URLhaus Database

You are currently viewing the URLhaus database entry for http://ttson.name.vn/user_guide/https://sites/Z5jJoFBLMUK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452542
URL: http://ttson.name.vn/user_guide/https://sites/Z5jJoFBLMUK/
URL Status:Offline
Host: ttson.name.vn
Date added:2020-09-03 15:39:38 UTC
Last online:2020-09-03 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 15:40:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:5 hours, 17 minutes Good (down since 2020-09-03 20:57:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03LIST_73634.docdoc e5115c3e86dd21ece011508d8b1b576b6b5b38eefde8dea14cdaac4a6a06f4e0Virustotal results 28.81%Heodo
2020-09-03AKM124 302.docdoc 2a9b356e211b6fc43b720fc28d8c9e2845466e9c79163ddb6b75ba3f9851b5adVirustotal results 28.81%Heodo
2020-09-03Mes_20200903_2793.docdoc 3898915681d8baa76a674cb8386bd9a88f2b8b3883e5db87f3c43e6eda4c08d6n/a Heodo
2020-09-03Arc 2020_09_03 KGS434.docdoc 3d79b0e046a8c799ccb81e9bac59c0b8f45b767a92e8c32465ebb56975ddbbc5Virustotal results 28.33%Heodo
2020-09-0306294855 2020_09_03.docdoc 8271c25e365343d937c375bcf822595d5cc823433d3d01b5a24874d1bcd89f9fVirustotal results 24.14%Heodo
2020-09-03Rep_2020_09_03_PZ76266.docdoc 83fb2541f76d29c147c40d39da0b2f69076d035dd8f0e17c4e7356cecf98d64aVirustotal results 22.03%Heodo
2020-09-03Arc 20200903 FR244.docdoc dfb1031ce56f9f39a32ed410629d9f46e753b4e0671d121c063d52a7a23785f8Virustotal results 23.73%Heodo
2020-09-03Dat 20200903 FLM965.docdoc af81984de14d081c2a5d015a4266dd625fd7eb4153810cb71c2ba3e9dbf382ddVirustotal results 23.73%Heodo
2020-09-03Rep 20200903 584.docdoc 87dc054eccdd1cd6182d372f5fad56aae34971c4a0ab10e92fd242ee82e9c785n/aHeodo
2020-09-03doc_2020_09_03_6873.docdoc 75e21b06b155b76eeb61cf02a1e3d2ed091b180853d2c6dba9aa7f4afa014aa8Virustotal results 21.67%Heodo
2020-09-03INF_UV47155.docdoc caf9674b2ccdb2ccd77f1873b6782fb06bf4ffe22bc103017f81b1c352c8afe5n/aHeodo
2020-09-03REP_2020_09_03.docdoc b66793cda5150365d467a564f89991b5d8c1942368050aeefee9db6fe5c8a107n/aHeodo
2020-09-03Attachments-20200903-AIH05543.docdoc 4af88a43df9708bbfe4b6e374b0a1d494ebe3e3e148bc26031e2274b74d33bd5Virustotal results 25.00%Heodo
2020-09-03Inf 20200903 53120.docdoc 95a7e791afc63ee2afec1fb8ed9283881d2afc17110419804e6dad34cf0914ddVirustotal results 25.42%Heodo
2020-09-03Inf_20200903_884.docdoc 68d32abf2673eb48f6df74b063aa17e978d10a50c746d8e0f27ba51c93779d01Virustotal results 25.00%Heodo
2020-09-03rep.docdoc afec2bfe8925c1750c88f1532f6c9f067e3751ce6beeca628db4850efd1d7bccn/aHeodo
2020-09-03rep-2020_09_03-411652.docdoc 4a2ee0cb09dab923da14ab985f65d156e600b82e42b0bb53bf982243bed9400eVirustotal results 23.33%Heodo
2020-09-03Attachment 20200903 88925.docdoc 431ec558729a17c71ef7827a20d49d5577d19b03f8ccaa3e0615a8db09ed3c54Virustotal results 20.69%Heodo
2020-09-03Doc_9655539.docdoc a3cb0dab145b2e5b5000b6b134acdb73594fb0bec769212dc3b848b5eb16d284n/aHeodo
2020-09-03Attachment-2694.docdoc 53b6f6751207755d917347f8d00bd9bf7341696e323b10ac482d24b1e25a3ea1Virustotal results 21.67%Heodo