URLhaus Database

You are currently viewing the URLhaus database entry for https://tuyendungtin.com/wp-content/lm/ztTA/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:720032
URL: https://tuyendungtin.com/wp-content/lm/ztTA/
URL Status:Offline
Host: tuyendungtin.com
Date added:2020-10-19 21:47:09 UTC
Last online:2020-10-20 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 21:48:02 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:23 hours, 58 minutes Good (down since 2020-10-20 21:46:06 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-20Invoice 15195.docdoc 513b71ba83e2dc965d906445134bc392882b7628f49e973b9d6021139f0ac8ccVirustotal results 33.87%Heodo
2020-10-20Form.docdoc f8918c22b7bf74403126907c7e3fd18cdba5c16dc3bef59652e99d67d57d8d62Virustotal results 33.96%Heodo
2020-10-20invoice #1678.docdoc 9c7f9441f61d7c2798707bc28069012911e4547e38374095bb23506fb1bbee2eVirustotal results 31.58%Heodo
2020-10-20Form.docdoc 1949d127f8cad19649adb5f4534e1b6eff752a31d5ea73e427d0ef8c90511ceeVirustotal results 32.26%Heodo
2020-10-20925051.docdoc 15e191fa2be80a5d0b1b3af67b1ed360c006e3634442bb6255e4cc0f901abcd3Virustotal results 32.26%Heodo
2020-10-200027015171.docdoc c9804b898a9d2326b05f4037b2eace298777d1a387273033692c9f6deede6cabVirustotal results 32.73%Heodo
2020-10-20Form.docdoc d71d5d04020304ab739545240d25684b106882802e265a64cba2af565ca6c8efVirustotal results 32.26% Heodo
2020-10-209145364.docdoc 5de10aad274888c1ae2d0b13f1cc5199b0fbf596200f2f0d567aa2e2df2e2e22Virustotal results 32.20% Heodo
2020-10-20October Invoice.docdoc 98bb25e6f42b7ed9cbaff96437ada2d6b17e0a4bb5a6d1d2e2a8636233ade5a5Virustotal results 32.26% Heodo
2020-10-2087685539.docdoc 61835e08172767d73a9e6c5dfb1fcc8b904d60c3b9cd7b382bcfe43aeab5c2c0Virustotal results 30.00% Heodo
2020-10-20Inv. 000277633126.docdoc 4217ed123cc2bd063b8cc599340aec39fda437a4e62df3118a01251a915c226bVirustotal results 34.62% Heodo
2020-10-20invoice #3227.docdoc e59ffb1d8684c5f593de0d953edca68b56546935b4c9eb2bfc7b55958865826fVirustotal results 31.03% Heodo
2020-10-20Invoice #55428.docdoc 6a003ad11e4785ca68e20e102246780b6e3d1ef660453fed530da4ba2ed14639Virustotal results 30.51% Heodo
2020-10-20049394.docdoc 589c7b11cb037b2183fcee493e98930358a15693532b1340c7f4cf1d2f50c636Virustotal results 32.20% Heodo
2020-10-20E00546 invoicing.docdoc 6664d59aec5871d443503652ecf25bac9b57963b8022e44f0d00711ec4aca495Virustotal results 30.00% Heodo
2020-10-207672277.docdoc 6e81190ea76657504baff9bef3ee1e2b652f05d439d5d47cd39fe510ac240b26Virustotal results 50.00% Heodo
2020-10-20WNT-100120 NBHD-102020.docdoc 354fea5033e720e774f141b26f7606a4d844f9e990565c0c9ef51558c3581836Virustotal results 51.61% Heodo
2020-10-20October invoice.docdoc 2f0abbe89ce350352b4029575dffb4895f42d2296aadc1745287763704b7093dVirustotal results 51.67% Heodo
2020-10-20V-100120 CVWJ-102020.docdoc c059700c980038c5bd96da0591c886f34c3e6c0ab17319d89c4aa1e026ca640cVirustotal results 48.39% Heodo
2020-10-20October invoice.docdoc 79fe11a895e4e6d9945022d70da2ea0c06927b3b91d7947564e610377117ee72Virustotal results 48.33% Heodo
2020-10-20INV #00959 FOR PO #00926962891.docdoc 03ed194d560f6e7b976f45dd5678707c7132079b5d6d1bf0366c7163e939cb1bVirustotal results 49.06% Heodo
2020-10-20IJ7481594574HN.docdoc 31c9941b5e674b482e7b5020bce1c27dd86c8529fe254326dcd4a86d137492e1Virustotal results 48.39% Heodo
2020-10-20Electronic form.docdoc 365d3d49f5595f8f953aea3c3d22743b8319fad46a667472b4c3504b8efb805bVirustotal results 52.83% Heodo
2020-10-20form.docdoc f5996a9cae20e6d4cc8ef73a116b7b97723ef49093a4d518c6c85d757126cdb1Virustotal results 50.00% Heodo
2020-10-20Form.docdoc 63079c50ac6b966778ae92e6a4d39927b58a475be4b8d095192b40ad5a877756Virustotal results 48.33% Heodo
2020-10-20Payment status.docdoc 9dead7615c9982a5935592ea257a1c754b61ee79c39b61345ce30c18e1756cb2Virustotal results 50.94% Heodo
2020-10-20PO# 10202020.docdoc 73f22ba33ef477380a8177c19532c0e6a7c993ac47333c22b3ad4b53544bade1Virustotal results 49.06% Heodo
2020-10-20invoice #672401.docdoc 544ff4b94e4f7afb43e2c47a07cffc8162ca9d60b804e0d7203ec85fc2ef81c5Virustotal results 49.06% Heodo
2020-10-2080892.docdoc 9d08e7c389570de57d78a8cf91e14d9c814ec46202b241acdcea2d9dcf7c427fVirustotal results 50.00%Heodo
2020-10-20invoice.docdoc 925df0de20c1970feff21e7c085d0c4ba2f3f2feedec51001b1f2410c2c31846Virustotal results 50.00% Heodo
2020-10-20L8810981728DO.docdoc 351fcc4213634fcc050b1b9fa1b83edb1aa5b64736aaf801c2928e5deb5c35b4Virustotal results 50.00% Heodo
2020-10-20invoice.docdoc 477afd6f4a7fed4b0886e1d509e130c736c6f2203be85ed8c18d40bc6db385f0Virustotal results 51.61% Heodo
2020-10-20Copy invoice #244795.docdoc b53ae43743c6308bc894bdee9df0745d8c360217f26cf37ceda3a979b519969bVirustotal results 48.39% Heodo
2020-10-20Form - Oct 20, 2020.docdoc 1dbba69603fe6866b9b3762959b8d745e12bd325c1a203a5160e547f7ac4997eVirustotal results 46.77% Heodo
2020-10-19invoice #2246.docdoc b52f4d01a0ab4d1cc721d51d83479234dda82213536075936f096f0d1203552eVirustotal results 40.98%Heodo
2020-10-19Copy invoice #23627.docdoc c22cff8c43e59c186145e91cc19bf98b0aa99956c6b462715d0b72959c3b71f8Virustotal results 30.00% Heodo
2020-10-19invoice.docdoc 7eb56f82b5ff2b35c514fe7d1a001246488a656499eeddd21b48279c27921affVirustotal results 37.10% Heodo
2020-10-19HG063 invoicing.docdoc 995b23a9bd0a11c32d07365a8fa7adc883c2c7b35b640aa779badac6de9d98a8Virustotal results 33.87% Heodo