URLhaus Database

You are currently viewing the URLhaus database entry for http://it4work.com.vn/f4cwa5z/Overview/swybz85642960474sphb1ndz1e/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:493905
URL: http://it4work.com.vn/f4cwa5z/Overview/swybz85642960474sphb1ndz1e/
URL Status:Offline
Host: it4work.com.vn
Date added:2020-09-14 10:28:36 UTC
Last online:2020-09-14 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 10:30:03 UTC to abuse{at}vnn[dot]vn,abuse{at}vdc[dot]com[dot]vn)
Takedown time:9 hours, 53 minutes Good (down since 2020-09-14 20:23:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-145816481231547.docdoc 9f0ae988efa45dd5a31b192546bb881ebbf6b50e79bf2da69fa2256bbf4d845dVirustotal results 38.98%Heodo
2020-09-14FILE_55397432148646.docdoc e1bc3bae87aa0a48be0f3828171ea815daa1a2f96a613cb7570907068bbd3dd4Virustotal results 39.66%Heodo
2020-09-14MK6898106133GC.docdoc 8bffe2b8680500569488a5d758d2e9bd38112150a1897e88d03a94cba11c23f3Virustotal results 35.59%Heodo
2020-09-14B_FV5788190177LR.docdoc 894bb7216efcd37908b4ffa39eaee5a09c5a3c264cdaddb5918bfbb9e7b65860n/aHeodo
2020-09-14498678012503057.docdoc d0aad7574a29f26aa7b13b0d9ee67b527c0e4dfc5275c0a8e28e000adad26297n/aHeodo
2020-09-14KWR_HJ0819189830EQ.docdoc 968f255a72c41d86299b48628eb79d831741596e1383081eebaf08810ecaacden/aHeodo
2020-09-14INV_78YO67NDUSZGA.docdoc 18a08bfde32fec48dd39f4ba41cd7449d4169cd9252a6dcc077cd7fdca819191n/aHeodo
2020-09-14BAL_PO_09142020EX.docdoc db5dc06cd13c8fe3e12b314bae4c8be7651a26ed861eecaac0e79a8f8bf0ef43n/aHeodo
2020-09-14DOC_96598040.docdoc 3e64b6ff86edb967541e4c0b1dc3667ccbd807e99af91d16f9682597b1352ee1Virustotal results 28.81%Heodo
2020-09-14REP_PO_09142020EX.docdoc 875aadb39437a5366487bf9232ad64eb3d635fae59449e241d84be3133ed2a44Virustotal results 27.12%Heodo
2020-09-14INV_47072771.docdoc a3f6b39e72cc5764544ad0f6abcdddcabce1f34999a2d78268a80c5b4f8546f2Virustotal results 27.12%Heodo
2020-09-1442534646169085441.docdoc c337bb16756fc3e3e080c725f6b9f3835b7277c26e3c9203be11189c6dae201dn/aHeodo
2020-09-14MVB_090120_IMD_091420.docdoc a153e7d47a196c8848cbd1aa6b81d15adb43a1cc0c6402dca515ea34723c0ca9n/aHeodo
2020-09-14FILE_4M9MTG84P.docdoc 65af960efb522275c12cbbc2902476854043df45ed96b435103aedcef02eecben/aHeodo
2020-09-14PO_09142020EX.docdoc e4a9024be2fd969f3d64de3bcff992a2d29ad69e823b5ed145c96a395a013e19n/aHeodo
2020-09-14FILE_7R4NKIZH8S.docdoc cfcf57cba19a0007077044365e06c2d6adb3e658011379a7e16796b25072d391n/aHeodo
2020-09-14REP_PO_09142020EX.docdoc 6c582c81ef9f686301cf1a663938a08c6f793a3f45403b3d4d87da94d5eefc00Virustotal results 23.73%Heodo
2020-09-14FILE_16616327.docdoc 2762b832d1111457d6402af3d53a4f516dd99507d963614d4bdc48855dc057c1n/aHeodo
2020-09-14REP_80997310.docdoc 55893c0cc8ef597e993ef13a63a900b29c09d7903bb693d3a0ff3f77b917eecaVirustotal results 22.03%Heodo
2020-09-14M_SH2976137271AW.docdoc 42c4b1eb39af3f83f49c39994431eb0a042d94a008313cdaf1831db93c45cf5dVirustotal results 22.03%Heodo
2020-09-14SF_PO_09142020EX.docdoc 21bdbf6ef88670da6f32d97e4d4d1ddaad79bbee1a8d10d476ef78b5a63e14b3Virustotal results 23.33%Heodo
2020-09-14S_NX6252783124WK.docdoc 358777fc6c34cc75ebc7d92ee6c2bd0b29eaf38c4a215fc317e920ab0f60476fVirustotal results 20.34%Heodo
2020-09-14WIJ_090120_LJL_091420.docdoc c2e8f7c925f56e68086ee279048349eaede27f3cff8aea65d4298610fd97a3d9Virustotal results 21.67%Heodo
2020-09-14KQPE2T5YX0O6FC.docdoc 35087d749d504d6fcc9959894bd3cec2ff4aed21cc086ec8f4b945dc25e0ceb3Virustotal results 23.33%Heodo
2020-09-1400742507.docdoc fbb786eb4a0f0a9ecf9da92977d330921554d0c4cbdc1218de3641c9a9a16933Virustotal results 23.33%Heodo
2020-09-14IMSVDOT91.docdoc 11cc4036d50f7e705e15ad8d6b14813b0f328d9e14d31aa6ca51ba7e13fd4f4en/aHeodo
2020-09-1456132979.docdoc bed57dded8f474e1685273acb47e279b76b699d0e2c44ac0f299ee924329f3a1Virustotal results 23.21%Heodo
2020-09-140297428909.docdoc 098897d4d3c482f9c893a2e5e57a45d28eae55a43d34b828145c427ec86d8145Virustotal results 23.73%Heodo
2020-09-14REP_27492847.docdoc dc1c646e606fba7effc8189aa637674fb80c79e6227bf2751b9d734372e9dc29Virustotal results 24.14%Heodo
2020-09-14INV_PO_09142020EX.docdoc 86499f4888585de10a1b85f63ecf6af52670ec0819b7387470d9d2b2f5610ae1Virustotal results 25.00%Heodo
2020-09-14FILE_UC7484688067GZ.docdoc a4382cf56e05d13630c7a129db107238817296f692f1eecf1822c8570b7cb51bVirustotal results 25.42%Heodo