URLhaus Database

You are currently viewing the URLhaus database entry for https://celebitech.vn/xdvnl/j3h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:698174
URL: https://celebitech.vn/xdvnl/j3h/
URL Status:Offline
Host: celebitech.vn
Date added:2020-10-15 16:54:07 UTC
Last online:2020-10-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-15 16:56:05 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 days, 17 hours, 10 minutes Bad (down since 2020-10-19 10:06:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-17R_226136712.docdoc 360a5cb7eed923017b4ef07460e7652362cdf1fc0a902516addbb8e244e30134Virustotal results 54.10%Heodo
2020-10-16MSLL_233682103984751649818.docdoc 9c52e949c6c2ca01cb5bf09538ef75451e8aaabf492927bbc8a9f6253007a31bVirustotal results 42.62%Heodo
2020-10-16BAL_VRS_100120_OHP_101620.docdoc 80f4eeab6a06e618009ae98f990dcbebc222213491d87a9f59c98daef7ff882fVirustotal results 40.32%Heodo
2020-10-16DOC_20651684865.docdoc edb4f70584295164d9d97ecd140501fed80903b2d3149447f60b6dff1a991a82n/aHeodo
2020-10-16REP_RVY_100120_DZE_101620.docdoc 6a643872b2481769c2b5927a429f7f678557018b9e08015b2be084d104bbad4eVirustotal results 32.79%Heodo
2020-10-16REP_8YLDJY1.docdoc 14e3c057772cb7ce44d16fe68b8499294c3c88564a42712c0568481bb9d83ad2Virustotal results 33.87%Heodo
2020-10-15DOC_MA5QM1QHDPIIB5.docdoc b1ebf8efae5ce8d163d465c5ed7b819bdcc16fdbe03f723da2d0b61114721d04Virustotal results 43.55%Heodo
2020-10-15A_02607589.docdoc 004b9a020076d8317b6e57259eff30a147253aafc450379efc2c62a61fcd42efVirustotal results 43.55%Heodo
2020-10-15REP_48697784.docdoc 9e399c9bbd8e0a5be20ce299ce14f5e1f7ae22f19f564231c3650f1a6c055c3bn/aHeodo
2020-10-15A_WTA_100120_TLF_101520.docdoc 30b3400f4a69274881ac358ceaed2b0e632dfe513ad2c374e97bc00fc214ad10n/aHeodo
2020-10-1526935379320010.docdoc 3f6955a4c8030234f81c5371a9fe055356a777586aec5021a269eb74083d6ce6Virustotal results 40.98%Heodo
2020-10-15DOC_14286832.docdoc 8e85bdc8bfcc70eea561513c94cabb062b60b8270a0427d01f6db78ee4532b5an/aHeodo