URLhaus Database

You are currently viewing the URLhaus database entry for https://babyg-vietnam.vn/wp-content/sites/58328246456/pxu6yod8-507598/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729253
URL: https://babyg-vietnam.vn/wp-content/sites/58328246456/pxu6yod8-507598/
URL Status:Offline
Host: babyg-vietnam.vn
Date added:2020-10-21 12:49:07 UTC
Last online:2020-11-18 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 12:50:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:28 days, 5 hours, 1 minutes Bad (down since 2020-11-18 17:51:47 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Copy invoice #216977.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22October Invoice.docdoc eedc1f3d57d4274cbfc97e09ca0975f97fff204e89fe92574f9e3964a569c9d7Virustotal results 38.71% Heodo
2020-10-22090140.docdoc 73afab923f309960ba6ef1f00b4d373abce5e6605b10a2b214ca42b7736f1f6bVirustotal results 40.74% Heodo
2020-10-22form.docdoc f90f25c4d93aec229941322b4e7d2a590396de4d16baccd18793fcccaab5f374Virustotal results 38.71% Heodo
2020-10-22INV_43137.docdoc f78e345d35c9468fe53fa232310f2f1836c8f1dd99d632578360bb1904400b0cn/a Heodo
2020-10-22Inv. 038387408328.docdoc 8a84251f63aa90465d3b8b145a9e710d1aedfc23d03511b87681f18ec3542298Virustotal results 38.71% Heodo
2020-10-22October Invoice.docdoc 73c15020ef9bf16ef338a7808aeba33bed02253197dbf1251f68c3a954ead5b5Virustotal results 39.62% Heodo
2020-10-22Form - Oct 22, 2020.docdoc 40ad317b6909d6800860af835411d7aedd3ff816bd1e02c7aa0553dadb8735b1Virustotal results 38.71% Heodo
2020-10-22INV_952755.docdoc 8ce84cc08c61ef8da560dab9863109bab6dac208bdb030c9d513aa71dc7b3492Virustotal results 40.68% Heodo
2020-10-22October Invoice.docdoc 709d844ebb9040838314e0bb22f53af41eff662d3b322cfac5858710def23245n/a Heodo
2020-10-22invoice #652996.docdoc d078837cdc9042641925b36475f87954994b19f05d89c10b4ab4a1ea28a806efn/a Heodo
2020-10-2200474594153.docdoc d8bbe49377ebac547c2afa2ab29a64b774b4ddb3501f62becbaedf4d24c33a0fn/a Heodo
2020-10-22Form - Oct 22, 2020.docdoc 14a549a41295bc3e3af038d8f83d8a36aea9e70fc7daeb206d189d3bfff44dbcn/a Heodo
2020-10-22invoice.docdoc 01b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5Virustotal results 49.06% Heodo
2020-10-22form.docdoc 74e16bd58ef88cfbc4267cf32b54a6444f5a01675811af2f8da025c1dd9e7272n/a Heodo
2020-10-22Invoice 0908591.docdoc 0cbc8f1c920ee2d242a6ca5d19dfadee47264af9f96e500ffd59de43cc83bd0dVirustotal results 50.00% Heodo
2020-10-22QX9692188704XJ.docdoc 8c15a10ed4c619cdc9eefbb7d32596330ccb2dbc41b5e21841dd141fee55a85bVirustotal results 47.17% Heodo
2020-10-22INV #0029 FOR PO #006450410.docdoc 65fab287607d55bb546b639bcce9b869bae1c1fda07a15c68e1b9ebe8a626a68Virustotal results 49.06% Heodo
2020-10-22Inv_67198.docdoc 64ee7027b8c1fc6f5a53589c1b063a42cf59f5a99924588ae219a9950fbe7130Virustotal results 46.67% Heodo
2020-10-22October invoice.docdoc af5bddd9f46abad7cf836d9faf757a676ba5bf9a7ee90e04c3a5cecd22c7fbd6n/a Heodo
2020-10-22Payment.docdoc a89a346ba95533594891a15e53625209199e68bad7519485b3bfaf1954b2a8b8Virustotal results 45.16% Heodo
2020-10-22invoice #607362.docdoc 4c0eefb631af43ca75f18562817c8ac29361fdf7b5a528341efa855a8d1c6a6aVirustotal results 40.35% Heodo
2020-10-22Electronic form.docdoc 47024e56dc7cb9b1cb36ff764702c5105a0af0873104fd86e72d9f206c38ebacVirustotal results 42.62% Heodo
2020-10-22N07 invoicing.docdoc 9e13f2a6023aa5aee27ad5d18154d66135feae3909574687817e602e90390b5bn/a Heodo
2020-10-220775342.docdoc 077db39d1c6f7785aa6191761f4033eeaf24c81e2c0ed0f104e798e63a6a1c4aVirustotal results 44.64% Heodo
2020-10-22form.docdoc 2566d4cd03b1b31a54ee14af117d50f0d166a3500ac7b39df87cc69f567a862dVirustotal results 45.16% Heodo
2020-10-22INV_7270.docdoc b97b367766b6d02c9d56c0e849f894229c5eed891450c0a04794ec7124168c56Virustotal results 47.17% Heodo
2020-10-21INV #9193780 FOR PO #8007525.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 32.20%Heodo
2020-10-21Form - Oct 21, 2020.docdoc 2a603eb060abe8cf0ce5259b69da9cdd0e5c3015332a943828ef24212ae982e8Virustotal results 33.96%Heodo