URLhaus Database

You are currently viewing the URLhaus database entry for http://lamthanhphong.com/nrhgi/Document/zu680ytkhn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:538670
URL: http://lamthanhphong.com/nrhgi/Document/zu680ytkhn/
URL Status:Offline
Host: lamthanhphong.com
Date added:2020-09-16 22:31:05 UTC
Last online:2020-09-17 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-16 22:32:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:5 hours, 13 minutes Good (down since 2020-09-17 03:45:48 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17PO_09172020EX.docdoc 6758d3603f3eab05e72d8c9e6f7714f93f572ca89397a5018c8104d0c6099810Virustotal results 28.81%Heodo
2020-09-17DOC_92695392.docdoc 1a945df2c4c5399840e2cdcc623c15e12451e66db694d71f26bd718dc8628993Virustotal results 31.67%Heodo
2020-09-1744550726.docdoc 430ef6af760d2105f3c14655f66ff5dc191916c938a26256085965a4a536c827Virustotal results 32.20%Heodo
2020-09-17BAL_34076746.docdoc 524f6d1744c625d4ee827ab1ee1406f5aeef8c8799b8cf6474c2a53014a1dfadVirustotal results 32.20%Heodo
2020-09-17FILE_16379363.docdoc ca5204766a181d5961896a0f4c506ed00718fad078c3a951d9343e52ad7f16d4Virustotal results 28.07%Heodo
2020-09-176XPZLPPCEX6.docdoc 76bf8d09a314a6ed1f11e8794d3027fcedcc3762677e37d8f7a304e4d370837cVirustotal results 27.59%Heodo
2020-09-17DOC_PO_09172020EX.docdoc 6ba572ac222372c95a63401ec2b6710af0a9445d6c38efc7cf8397461ab1fd8eVirustotal results 27.12%Heodo
2020-09-17RF_HJ9978489569VP.docdoc 528a62bc2a5bb42529a57abc0367b0a612ebe84f846906aa5a6737e759d6ae84Virustotal results 25.42%Heodo
2020-09-17BAL_YJ0M83MWQUM8.docdoc 7a8024cf777ab45c5c969c5efff3dd4f289bc22baf1c91bd884fc2d29435c884Virustotal results 25.42%Heodo
2020-09-17REP_OQJ6SP5UM0YE.docdoc 2bc521550fad4a12b0bb8f34a8958db7b2f5b50e9f8579d30d814cee697ab694Virustotal results 25.42%Heodo
2020-09-178470050924158725.docdoc d30169f108ec72fbaf16bb8726e798602988e1c42a7b3020b0ef0ad0572f9625Virustotal results 25.42%Heodo
2020-09-16TF3827743870AY.docdoc 1ecaceaeb20649c823b3a63accf639925ba8e4c350b2509496c04dbd622d5d4eVirustotal results 25.86% Heodo
2020-09-16RIJ_090120_RVU_091720.docdoc b2bfefad5d4d6a3dff230f61a9c4b055d5ae4b37b8fecca5550317c89f615504Virustotal results 25.42%Heodo
2020-09-16INV_BW0857641107CC.docdoc c95b5dca5208b5d4dea488991b6cae5bc1d6e7686af278285ea7e77a3b71cd03Virustotal results 27.12%Heodo
2020-09-16CX_CUI_090120_PQR_091720.docdoc 73158e3c574c5cfbe98520ebb3b8c4270609205751d997b87414e5a43980f960Virustotal results 25.86%Heodo
2020-09-16FILE_30E8BROE9KTTSHN.docdoc a9c8d3bb56d6abf69a804578bde7b85ae2717ff03d86c79d9f96d313d82552b5Virustotal results 26.32%Heodo