URLhaus Database

You are currently viewing the URLhaus database entry for http://dienmay.webdungsan.com/wp-admin/attachments/suljo90wdy3r/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:622068
URL: http://dienmay.webdungsan.com/wp-admin/attachments/suljo90wdy3r/
URL Status:Offline
Host: dienmay.webdungsan.com
Date added:2020-09-29 09:33:08 UTC
Last online:2020-10-02 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 09:34:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 16 hours, 27 minutes Poor (down since 2020-10-02 02:01:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30PO_09302020EX.docdoc a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47Virustotal results 26.23%Heodo
2020-09-30PO_09302020EX.docdoc e8a8b9fc12cfa3ee4f3cd91504cbf5b9af3281a25798c9c23c319044b39b551fn/aHeodo
2020-09-30FILE_75543155.docdoc 5fa75a02b1c855828a4a11cf3cf8da64502f2b4023c776b5f37c98ef894df875Virustotal results 26.23%Heodo
2020-09-30EY6060660375AK.docdoc d46320a38b414b43c59ca8d4290d2da2129bafa4cacc5de0162242e761f1dffdn/aHeodo
2020-09-30EUKJD9SO.docdoc 89184bca1106ed62901477bceef09ee282bceca404d17c44630544fdd803cbbfVirustotal results 25.40%Heodo
2020-09-30SPA_090120_XIT_093020.docdoc e0b14c7013db13d2758bc65aa44f7d54f176e4c60749b9dfa397e1d4d9312355Virustotal results 25.81%Heodo
2020-09-3072797215.docdoc 05917a3d7daf2bc7de49c374fe7ec364e19f2aa1b60480a666ed224053f0fe1dVirustotal results 24.59%Heodo
2020-09-30V_NER_090120_CFU_093020.docdoc efa9c669d5b042ca0892a07861b3f039c3d61f0fa89c57348ee5058445f2db1cVirustotal results 22.58%Heodo
2020-09-30REP_DHK_090120_JYE_093020.docdoc f5e365e70de80b2c17172db5e9c99d037fe2d025161e0c78d7665734a2d108f7n/aHeodo
2020-09-30T_8EF3G4HVL8WF.docdoc ea04aeb35f3ee924c978225fd95f2fa3df8a4847a761685ad79f96c82886f80dVirustotal results 22.95%Heodo
2020-09-30REP_PO_09302020EX.docdoc 583be8560739028b53b2363adc1a5198c194b0ea7abb706f3dd49e9a170d7f79n/aHeodo
2020-09-30BAL_71532735.docdoc 2d09a2c2cc27e1e5e697d5c7fd6e7cbba00b82f6e118d417147a336d7c4fe92aVirustotal results 23.33%Heodo
2020-09-30BAL_XAX_090120_RCT_093020.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.22%Heodo
2020-09-30P_7CKKGKX7G8B2FD.docdoc a8dae6d86f2ae529335810a70a6f959f195bf9fd10f2ade7549334ff2767cd04Virustotal results 22.58%Heodo
2020-09-30964615252950.docdoc 110b8287dac073cfd63cca6a49c82963d72e5883bd93e56f99445993e41bc097Virustotal results 22.58%Heodo
2020-09-30DOC_BA0974494165JD.docdoc 380569af88b834f9d208236fa12e84cab31e0caf8793dacf54e7d8bcb290e5adn/aHeodo
2020-09-30DOC_2747993952.docdoc 6b28e785fb139d9950f37bf989bed92089e9f22d3160a16699b2fc8b0d3500efVirustotal results 22.58%Heodo
2020-09-30PO_09302020EX.docdoc dae3de0260b268fd89734a96196759e0a878835e38a868db1ec44194c212e1f0Virustotal results 22.58%Heodo
2020-09-30INV_1G20MGOTV.docdoc aa20d5b64ffd09ab64443f3159ab02394d97ae2baa93aa75de32fdbdf7f30e6bVirustotal results 20.97%Heodo
2020-09-30FILE_25R5D6IQ.docdoc 13d2b3475b4383e26dba14d71c6977c5eaac45d957a98cd70218a93fb28ca36dVirustotal results 20.97%Heodo
2020-09-309715631808347138463.docdoc 5bd1dec77e268f1da221047d95d57981748b9f359c04a76b1b80de3a2144c67dVirustotal results 21.31%Heodo
2020-09-30REP_6739547896569645153504903.docdoc 786c646aec87e25c98dfbac09f886f13f05a1e6690baf9974f99f1b37b6f3713Virustotal results 20.97%Heodo
2020-09-30K_54699338.docdoc 119dab813d43139ec7ee0f953f68341391776f7f5cdbc1fc6eeabf95356a8a21n/aHeodo
2020-09-30INV_9466831169278.docdoc 0c169d8b50436ffcfc67dc75e5a8534829a932697bf5e79107b4ecc423e227f9n/aHeodo
2020-09-30PFV_GH575BMT9VR.docdoc 0a2e10583a6c70298eb3c353e0a15ebd98c8a9ae09db8e6cc9cef513e39c95dcn/aHeodo
2020-09-30DOC_PO_09302020EX.docdoc fc6f0ac3e38b970866e30342911b1f72bc2a028a33a093badc8c5694321d5808Virustotal results 20.97%Heodo
2020-09-30INV_GWTJMI7MR1.docdoc d0ce4cd7cb0a84604bbd7f40f0aa48a2f09e21fb9eb3d4b72d64cf88790f3081Virustotal results 44.26%Heodo
2020-09-30PO_09302020EX.docdoc a9b4569007c2822d7d717a8ea3a4e3a496c52a3f2011519ca3c4dd5e42011465Virustotal results 43.55%Heodo
2020-09-30FILE_78553355.docdoc 9c8962de4c40c27a546d2347cc878f099354ae9f5cc7e799e78d864d74a6a72en/aHeodo
2020-09-30G_SXU_090120_TGF_093020.docdoc 16570616ac7a29eab86f3d418f18b67750c4deca1c01529454e5f1a591e6fc6dVirustotal results 45.90%Heodo
2020-09-30REP_78966041.docdoc 3d322e72fd831b7624674c0a9ed650c75bf0cf2d05e5c2dcf7746ee4187260b3Virustotal results 45.16%Heodo
2020-09-30DOC_PO_09302020EX.docdoc 010d313ef5a6680acc6fcdaca0eed3e19f256a23cac861684466d6e7f7138030Virustotal results 41.94%Heodo
2020-09-30IVJ_090120_QPX_093020.docdoc 42c1f3bb9e1fae138c02e1447a93ea34c9c4859fca0078bdd3ea01145c4ed12bVirustotal results 37.10%Heodo
2020-09-30FNA_090120_TXK_093020.docdoc d8f8b40e6c0fff5344fce0199e4fd683f50bc846af26963d53ea1554aa202e61Virustotal results 35.48%Heodo
2020-09-30INV_63408438.docdoc 31096733d8d5f5ecff8a6a1f0bbf9b3af3fb5f1e8f0b509b342a38cdb0a01b43Virustotal results 35.48%Heodo
2020-09-30DOC_3396562132045857.docdoc aabd54aa244d3a19daa025d685a63495581f02a35c44e11bdb76ea7bbf7360baVirustotal results 32.26%Heodo
2020-09-30LC_95035880158004710.docdoc 020aeaa470dfa7a4e9fc3e8d88db9d7f89b1bd64df67a963467490068a6f3d6dVirustotal results 32.79%Heodo
2020-09-30REP_QXN_090120_GPI_093020.docdoc b3e10600287dfaee56f53325acb38c44c75d92fdda24bce58c9d231eebc0bd06Virustotal results 32.79%Heodo
2020-09-30QP_FF7577394944GV.docdoc 9503120eff8e09bde10d7341fc02b19428bf024bfa48b4db12e902ce9895be55Virustotal results 30.65%Heodo
2020-09-30INV_JR8544273560XN.docdoc 75f032ed1b4c5d9738c4ebee1d878f1fe5307cba5c43dc44ce2443a640e7fb2fVirustotal results 30.65%Heodo
2020-09-30O_018343482845210687.docdoc c7e94b09a7bf83d363a7949d7aef5bba5516bd5b0e0c149bbd1dc341b9cd5180Virustotal results 31.15%Heodo
2020-09-29DOC_FM60OW745R3ABJLM.docdoc b11de73e98459e676a482af2c4e52dbbaf7d6cc9fe43b57ab758f3ffed754223n/aHeodo
2020-09-29FILE_8M1LZ4V5Y0OS4KS.docdoc 5a9f82efe64ed654c3bc8be5822ab7e6cc987624f9b90222d1ecac779b7d2347n/aHeodo
2020-09-29BAL_KG8331018020JD.docdoc a0269d67f007490795637a732bf26ce5976a2b4039df3d784930ef9109697365Virustotal results 27.42%Heodo
2020-09-29REP_GK8073852968TI.docdoc a863d09af176344fa94c7820a54398bd505f2ee93f7f66a6f05d3e60b71479ecVirustotal results 27.42%Heodo
2020-09-29BQR_090120_BJR_093020.docdoc 76d3bae4ebe683a5d3ff0d90971119c287a3acbab073e28b979ad7eaa60e37bfVirustotal results 27.87%Heodo
2020-09-29M54K6H5ITV.docdoc 14e6ea40cc1e124fe353ed7aeb27490dad58d6a116bfddc62aacaa02921c5d88Virustotal results 32.26%Heodo
2020-09-29FILE_DDC_090120_COY_093020.docdoc 0696c08b3e38944c68c4e41b8589256b865c69f40b1dd4fd6016b27474f54488Virustotal results 32.26%Heodo
2020-09-29DOC_21555747.docdoc b84c2da4ab10a702decf8a1bd04eee1ccd250b8b792bd32957cd1bcac6c50861Virustotal results 32.79%Heodo
2020-09-29FILE_98555020.docdoc 7536e91c00f2d6ce6bff6c4241db275e75c1696e91929da0f4005d58644f3459Virustotal results 32.79% Heodo
2020-09-29INV_OWE_090120_JSU_092920.docdoc cb9fa076c152b43bf6144934c0db90d82803057013a15d526acbec0b6144e979Virustotal results 30.65%Heodo
2020-09-29151955987445390564727.docdoc 2e997b7baaa8519fff2a756670247b75a5b9fd00addafb830d7ad6ebc7ad18d1Virustotal results 32.79% Heodo
2020-09-29FILE_RW9768543882CG.docdoc 4c12091055b16db3d329d221e16a7de91f9dbc93593c907716507d7e3eeb8a53n/aHeodo
2020-09-29INV_338966305643364822249379.docdoc 3aaf9d87f200afabb589944540ab256fe76be08830881af24d5c40dd48cef8f7Virustotal results 32.79%Heodo
2020-09-29FILE_TOO_090120_OFO_092920.docdoc ea4deabda061cf0e59e34cc08f01c386557bbb0fc8f9fbfb31b1ae8be808c0eeVirustotal results 30.65% Heodo
2020-09-29DOC_PO_09292020EX.docdoc d68b772804de699fd2f1abb0735015fbe96bb1e7d89c9a1358ba210724b39b52Virustotal results 30.65%Heodo
2020-09-29R_994249730148183.docdoc 6a885b798b52f7d192ca45fc985e8cf77812dc4f50fdb9ed11a8861a63c5c061n/aHeodo
2020-09-29REP_CZO7389Z2A.docdoc 5560f4bd35a2f200e40eee7a63cb48b4d539e2f6dc8d1d793356e1a6b2b9cb1aVirustotal results 31.15%Heodo
2020-09-29PO_09292020EX.docdoc 9007b11425b5f1dd609e2fde237534a31b3c5576fcbbf0287b8025e59c2773b1Virustotal results 30.65%Heodo
2020-09-29FILE_PO_09292020EX.docdoc 521b43b0a4013e7b1407116f9896d153d7401ea8eda3b29b63b64b744596a651n/a Heodo
2020-09-29REP_18032426.docdoc 44227b77d84cd888cb5d44f59159a5bdc0c7b3021042e2d2814718e870c2b237Virustotal results 33.87%Heodo
2020-09-29REP_5236547715488507.docdoc 4b00a598c3d77faf9cb3fc8f0432a1dbe25d233571c98f35c4cc6660d604297fVirustotal results 34.43%Heodo
2020-09-29YS9524768695MY.docdoc af66021f5673c71460b46b35f0d09a751b24676c36e0a9524e18841c4c4dcb80Virustotal results 34.43%Heodo
2020-09-29HOR_090120_PNS_092920.docdoc 488426d051ae8f32ce12c8252cd241d051cf8b75612a38116fd5f496f7ec57b3Virustotal results 33.87%Heodo
2020-09-29INV_64363796.docdoc 5c29e4a154bd815fa7b0b8378bc4ef9067aa0b244cd56b506afeea21d166d678Virustotal results 34.43%Heodo
2020-09-29REP_149134257190051286.docdoc 67453aa858ac24a5403b4bd5cc27a734bc73baed1a8d891fcbcf0dafaf280d53n/aHeodo
2020-09-29BAL_731047923018366908860.docdoc b36bdec74fb8bb17b9719193ef5c04e4696e6b2bb02ddd5900d90dd52f2dda90n/aHeodo
2020-09-29DOC_XV6463040449ZX.docdoc dade9df0dc4f0946c890687fe36e0d7606ab7e2679a0cfb77ebf88e0881be28fVirustotal results 27.42%Heodo
2020-09-29FILE_ZPIBECD8O.docdoc 930f463961fe5e9a4f12294d8b8971666d98014f3dd408c1ffa285c37276cd8dn/a Heodo
2020-09-29PO_09292020EX.docdoc 6e9852d3647c4e98ea816cd8a40aaad4dd2c5f2b2b1f23aadd3d237eee251750n/aHeodo
2020-09-29S_0NA4UWLU.docdoc 0c8337868addcbf512070ec0f2932bec08c65c25b64adc9374590fc9764214e0n/aHeodo
2020-09-29337985446352172522.docdoc 6e2b253000053aeeec708e1f19dc55340faa394c2a8dc55c25b19caa4bb8200an/aHeodo
2020-09-29INV_QW3712750595CG.docdoc 05f1651c27d78b774cd2de8746ece22449b03816577af4b84582dd60ca81643an/aHeodo
2020-09-29P_ATN2ZF4DSK2M.docdoc 4389a40fe8a20d1e8eff4be2fef943890f835363717a6669ef1ff624b480700fn/aHeodo
2020-09-29INV_62486864.docdoc 52d4d3ba3631c4dd2d1c90876ed2268eb3da0bacc02fd451a5ea5e4c84bd96c8Virustotal results 24.19%Heodo
2020-09-29BAL_NGZ_090120_KYW_092920.docdoc 36bfa7a98a671adc28799b87a656330d4ea7cbd8c52fbd6d75d77049acbcf95bn/aHeodo
2020-09-29WWL3NVBD3R.docdoc 8463091366fd555af04f6e98903f8959e0735f49e6ca9bd462cabdda01e5ec9cVirustotal results 24.59%Heodo
2020-09-29INV_KA6777845807BR.docdoc 958d53abea6cf0f1aaebf262ad00527d7662a411d70635dffb45d95e2a44c80eVirustotal results 22.95%Heodo
2020-09-29INV_NNCMESK.docdoc e14d5e952754ea4e70d6b4e7fa8492b977440f96102fd4b5962df2b34c5ec4a6n/aHeodo
2020-09-29FILE_UU6CTTQ5QB.docdoc 57c668a0bbfa7e8683b5b1aa582e5bee9674151ae3b0a92c61f7fb594b2fc2a6n/aHeodo
2020-09-296044059585911697.docdoc ba7a38c7d93f68b2667ec34c2bdcc137d46a2e58bd678b48cff292e3c8f47e53n/aHeodo
2020-09-29INV_PO_09292020EX.docdoc ac227d3a7a5726f8481ab18b06d8afab6c1d4f31572578a71f4375020fa715c1n/aHeodo
2020-09-29BAL_PO_09292020EX.docdoc f5013fbc3f4e685f68f19711624f55a63fc7ff5dfa0005f8c16803761c7d2788Virustotal results 22.95%Heodo