URLhaus Database

You are currently viewing the URLhaus database entry for https://nguonhangcn.com/wp-content/form/36290104/xyjv2kd-000379290/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:751506
URL: https://nguonhangcn.com/wp-content/form/36290104/xyjv2kd-000379290/
URL Status:Offline
Host: nguonhangcn.com
Date added:2020-10-26 12:15:09 UTC
Last online:2020-10-26 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 12:16:05 UTC to abuse{at}choopa[dot]com)
Takedown time:1 hour, 51 minutes Good (down since 2020-10-26 14:07:20 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-26Inv. 0081359792005.docdoc 85ef6233fe3651d7b5eaaaad06d0350456e419abe29affb49dfc0cdb2d20e875Virustotal results 34.92% Heodo
2020-10-26Electronic form.docdoc 96e5facb575f443054025d85864f29682c7c0c71148252f5b48c00589fd821c8Virustotal results 36.67% Heodo
2020-10-26NBS-100120 RGLO-102620.docdoc 371b040a51afcedc85741b1a132bd26e2f4f47d381986e2a900893ff0cb64b02n/a Heodo
2020-10-26Copy invoice #8560.docdoc e50304baf418b794765ec3e14c25137e509a3670f0877da91666c85965993c23Virustotal results 33.33% Heodo
2020-10-26Inv_7397.docdoc 8a07a861fdc5ba7fe5b33d79984936f768340b1ec529473a339aeeab7ba0c8ddVirustotal results 33.33%Heodo
2020-10-26Form - Oct 26, 2020.docdoc ff2b4921249a74645095e01d292a40c3171d4c58a57cfe068ae978c9aa5df17cVirustotal results 32.69% Heodo
2020-10-260078095.docdoc 9013cb74eab6bb9671aa92093642022a5ec16467040cdf342afc99cdcf9fba2an/a Heodo