URLhaus Database

You are currently viewing the URLhaus database entry for http://comaysaigon.com/ocmms/cKWyvDtI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:431930
URL: http://comaysaigon.com/ocmms/cKWyvDtI/
URL Status:Offline
Host: comaysaigon.com
Date added:2020-08-13 13:17:03 UTC
Last online:2020-08-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 13:18:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:17 hours, 50 minutes Good (down since 2020-08-14 07:08:46 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13Inv-52-610243.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13invoiceEAQ7058848067.docdoc 294443b3b8e68154544b8f501310b598b2925bc108c42f5a30bccfa9598b6782Virustotal results 35.00%Heodo
2020-08-13InvVIKK192988265376.docdoc d50993fa8e4d9ec3510e0980dd77bb417ce8cd1455e5b3b789b4bf66e4f7b29fVirustotal results 35.59%Heodo
2020-08-13invoice-VDT8-725681.docdoc 5912b8e3ef4983ff2a2edb2097d0149b2828a6d735e579fc964a0a938c0afac7Virustotal results 34.48%Heodo
2020-08-13Inv UQ063 2752096.docdoc da66414b758cec9e59a4d246d1a01e3339644d5be305c6447ddaf0f65900db71Virustotal results 30.51%Heodo
2020-08-13INVOICE_22_252588511.docdoc 1344d4ea858a94b81b25c9c85ca54dabf55f7ac242bd4e4a9eaeb991ba75fc4dVirustotal results 31.67%Heodo
2020-08-13invoice 45 30974692.docdoc 53012447056c43d98e67bc063b1016fc1330216796dcc7c1eaed32a4aa02b45cVirustotal results 31.67%Heodo
2020-08-13Invoice YQ0 503150.docdoc a9daa1f1f97ea5d02fc81e34cbab89ca25f94540d2fb3506f7339f3398470d67Virustotal results 29.51%Heodo
2020-08-13invoiceID78630618162.docdoc b8a573213c36923b03e13902ca78fa55cd62d801d34fc7f5ecaf692f7b68482cVirustotal results 28.33%Heodo
2020-08-13InvoiceLOX311694469.docdoc 938e03ff3d361fa26c00218160d0ef65786280283d80678e729a73ea503e0d95Virustotal results 28.33%Heodo
2020-08-13INVOICE-KFTU6318-712083776.docdoc f029a391648b1fe61978c79aa2a2c7783ff27cdded15c30ce648421693898e2cVirustotal results 26.67%Heodo
2020-08-13invoice-YPBX2-27841711.docdoc dce7a722033797f2aa2ad0124f254c5b8774adde48fdb0be22e150e8b368588fVirustotal results 26.67%Heodo
2020-08-13invoice-H42-59449318.docdoc eeb469414b6509fdd0d204f306b29d55021e2de94608991794b5f59c2add1e07Virustotal results 26.67%Heodo
2020-08-13invoice-BCZZ259-251343564.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 29.51%Heodo