URLhaus Database

You are currently viewing the URLhaus database entry for https://vieclamvinhphuc.work/sys-cache/eh7j0o0y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:625224
URL: https://vieclamvinhphuc.work/sys-cache/eh7j0o0y/
URL Status:Offline
Host: vieclamvinhphuc.work
Date added:2020-09-29 22:01:37 UTC
Last online:2020-09-30 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 22:02:03 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 hours, 14 minutes Good (down since 2020-09-30 00:16:36 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-29REP_PO_09302020EX.docdoc 5bc9314961b874f09854775cf9f6bce09cc9c8106200074edb961cd544efb675Virustotal results 30.65%Heodo
2020-09-29REP_GLXXIOT603127PN8.docdoc ad21f91ac048eeb669e0a9cc8199225d755cf89a9f5d79d7fb39ef2659f04a9bVirustotal results 29.51%Heodo
2020-09-29UT9268642311YU.docdoc 5d9881c8900498814ca049d263ca3339b113198bfe781ccb5e5ffbc2b23eb325Virustotal results 30.65%Heodo
2020-09-29FZA_090120_JTN_093020.docdoc 91d4d101c3e8a665106bb48847dbee3791e2a9a04c0adb2f363ae7767e463337n/a Heodo
2020-09-29BAL_OX5906684195AO.docdoc 76d3bae4ebe683a5d3ff0d90971119c287a3acbab073e28b979ad7eaa60e37bfVirustotal results 27.87%Heodo
2020-09-29INV_PO_09302020EX.docdoc 0581f0969b158a86c635f6c5a3931c57571aaaae1eb93475efeb0fcb6a99d1f9n/aHeodo