URLhaus Database

You are currently viewing the URLhaus database entry for http://lamthanhphong.com/journal/Scan/g1BCikkFw4yQ4hXV2H/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:597028
URL: http://lamthanhphong.com/journal/Scan/g1BCikkFw4yQ4hXV2H/
URL Status:Offline
Host: lamthanhphong.com
Date added:2020-09-22 13:22:48 UTC
Last online:2020-09-22 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 13:24:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 30 minutes Good (down since 2020-09-22 16:54:51 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22rep 20200922.docdoc c4699bc83e2c480aa53af341f4b67b5dfb27cb5d28fb09a7619b55689b686ae3Virustotal results 45.90%Heodo
2020-09-22rep_20200922_9471.docdoc 2c9c3cbda0aa694b7f8075132ef84de6c06632e7959d6356634acb932ef4d9b4Virustotal results 45.16%Heodo
2020-09-22Attachment_0634105.docdoc 32c8a986a400721c89ff872dabe5fb5a485720706e240f6f7cda0d6dece17d0bVirustotal results 45.16%Heodo
2020-09-2259772_5490628.docdoc 8ce52163ceab79b32f012e6129070434d32ea30dfab92da2a9e62e79da693497Virustotal results 45.90%Heodo
2020-09-22mes 2020_09_22 IIA158359.docdoc 5dd221021744417bff46bb5b349b66b0417efc8148a1f40263013ea591e10ba0Virustotal results 41.94%Heodo
2020-09-22929U-2020_09_22-UEF065314.docdoc c7ca7a44edf6effa174d0b1dce9466bcc8e5f5acb9c0fe0e9925104c9af8e5daVirustotal results 37.10%Heodo
2020-09-22REP-2020_09_22-5736.docdoc aa023277e7c4a82947af555cd343fecf048c1c044e4e2fa8bd830e3d09fc5adbn/aHeodo
2020-09-22arc_2020_09_22_PZZ06186.docdoc abdd1ac85459873879997482fe416aed9e065d97999a52f679df62c5ba9bfe18n/aHeodo