URLhaus Database

You are currently viewing the URLhaus database entry for http://onofashionvn.webdungsan.com/wp-admin/INC/Wtu9jxCNq6kE/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:619591
URL: http://onofashionvn.webdungsan.com/wp-admin/INC/Wtu9jxCNq6kE/
URL Status:Offline
Host: onofashionvn.webdungsan.com
Date added:2020-09-28 23:29:05 UTC
Last online:2020-09-30 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-28 23:30:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 day, 6 hours, 58 minutes Poor (down since 2020-09-30 06:28:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30ARC.docdoc 9514f8559ebc3346ee2ad8a0dc066f680f456064bcb9dc07a2b528f14293d522Virustotal results 46.77%Heodo
2020-09-30REP 530.docdoc e0241059c22b3f4c297b2b6d6c3d0d854d45f39af3ec08495ca2b04025772414Virustotal results 47.54%Heodo
2020-09-306645IK 2020_09_30 WI058412.docdoc 23ccebb7161e48fdb44034be5f97acd1bfa117b92ee7c747f07dfcbd15d5fd9dn/aHeodo
2020-09-30Mes 20200930 MTQ08206.docdoc 267561ab8d4856ba0064185a8d6269693f1c580b721f16db305b6a9299f5c41dVirustotal results 45.16%Heodo
2020-09-30MES_20200930_117.docdoc e8687463d9ab753f201293dcf26cc49ccc1d536ca5eb2807821502b5e45a4b3cn/aHeodo
2020-09-30inf-MF6057.docdoc 6dcb7e9d3ef574e032cf8d4f7da8e1ddefaea58991677a7e53be13723839e09dVirustotal results 45.16%Heodo
2020-09-30UNTITLED-SE526776.docdoc 892d8f9cfb26bae3277304d3396027dd55d0899e78181a1431bb43e29dd3e857n/aHeodo
2020-09-30INF.docdoc 9d14d3ff8abad95d71af0043f19dd1644cfa14ceb0a6ba617a49f3bd559523cfVirustotal results 40.32%Heodo
2020-09-30List-20200930-0176.docdoc f8b2d066f5a3d657edb1544f9df31a9a7b3121c5c14ddb1b96b50ddd69b44c22Virustotal results 37.70%Heodo
2020-09-30FILE_20200930_F04653.docdoc a3aa47fd0e69bb9abfdf3263e13b7d854f23cc07579e8e294a8930e6498d6143Virustotal results 37.10%Heodo
2020-09-30mes-20200930-7872.docdoc 1d44cd8c3d04874dc41108bc844eb637f657064927fc28927f68c95fe596bcaaVirustotal results 32.79%Heodo
2020-09-30DAT MGB066.docdoc 1b7ae75c0843e24188c16e98283ae53b2d5d441a3149a30eae0eda9db7781220Virustotal results 32.26%Heodo
2020-09-30Doc_2591378.docdoc 0cbe205dde93631435eaf136feea1e35c86b49f20a0067c26fde038b48e2d725n/aHeodo
2020-09-30arc RQN00967.docdoc a87836e6fbf70862d74980ad32f16b6dfe157bcea1172817e7235764aae0c4den/aHeodo
2020-09-30dat 64018.docdoc 7d9b105bc30d62bcdd42543f64fbb302ff4a66be6a6d588357338a2437f9af74Virustotal results 32.79%Heodo
2020-09-30rep_20200930_182726.docdoc 9d6a2742e7b189220132964cb3ecc21eb2bf93bf90143787ab21937cbb1b2e5fVirustotal results 32.26%Heodo
2020-09-30UNTITLED-2020_09_30-8856582.docdoc 8b094b3853afcb79ef514333bfa570faac9b7996f06500f174020ce0e5a31751Virustotal results 31.67%Heodo
2020-09-29Mes_20200930_KQW672.docdoc 9a24d61f24a1211065b986def505c02b66a94f2b1cbde8fc6ef868391c24d4f3Virustotal results 30.65%Heodo
2020-09-29Doc_2020_09_30_RDU100.docdoc fe1ce0fd30ae39c4347efaf4fd829853c3df12a2eaa46b281faf17855b5c3a2dn/aHeodo
2020-09-29RF89988_2020_09_30_F789301.docdoc 1d742e585ed7b4c237726a945da11795c46da01716e9da561d98fff100ee938fVirustotal results 31.15%Heodo
2020-09-29DAT-43448.docdoc 2e0fc31a6ff8f20507c6979fa9b5be9e11f13d424e2962ec30f1fc596c069898n/aHeodo
2020-09-29LIST-2020_09_30-1776279.docdoc b6924c37febb8c64ef7ba11d8266e713aac4062636eb088d498cb095fb68010fVirustotal results 19.67%Heodo
2020-09-29WR2867_2020_09_30_448.docdoc bd56a042ecf4e68f3f6d427ca4ee9ad03267b1e53db58ae19e8335e34f6231f1n/aHeodo
2020-09-29inf_20200930_446769.docdoc cdbc3d9af98086634425aa8705246094a3b602fd00a7f35717208a55a4da2144Virustotal results 20.97%Heodo
2020-09-29LIST 2020_09_30 ZL9161.docdoc 0750c5ef1066dc83b228d1a3ac248ae8ad5825377fd3d39e8749ca492d395599n/aHeodo
2020-09-29mes-20200929-XW045968.docdoc 2225d21fb51eb2731d606c94088c9ac64900275d5970515cba58374eab5dcdceVirustotal results 19.35%Heodo
2020-09-29rep.docdoc 66e0d59d4c4e46b4e5589d41dbb45277b6dd25aba1efb68deada81d72a492aebVirustotal results 19.35%Heodo
2020-09-29INF-20200929-ZJ407017.docdoc 65b6ad21a24f882ef5e67c7126644c2427a2ede7bba65315180693daa77fb5f8Virustotal results 19.35%Heodo
2020-09-29INF_43001.docdoc e05b6ed555dc8741ddf076484cf7ce5f0167e49096c5f25549b9eb7c5a01f81an/aHeodo
2020-09-29Arc_2020_09_29_DEV680.docdoc 30a41f457f62ccbaa26f3679ed88fd959c5cae23e1b9faa2799ea867bd7e916bVirustotal results 17.74%Heodo
2020-09-29Attachments 20200929 074.docdoc 32049385466cefdb6902bff7a1c1c93274f20eb51842f1dc68a84e5de14716d1n/aHeodo
2020-09-29INF 3659.docdoc 275a46a9c86fcb536d7dee38a273fadc27066204b68ef852423568f9f925ae81Virustotal results 17.74% Heodo
2020-09-29Attachment_XZH591.docdoc 748a109fc55c5d0dec25da9b91ecc76785ea1f1b2af565f4f442547dd9b28fd4n/aHeodo
2020-09-29MES_2020_09_29_EC8136.docdoc 054954c8adf177996d7b60d1f0f7490910c3d38ccfa915725432a3702b1fa6c7Virustotal results 36.07%Heodo
2020-09-29file.docdoc 3203c4486d366305fbf9764c203642efa21a522ad4ff60316270cd53c827c06dn/aHeodo
2020-09-29UNTITLED-2020_09_29-64005.docdoc 9d62529a510f5ff1233ee41b2df2feb66813e33d5827aadd11b8d28984fd4bc1Virustotal results 37.10%Heodo
2020-09-29DAT_2020_09_29_OUF1459.docdoc 0e5df02eee4e4ea12ffc82d147544638e2ef823b439f968d9ab64ad4f6810e23Virustotal results 37.10%Heodo
2020-09-29File 702.docdoc 06132db525f2d128efb9a6e0b0322a1c08e01cc5e431086b6b9d1531aaf23914Virustotal results 37.10%Heodo
2020-09-29Untitled 3980.docdoc 23b449fb112ad9151ab2a3e4951ca38ed7ee57f9025e3c70de11fcdf956ffb98Virustotal results 35.48%Heodo
2020-09-29Mes-20200929-CK796331.docdoc 57229d906148c6f3778a3c63cca56a2130ae7815b9d77c017d06140bcc7ccc7eVirustotal results 37.10% Heodo
2020-09-29REP 20200929 SQE06278.docdoc b9c59ca726a42938b8805f8ea4627b5e74d5311faa900d6281e185b7eb349bc3Virustotal results 37.10%Heodo
2020-09-29rep_T680.docdoc 7c1568ea1edd2b220561f08d092e30f64d4fb68540c3de0f5475896f0cbe1d92n/aHeodo
2020-09-29LIST-12350.docdoc 38b279f0aaa0e8e18af504e170e42b1fd63403cbbe5148d93639052b30e03fd5n/aHeodo
2020-09-29File_20200929_Z780841.docdoc 2415846d6579d0de479c9649f6264dfba2c58a9be7405a75c13c83c4170b5d6dn/aHeodo
2020-09-29Rep N260598.docdoc ed8130dae0bd49af3066f45c3a331845416a6728ae51870d4c515c17ad13224dn/aHeodo
2020-09-29Doc.docdoc 5d931fe809f45a29463f740d0fff63d9edd8eb1f5ef70e21670dbe3208539e6fn/aHeodo
2020-09-29arc 2020_09_29 WG91313.docdoc 4bf2fdff643640474491abe2e6dc4a67a7848d8dc28ccef1cc8fefdc1926db5fVirustotal results 29.03%Heodo
2020-09-29File_68196.docdoc 6742ecfe387572b5377d9dd4a476a24c98755c2594bbf861694e57750345e086n/aHeodo
2020-09-29list-2020_09_29-O7342.docdoc 735040fdbf1b513dfe79b4c6485de58b176dba061ef76dd8a0cb42e8161551b4n/aHeodo
2020-09-29List_2020_09_29_XJ09570.docdoc 98ca5617082e699b7edf525fdceb3e43d181d5907503029ea680366ec177d376n/aHeodo
2020-09-29doc_20200929_TZB098.docdoc 741e14a66eb965aae9fcc7da6bc90f096cb91d8492405b53d81e9d13ea0100ean/aHeodo
2020-09-29ARC_2020_09_29_4315.docdoc 8f3f64a249482b0a6dd6361950555bb3bee2b9be6a613991d66eb5e221573bban/aHeodo
2020-09-29inf_770.docdoc 7c61d826037c688e65ce93151bad3d16906e77cacd987560a4151c98ce756939Virustotal results 22.95%Heodo
2020-09-29Doc 20200929 6313.docdoc 7ef3f48a7d33e3c8add4458bddeac305c6a51f4471e8538420f255f3b77013f2Virustotal results 24.19%Heodo
2020-09-2958658ARB 2020_09_29 15899.docdoc 7846dc72ed56d56ae1eef1756a7217bc4f8e4f50efa99051b54f9603c5aa8ea9Virustotal results 24.19%Heodo
2020-09-29Dat 20200929 892432.docdoc 0fecfde61b7f7f3534c0bc1768d898beeef96c53f2ff2aea67835319b4c5fe91n/aHeodo
2020-09-29List-WTU193138.docdoc 2a3f1606dff59a1aed0077676c39e10d432a1c36d244d4b4fb8e5d6fa7e68e57n/aHeodo
2020-09-2935032_20200929_FF603.docdoc 6e9744f364184b29485e6cad1604f0b2afc996e5216392c1dd695dd2e6d58bfbn/aHeodo
2020-09-29LIST 20200929 0679982.docdoc f81dda880a80e023ad07c79a2c75a4f1e372a11c97edcdf97b57565c8987d651Virustotal results 24.19% Heodo
2020-09-29file 20200929 070.docdoc 3c75ed8af10c5b4edceafce4736440fc1b3243e88e43b8380adf7097d716ab10n/aHeodo
2020-09-29list-TBF199.docdoc 30490b4f611eb7e7e2458129bda3265befe37d0133dba94e10cf07c5aae28de6n/aHeodo
2020-09-29Mes_2020_09_29_5028.docdoc 99eae20e9f85e8f87d7559e43c98d5477c2931dfb5bedcf8cec0eb6cb1c93030n/aHeodo
2020-09-29MES-20200929.docdoc f8382d886701b5bdb8f0651a1346114c55dfd557cd1f80204a645d9f49a6cd52n/aHeodo
2020-09-29MES-20200929-FQ13624.docdoc 013a25b863e1527621bb2f01cd41fcda76ce02c4fe3b39c20ef37aae708dabfcn/aHeodo
2020-09-29rep-2020_09_29.docdoc 4c47677a2b29a91e0a497ec1b4a35358c64a48568ab32bd9b24ca10bf3bee27aVirustotal results 22.58%Heodo
2020-09-29list_20200929_N6980.docdoc bd40e03f49d87ba4aa6366400edcdc932f81cc11fe0ddbadf1ba4c64981d421bn/aHeodo
2020-09-29Arc-J974.docdoc 831c896b4d6b4ad14823c8d4b0aba608b79c4198ae79804ef5843c2915dd6881Virustotal results 40.32%Heodo
2020-09-29DAT-NE091.docdoc dffe6b12754772da4ccc5aa7c07425a752a3680f801e0df24fc609e879e83e8cn/aHeodo
2020-09-29Mes 2020_09_29 375.docdoc 27be7747d9f1e8080ba29e9d11d4623e75d529133896b0c741ad580a77524be1n/aHeodo
2020-09-29list 2020_09_29 9779453.docdoc ddc79b5cef58dfcaaaed830ddccce3755acc13c2ffdedbbf3241cc6b35d3358cn/aHeodo
2020-09-29216WJ 20200929 834167.docdoc 33c4a2fd6323bb9b915d3368cca5015470e2ebe56ac0d7fc33568530acc9fafeVirustotal results 41.67%Heodo
2020-09-29inf_7173041.docdoc 84d5460aef2a23f5767b23450722501823e848fff6d7c0f2c5676a6ab79706fen/aHeodo
2020-09-29doc_2020_09_29_3699.docdoc 1ce10d907f4929d568a03b5336386ce51b7bb4cb3d4814bca951bdcbb11a0930Virustotal results 40.98%Heodo
2020-09-29file S51351.docdoc 466ecc37e94d5c4fc81bab60c1395d3cba013f2b4cd613280ee6c9f394f93f19n/aHeodo
2020-09-29751257_2020_09_29.docdoc 15915a01d4795b2cdd261061864a25011d8856f97865e6538890f9259958392en/aHeodo
2020-09-29Doc_20200929.docdoc 0028d5cab5558cff8e7be74cc0522d68dff4b695f5bf9e8067f2b5c61b0c05e8n/aHeodo
2020-09-29UNTITLED-0685836.docdoc b19337ff283d5e928eb6bc9b902fc02a47f506746ab9fc02955e02d7112f3be5Virustotal results 40.32%Heodo
2020-09-2919754719 20200929 PPW34523.docdoc 1340d8450093c4b10ffd24cd42262a4c1115b9f6e0a8a7c0bc184f9973cf8b6bn/aHeodo
2020-09-29Mes_2020_09_29_QWO405.docdoc 4dc9418d6c5b851e2985dd79fb58ad409a9442d22dfa9e5c9e2c4b475bd8f02eVirustotal results 38.71%Heodo
2020-09-29UNTITLED-2020_09_29-2678.docdoc 15e628ef0bab8fa7574005e71632246fa922e8aeabe4dec14dccfcfb2d87beden/aHeodo
2020-09-29arc_2020_09_29_VB101.docdoc bcc520a7c5542f305e98d2eddf75f362f4771597d4e51101ea9485aac97614e6Virustotal results 37.10%Heodo
2020-09-29Arc-0095.docdoc 5f87d95e028a5e898dd317d4a0e297434e8b30770d448c4a07687bfc44e9688dVirustotal results 33.87%Heodo
2020-09-29Mes_20200929_74949.docdoc 085bd44289d94c5a4c9f4b533a6c4c65d15d751153585af0272085401818dd04n/aHeodo
2020-09-29Dat-20200929-YWQ971.docdoc 6a4f1212417249a2a041859ef4fcb7c2968111ee6273aaf0fa840e06c7905b52n/aHeodo
2020-09-29FILE-2020_09_29.docdoc e56bc063733d1ff4a57a70fa7ba2925de15320cae5a623a2f04fdd771c879f43n/aHeodo
2020-09-29Attachment 20200929 1918.docdoc afa3c59ecd5a7ea34b729710fb369a12eac463e7538b0fc2a72d5d10f9428b5an/aHeodo
2020-09-29list_39594.docdoc 6204f39e37c6d400ac0f2645485382c118deedd3e22577637227b3ecb0253399Virustotal results 32.26%Heodo
2020-09-29List 2020_09_29 6446159.docdoc a6dce2f62aa3f756e9c553b8a90aa762858a689da483bfcbbac5dd34ea3e57a2n/aHeodo
2020-09-289664003_2020_09_29_XHG0113.docdoc 45397b94d776a37290f1bc5d37f73758d17185070342f0186eb8aa5b031d8e12n/aHeodo
2020-09-28REP-53487.docdoc 87db481003cf7afd6d3cda5e4f25cec1329d666c4238e33a8dcaa986267b1d97Virustotal results 27.42%Heodo