URLhaus Database

You are currently viewing the URLhaus database entry for https://thinkpadvn.com/wp-admin/Scan/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:529521
URL: https://thinkpadvn.com/wp-admin/Scan/
URL Status:Offline
Host: thinkpadvn.com
Date added:2020-09-16 09:42:14 UTC
Last online:2020-09-16 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002940770 created on 2020-09-16 09:44:05 UTC)
Takedown time:6 hours, 47 minutes Good (down since 2020-09-16 16:31:32 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16N_GA2489316539JE.docdoc 06875ecfcdad40771a2a6d4ea795ebf797776a5fb3289a4f4f6207dc2d4ff91fn/aHeodo
2020-09-16HA3939413866VG.docdoc d84e8e3441cf862fa793eb241277718737789cb1e43d92be3b8510f8bdaeddc1Virustotal results 37.29%Heodo
2020-09-16X_PO_09162020EX.docdoc 373849d14e1a5afad2cd1632a3b1a8324d242fcb48c47c2732d9b5c67e538af1Virustotal results 35.59%Heodo
2020-09-1603151812.docdoc c714262e7ca075c2816149ba0cf39cd465e11d7020a2675a228f4180df6163c8Virustotal results 31.58%Heodo
2020-09-16OOZR_QQ0095491053GK.docdoc 361d848b59beb5b40b7839f66735d926f31725d38136435f01499fb0e4a66463Virustotal results 32.20%Heodo
2020-09-16BAL_CY6264603138SG.docdoc 6ab3c98c93e0973a6d291313199fb6afb3ee259509f1282acaa4673687b6880bVirustotal results 30.00%Heodo
2020-09-16REP_06643769.docdoc 8f20ff26311834e143d010f2fa23f292d4d619b34cf2639d9d4ef2a7e4df9d8fVirustotal results 28.07%Heodo
2020-09-16INV_RUR_090120_OBG_091620.docdoc 7d29e749c79d53fc5303ab43bed236a5f884e21617771cce4518860bd7bec1f3Virustotal results 25.86%Heodo
2020-09-16INV_Q322QCBGSCDJAR.docdoc 11fc9d76f9ab6d54ffc389ea4c4b2445ab3d2c00935ea19c38de48d2e29010c6Virustotal results 28.07%Heodo
2020-09-16INV_EE1989401438PB.docdoc ff0be8f9b0efc6b14928e8ea89ffb82ebe82f74db08241df5ec7713c073dfe91Virustotal results 24.14%Heodo
2020-09-16BAL_IHD_090120_NKR_091620.docdoc ebc2b7cdf7a980a33d015502bafcb4a5b6333f49795569f1e2d7e18733d274d6Virustotal results 20.69%Heodo
2020-09-16NGWZ_69260493.docdoc 0e0913f7c913e70406fdc7b5e47f2455d7152c4e461770cc1b9bee581491fab9n/aHeodo
2020-09-16REP_76035548.docdoc 4f21e25c362b1dc72f9dd3b2b0910516918a46a4016a631a2ee276493d7d160dVirustotal results 20.34%Heodo
2020-09-16LZOS6ORN0Q.docdoc b3f649438cba7dc8f34dbdea69bb67a356906ead944752b8abcc4fcc23b737e6Virustotal results 27.12%Heodo
2020-09-16INV_OH3359837635MT.docdoc a1a24cdd447db95aa10894a3b471875da732d0240e0b855117d5d31d9ca09500n/aHeodo
2020-09-16REP_PO_09162020EX.docdoc b8d558c1ac20808b0809fcfa0c5a017da7e300736b6dbfee52ed1930c7b19a08Virustotal results 23.73%Heodo
2020-09-16PO_09162020EX.docdoc bdf14c66a5a4843014c1fef6f147f6a7454f8f34223c51a2cd78f684c80e010aVirustotal results 20.00%Heodo
2020-09-16BAL_YUY_090120_QIT_091620.docdoc a77ef77d33744bee43471f6efd79797f4e3b790cb616c1a01e546f03a4e960f7Virustotal results 20.34%Heodo
2020-09-163047313560050909.docdoc c81e73cde0ba06145f34071dd88dcaa6a7a0490d9096b1c3f78886fbf5063669Virustotal results 20.34%Heodo
2020-09-16DOC_78737826.docdoc 09c3f3aad8f9bc8f65a86d581ecb23b0a6262a9e28d5c5e19750e6770aa5e40fn/aHeodo