o4947434501330phpls454uhkviqqagth/
URL Status:Offline
Host: viettellogistics.com.vn
Date added:2020-08-12 19:23:11 UTC
Last online:2020-08-13 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-12 19:24:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:10 hours, 45 minutes Good (down since 2020-08-13 06:09:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13Z_LKK_080120_JWW_081320.docdoc 66c466602e92ce814b3d1f3270664f374e0016b5e166867a4c9f01cc5cf94a1cVirustotal results 53.33%Heodo
2020-08-13Z_LKK_080120_JWW_081320.docdoc 66c466602e92ce814b3d1f3270664f374e0016b5e166867a4c9f01cc5cf94a1cVirustotal results 53.33%Heodo
2020-08-13REP_ZH2776044091YW.docdoc 2ec1025c3a44b35de74853b22998ea439d6eb5f0d92d9065256692f0deadcbd9Virustotal results 51.67%Heodo
2020-08-13REP_VIEMYQ699.docdoc 5ec2a412f6729dbbd84453b84c85ac56f93e865a1900eb514efedefedc56467fVirustotal results 50.82%Heodo
2020-08-12INV_18480165845840501491.docdoc a9af06ae735677ec282b4a66f7bc85a343dc7c71491658673fed6150e05ef3c5Virustotal results 50.85%Heodo
2020-08-12UCC_080120_OEO_081320.docdoc c872e36dabcc02d5ca6d5a1c7ff09a8673509c3a45dc42978988f19f053fffadn/aHeodo
2020-08-12DOC_NG6389711862DA.docdoc 6d377770b986243d95806974b9d72c7f06f0cc80801d73a0860866cf4d95376en/aHeodo
2020-08-12PO_08122020EX.docdoc cfec1c4aeca2bf10496b8ae3be0b77a9dfade44f1503c09398114731db0e92b5n/aHeodo
2020-08-12IS_VYH_080120_HDI_081220.docdoc 448b77551e8ab272663dac5ccf4cad4be8b7dcfc1759a2859785754aa44d285an/aHeodo
2020-08-12PO_08122020EX.docdoc 81b56737e0ebf1766ee14ae1a7c022da0208f91ddbae7d06bee3cefbbf3b01a1Virustotal results 48.33%Heodo
2020-08-12INV_BGS_080120_THB_081220.docdoc f2ccd3c493881b68693c2d24addb0a1ec854e6020efdff1cbccf785a1ad099bfVirustotal results 48.33%Heodo
2020-08-12REP_PO_08122020EX.docdoc ed26d991b694c8bb2d0c371dcf61bc637d597cc26ebba3b826a73f8bfaa922can/aHeodo