URLhaus Database

You are currently viewing the URLhaus database entry for https://mobi-game.vn/wp-content/themes/Newspaper/Scan/dF4BjQrUKWZZCC/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753595
URL: https://mobi-game.vn/wp-content/themes/Newspaper/Scan/dF4BjQrUKWZZCC/
URL Status:Offline
Host: mobi-game.vn
Date added:2020-10-26 22:26:05 UTC
Last online:2020-10-27 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 22:28:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 48 minutes Good (down since 2020-10-27 02:16:19 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27ARC-20201027-226633.docdoc 7db77f1a42a01fd8da4a5ca5eed3c944f6cc3db9caef5ac3e8b5d420b970b612n/aHeodo
2020-10-27Rep_2020_10_27_2313.docdoc ba144b2c722855e58aea0bc21aafb2692d8b535dc920fa40677eee2de5baa662Virustotal results 52.63%Heodo
2020-10-27Mes-20201027-FLR92207.docdoc a8af91bef70904171bef405f02b5defa05d6b30f158c7ad6360a7436e6b7be3fn/aHeodo
2020-10-27Inf 160063.docdoc 98ce88c9f247c75c579d1893aa0e20cd63f5a61f4b7ab7a70b4e138e34fed993Virustotal results 48.39%Heodo
2020-10-27UNTITLED-2171.docdoc 52d4dcd449517b101bb99988f9b270b9785a8987cc4edf558f18fa0bbd5bb438Virustotal results 49.06%Heodo
2020-10-27Inf 2484960.docdoc 34552d4adde7395abb5b114284e79a47c0aab68c0ab1fc62affe993b7373852eVirustotal results 48.39% Heodo
2020-10-27Dat_20201027_71743.docdoc 7f3ad8f66409867f25e71e87520c6c5bef13981bf27cab43e285638a3681292bVirustotal results 50.91%Heodo
2020-10-27Attachments_2020_10_27_JV0213.docdoc 4e6cc9395d61d172bbf4609dd2621e07304e62e0d580fca4ee823d4359fcc7a6Virustotal results 43.55%Heodo
2020-10-26INF 614669.docdoc 83977121b9e97f87d650fe12845d19e59c28ab763af8051d755ea26ca2ae9821Virustotal results 41.51%Heodo
2020-10-26List-2020_10_27-0309.docdoc 46a7efb8d08758d71739208f61876f02d174a3a9e8351924dc15cf5338c46d79n/aHeodo
2020-10-26File 20201027 N939954.docdoc 73d1b4c3fb5a035d592fd68fb3393cbfbd659c6fb165d4aebb3c1abd953aa593Virustotal results 40.74%Heodo
2020-10-26MES_8960771.docdoc 9624eca338cef03d8004d874cd0c774bf67ece67290d5a0022da8117345b11c6Virustotal results 39.68% Heodo
2020-10-26MES 090562.docdoc 300fe8a8206fc96bf8007311c265ecd86c75124818fc9b9f3424286f106da398Virustotal results 39.68% Heodo