URLhaus Database

You are currently viewing the URLhaus database entry for http://ttson.name.vn/user_guide/https:/sites/Z5jJoFBLMUK/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452670
URL: http://ttson.name.vn/user_guide/https:/sites/Z5jJoFBLMUK/
URL Status:Offline
Host: ttson.name.vn
Date added:2020-09-03 18:18:17 UTC
Last online:2020-09-03 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 18:20:07 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 hours, 18 minutes Good (down since 2020-09-03 20:38:33 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03AKM124 302.docdoc 2a9b356e211b6fc43b720fc28d8c9e2845466e9c79163ddb6b75ba3f9851b5adVirustotal results 28.81%Heodo
2020-09-03Mes_20200903_2793.docdoc 3898915681d8baa76a674cb8386bd9a88f2b8b3883e5db87f3c43e6eda4c08d6n/a Heodo
2020-09-0306294855 2020_09_03.docdoc 8271c25e365343d937c375bcf822595d5cc823433d3d01b5a24874d1bcd89f9fVirustotal results 24.14%Heodo
2020-09-03Doc DI76165.docdoc 509ecb6a2610738956ebdf8a885bdb413fe84bd8143e1012a1fb4a4e14333d19Virustotal results 22.03%Heodo
2020-09-03Arc 20200903 FR244.docdoc dfb1031ce56f9f39a32ed410629d9f46e753b4e0671d121c063d52a7a23785f8Virustotal results 23.73%Heodo
2020-09-03Dat 20200903 FLM965.docdoc af81984de14d081c2a5d015a4266dd625fd7eb4153810cb71c2ba3e9dbf382ddn/aHeodo
2020-09-03Rep 20200903 584.docdoc 87dc054eccdd1cd6182d372f5fad56aae34971c4a0ab10e92fd242ee82e9c785Virustotal results 23.73%Heodo
2020-09-03doc_2020_09_03_6873.docdoc 75e21b06b155b76eeb61cf02a1e3d2ed091b180853d2c6dba9aa7f4afa014aa8Virustotal results 21.67%Heodo
2020-09-03File 2020_09_03.docdoc b9f390e14ff3a741d40f78b33a9e82622638b6a50caa19f042764a40ffea8236n/aHeodo