URLhaus Database

You are currently viewing the URLhaus database entry for https://phonghanh.com/wp-admin/ZNG0P3KPPT/6276930748/hyHPuCQG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:719784
URL: https://phonghanh.com/wp-admin/ZNG0P3KPPT/6276930748/hyHPuCQG/
URL Status:Offline
Host: phonghanh.com
Date added:2020-10-19 20:32:05 UTC
Last online:2020-10-21 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 20:34:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 day, 10 hours, 13 minutes Poor (down since 2020-10-21 06:47:59 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-218637028.docdoc d8e0f462d8d75918d376254506d8d9ca846f6fa1f33076a091cd9f61832efbc2Virustotal results 50.94%Heodo
2020-10-21Form.docdoc b7b2d0ef7df5007d18a8a857ab7b35956aa9060aa4edfb1bd80e17299d53d9a7Virustotal results 50.00%Heodo
2020-10-21Form - Oct 21, 2020.docdoc 10a79d7cf0b1366e69b0473e9164dcdf109149a6551b18a6c277a242261f5dd3Virustotal results 45.16%Heodo
2020-10-21October invoice.docdoc 33931df25bbfed2013a987a32738c165a5799d274381e76cbf534ba189be293eVirustotal results 46.15%Heodo
2020-10-21PSZ-100120 VJVO-102120.docdoc 58a681865ea454572eb661486c8e06854e90cc7cd2d5ab95ae331a724f5ce97dVirustotal results 45.90%Heodo
2020-10-21Form.docdoc 8d8971cd4eb8a2c26f5263e44299f9f468d43614dcccdcfae564420d264e0d29Virustotal results 43.55%Heodo
2020-10-21Invoice 006984144.docdoc f230273ae9e5eb57e36f98c374578e1a9856504dfbfbdcc7f815d20ba5974f2dVirustotal results 41.94%Heodo
2020-10-21Form - Oct 21, 2020.docdoc 916c5fa5d800ce852e4e0e1c215daf1e813c868e5b1d9b0c7956b16ec6649adfVirustotal results 41.51%Heodo
2020-10-2179475.docdoc 20c81e0a8e1547a4fe23a6d435e61f31253f5036e68c7564ad0c5d1fbb79120aVirustotal results 41.51%Heodo
2020-10-21Form - Oct 21, 2020.docdoc f75dfd9100b7fb7c93a95812e11a04f911e4ed1f61fafa8b73c747df9898a212Virustotal results 40.98%Heodo
2020-10-21Form - Oct 21, 2020.docdoc d590ed65aef80ecdc7f0a44755ee436937f30c0b05287ce6d177b654512940e8Virustotal results 40.98%Heodo
2020-10-20October Invoice.docdoc 368608fc48be7d6239425f9a9e23b2aa19d22aaa001796c8c0e391858bd2932eVirustotal results 39.62%Heodo
2020-10-20invoice #07873.docdoc a85c57fa12d0087eb6da3bbeff4a027b351978d8b8073086c43d522366e5fe9eVirustotal results 39.34%Heodo
2020-10-20Inv. 023748228006.docdoc 0fd8d47fc4990dfad6cb0567737449722837d2aa312d68143295e1a2846ed1ecVirustotal results 40.32%Heodo
2020-10-20invoice #606646.docdoc a8e92bb15ad9bcd8e93e71644a570c2aeb6d030e2b496412500deb4ee2a23889Virustotal results 37.10%Heodo
2020-10-20Payment status.docdoc 513b71ba83e2dc965d906445134bc392882b7628f49e973b9d6021139f0ac8ccVirustotal results 33.87%Heodo
2020-10-200052564.docdoc 2da7885a305894fb4a3cb76ff2aeafc9899cb7c590bf1179feea80f8795f9c30Virustotal results 32.79%Heodo
2020-10-20Form.docdoc 9c7f9441f61d7c2798707bc28069012911e4547e38374095bb23506fb1bbee2eVirustotal results 31.58%Heodo
2020-10-20PO# 10202020.docdoc 9de27d2156aa1a500c8317a999704637a436bc162590ccb63344d7930b438826Virustotal results 33.33%Heodo
2020-10-209532164695SJ.docdoc 36a9973c36b4c8891b4ff704670f49374aab0db27ba22546659b76a7f9c942d7Virustotal results 33.96% Heodo
2020-10-20017191.docdoc 3bc3a1ea24bd194a23d6c8493b9754de9a41127025a14052754eba04dd1dda70Virustotal results 33.96% Heodo
2020-10-20October invoice.docdoc d71d5d04020304ab739545240d25684b106882802e265a64cba2af565ca6c8efVirustotal results 32.26% Heodo
2020-10-2000458825.docdoc 92cd361e9c865cca5d1f5d5d2e60b52da8214bf163d2e1d3284184ae999b9d91Virustotal results 31.15% Heodo
2020-10-20Copy invoice #4480.docdoc 125f1d5c057389effdcea5d909bfffd9749d79c9a1370a3e057d777bae4bc1f8Virustotal results 31.03% Heodo
2020-10-20Copy invoice #651106.docdoc 61835e08172767d73a9e6c5dfb1fcc8b904d60c3b9cd7b382bcfe43aeab5c2c0Virustotal results 30.00% Heodo
2020-10-205559442088FH.docdoc 7e136d3bc68a6578cdb157624c2783f78b48a13944133de3d0f5b0d34ce6ffa2Virustotal results 30.00% Heodo
2020-10-20invoice #789040.docdoc 6a003ad11e4785ca68e20e102246780b6e3d1ef660453fed530da4ba2ed14639Virustotal results 30.51% Heodo
2020-10-20Invoice #426.docdoc c7bae32f76eebe4cb2fdbd687d6d09d30ea38d1c6751a1ae5cbee6c9bfb5b96dVirustotal results 30.00% Heodo
2020-10-205228508445.docdoc 589c7b11cb037b2183fcee493e98930358a15693532b1340c7f4cf1d2f50c636Virustotal results 32.20% Heodo
2020-10-2000311555.docdoc 0c826456d4bf7da7aaf36377a19de56cb2712b94c047a86518ff7745d252479cVirustotal results 32.26% Heodo
2020-10-20invoices 650 & 29061.docdoc fcf66fd33f42c75abf852452c661e3ccc4f85c48a721dbc4471bd28332760145Virustotal results 51.61% Heodo
2020-10-20INV_873509.docdoc 8bec43e2d05761c02be362fef3cf9b6f0f4963f122c275c7c7686e3cea6fd5b1Virustotal results 51.61% Heodo
2020-10-20AH0828 invoicing.docdoc 2f0abbe89ce350352b4029575dffb4895f42d2296aadc1745287763704b7093dVirustotal results 51.67% Heodo
2020-10-20Payment.docdoc c31795e9d2a3b7bf6e19d054a2574f0ea3eef997e49bd9318316efd609cada94Virustotal results 50.00% Heodo
2020-10-20INV #0011156 FOR PO #59719635473.docdoc 5cfa1457e7ddb2e7c49419cabef1c969debc4d677e7ca6f72d6edd8e2ac88a32Virustotal results 49.09% Heodo
2020-10-20Electronic form.docdoc 9fdb062ded6d82fd2d2d452643f3eccce639b07b20b205b0ce7cb8ceb31ac487Virustotal results 50.00% Heodo
2020-10-200032200.docdoc a417c81a25c5ac2873406cb44f9cc36a1b62ca6dcbc2eb4affd62cd438168b95Virustotal results 50.85% Heodo
2020-10-20Payment.docdoc d410b71a4badf540641e5b102f7296d63455fb941f370f9c8248d0fa8176896eVirustotal results 50.00% Heodo
2020-10-20Form.docdoc aea562896196459f11e274751fcc92aad6234db3e78088c86bda7f2b31be9b4aVirustotal results 53.33% Heodo
2020-10-20Electronic form.docdoc f5996a9cae20e6d4cc8ef73a116b7b97723ef49093a4d518c6c85d757126cdb1Virustotal results 50.00% Heodo
2020-10-20Form.docdoc f75ad4f83ba06b713679c42a55a1b4def77266dc5574330e418d629288877848Virustotal results 46.67% Heodo
2020-10-20Payment status.docdoc 1d6ddacfa157c7a54a7f33fc1f1941a643a4a4f799268d4f2fdb333e4d6d49a4Virustotal results 49.18% Heodo
2020-10-20Payment status.docdoc 775679d5aaee59d4fca6fbf59e84b48cfc8c975b4b5f57e5638a67885a2012b0Virustotal results 50.00% Heodo
2020-10-20invoice #159146.docdoc eea53beba6b9509581365a0a43ddf454f25bf59bb13e8549cf3eb66a5d832c92Virustotal results 50.94%Heodo
2020-10-20Electronic form.docdoc 2e687ca36b3132b0704c1da58bfd462aa6bf5272d6ecbc84616059abc2fab4f2Virustotal results 49.06% Heodo
2020-10-20form.docdoc a7a71a8db9345289a21c62edb7085cbff3e0dfcbaf3b66e6e17506a60af10fd2Virustotal results 45.00% Heodo
2020-10-20Form - Oct 20, 2020.docdoc be3645a6416b42048d934a1330244b34134f64f504a20c92af99c1ecd301deecVirustotal results 51.61% Heodo
2020-10-20INV #0025160 FOR PO #00198379065.docdoc 29b284995c7be9561c22f89c9c4d4ed2f4abad490ff34aafd2fb0cc7c0312b90Virustotal results 48.21% Heodo
2020-10-20Inv. 00373721.docdoc 477afd6f4a7fed4b0886e1d509e130c736c6f2203be85ed8c18d40bc6db385f0Virustotal results 51.61% Heodo
2020-10-20invoice #664936.docdoc abb1fa28c17964d8d4366e43c3fa606bb40eb59a69d128368a37c9ae5ba84544Virustotal results 46.77% Heodo
2020-10-20PO# 10202020.docdoc bd3634b192d3a73ca432502cf51882a5b60ab2d2b5617b526cf8cb2431a31404Virustotal results 52.83% Heodo
2020-10-19Form.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 40.98%Heodo
2020-10-19T6 invoicing.docdoc c22cff8c43e59c186145e91cc19bf98b0aa99956c6b462715d0b72959c3b71f8Virustotal results 41.94% Heodo
2020-10-19Invoice 0517520.docdoc 7eb56f82b5ff2b35c514fe7d1a001246488a656499eeddd21b48279c27921affVirustotal results 37.10% Heodo
2020-10-19241190.docdoc 995b23a9bd0a11c32d07365a8fa7adc883c2c7b35b640aa779badac6de9d98a8Virustotal results 33.87% Heodo
2020-10-19form.docdoc 65d548a2c80c974c878eff21c34e9d94965ab43d7da72c2557d3e47f61484738Virustotal results 40.32% Heodo
2020-10-19Copy invoice #479408.docdoc a875775bc542120368ebd7420d0b376b0199f439e16c9adaa061d37b56aca8b3Virustotal results 37.10% Heodo
2020-10-19Invoice.docdoc d1d223369aa2b6e5c67bea5f8537ca391f95bcab639c44daf6c52a51db312871Virustotal results 37.10% Heodo