URLhaus Database

You are currently viewing the URLhaus database entry for http://windybio.vn/wp-admin/DhqxK9hQSeZgFDjOSnfo3TE8uABNU4NVMmr69jk9aliRrjwIIwi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:939649
URL: http://windybio.vn/wp-admin/DhqxK9hQSeZgFDjOSnfo3TE8uABNU4NVMmr69jk9aliRrjwIIwi/
URL Status:Offline
Host: windybio.vn
Date added:2020-12-22 21:34:07 UTC
Last online:2020-12-25 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 21:36:13 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:2 days, 11 hours, 34 minutes Poor (down since 2020-12-25 09:11:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-245S93JIKW.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 65.57%Heodo
2020-12-23G17PSM637VZ2S.docdoc bce89cd09be85ac647d834fb41cec14c3f695ddd559477288bd3853accb78258n/aHeodo
2020-12-232XSVMPBWG3J0B.docdoc e706341bc37bf712b1c9cde4133f7a479e41cb8e6f4b9e9fdd3e3eaa8dcb91c1Virustotal results 41.27%Heodo
2020-12-2305WUBIGJLNRR.docdoc 54ed122348f1eb4575e53cf51a436566a3a19e35d0120a52eb54ef53895f855en/aHeodo
2020-12-23KJ4KBZ.docdoc c5681e7f73b34c33d33ebf5aa9e920a9bb1e0af9f6d3260ba9d49ced57a4cde2Virustotal results 41.94%Heodo
2020-12-23GWMZLY.docdoc 717acb04159cc5347a1e23d9d8c2a15857612e3379fa4e0a9a9b6b473bc2670bn/aHeodo
2020-12-230HMUMLVQTWJYGSK.docdoc 70cc44f855631b3a9358c0b5f202406738d8b5c6a21133f6ae2d775aaa3a8ecfn/aHeodo
2020-12-23O3OC9HK560L73S.docdoc debda494b0bad3be7b136c399dc6d16f1aa643cc3611c5fa3ffc9a4d32d2c808n/aHeodo
2020-12-2376278EEDV.docdoc 395efc9f98f81ccdcbfe6f9bffdd0e0ea5a2611e4542e43f1241c649713bf46dn/aHeodo
2020-12-23A402CXBNCXC.docdoc 08907511869c01824c3fa593161c3d71a507c9a403faefdb197811e3adaa4f8dn/aHeodo
2020-12-23WPN7C6.docdoc 2edf013ada24ea7a142b0844b980169d465e7f5aefdaf645b44ece962d10d74an/aHeodo
2020-12-23E488E9K2F9CG5YRA.docdoc a7b7abb4d144045e42bf5e55e294d5b67850d11ccaac312734570ccca072851fVirustotal results 26.98%Heodo
2020-12-23Z4EAC9.docdoc 09d5de04cf0dc8dff51dd2315b237fa491d213f8496f1c361a7ef2efbbe15932n/aHeodo
2020-12-23TBHJ3V2LYETO2.docdoc a28b7c24587230e5ac5533afb0324572f1d1341d264eccba2aaf6b2a34e5ce81n/aHeodo
2020-12-23VSNWZ0OUH94N.docdoc cb4f991bd4228ec60ab6af1bab6193e68f4fadf3a30b226e7ee9cdfe893113a0Virustotal results 22.95%Heodo
2020-12-23IGHLL1W1CEJ.docdoc b96bdcbde5a864db016ff0e5d071c9ab68331ac9c87debcf6e019c901fc8678fn/aHeodo
2020-12-23FNAO1FHZAT4.docdoc ef1fccd54eea48427d2f6011fe8786cd9ae4f0fc4966130f9f3a99877c49dd04n/aHeodo
2020-12-23WWJ4YK.docdoc 8538d00638c32a97eac2e8a9e1766a39268d8effa55c28026d3b75fe114dbc18n/aHeodo
2020-12-237ELVQZ04LCFY7KX.docdoc 8e6a0c5576e309e8d8bc23d6103bc9d355ac27c354d69992c7fe8650d39e10b2n/aHeodo
2020-12-23DOQGD40TP.docdoc 15231bea81bede2d3149669c6501c6a8ee8338cdd374c53eb34c9737249b040fn/aHeodo
2020-12-23LME9PJOW21VCG.docdoc 055f997b54c9f0fe5ab2c07849d8e88daae0adb0ff26458d823b6f7413f3ac72Virustotal results 22.58%Heodo
2020-12-230JPAEW.docdoc 318cf158cf886f17e7e947feaaf989f25e514c91bec35e9dcca2a4f2ef4baa95n/aHeodo
2020-12-23S318T9CRBI5P.docdoc a8a5d52ccfe6f7bcc1ef7c99087ec90083ea7e3851e760b0653bd4189d54bc9en/aHeodo
2020-12-2363PWSVRI46.docdoc 383bbcf6e40f5db6ccf0a07f33eb55614c381daaae647ebf0ed8db148d4ab7fbn/aHeodo
2020-12-236W7K5KNI0MXC.docdoc 87de984c9ce216b3c4c6ca196e51a042d9a5cd438c4968e8ae070b6053106556n/aHeodo
2020-12-231E0YZSNMV2C9JC3.docdoc c31a2ac228c882d72c112ad120473d012e0ba62c8d157e83cb7738293120eb15Virustotal results 20.63%Heodo
2020-12-23G9BD3VTK.docdoc a59e3318597fa65b37e597175045690d391ef038c7e58869d71ba50ab499cc64Virustotal results 41.27%Heodo
2020-12-23XVW0PRW.docdoc 4a6d02a3adc59903ee067a5abc702d78fb31c61deb56b7360fade2ec85195569n/aHeodo
2020-12-23VZMAP2DOL1ZLYIS.docdoc 93901d975d0df11ab32c4eaf841b43684882ce002e1222696c629076b1b81792Virustotal results 41.94%Heodo
2020-12-23HGNO3ILSEH64R8H.docdoc e269c87f3edd655d2fa4f379bac4ddee2c652386ccd598daf260157b1b9c033cVirustotal results 41.27%Heodo
2020-12-23QWFR5OC.docdoc 2bed788f0ae4910b2b76b0d6a72af5f76811598705f59de52684ab9f99ca1fa3Virustotal results 41.27%Heodo
2020-12-232KAFZKVZD2F.docdoc 098fd9226fa629b47b6a137b89e9f3f85f74266c494382a6678d910af2cf8130n/aHeodo
2020-12-23MEA5KS6GFRAK.docdoc 9e353b38f1dd65bbd6f1e50dc63ddc1350f17b8e382a9fe24328cf1f1609b181Virustotal results 38.71%Heodo
2020-12-23NBJ0US339UVA.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97Virustotal results 36.51%Heodo
2020-12-23XMSA3K.docdoc 74ca579457b696e80799f7acb8b3caa43a1a05be7c10a42fdfa94b1013490c07n/aHeodo
2020-12-23P7B3F4T7S.docdoc 68e9fac6a7996f04c150777aec9f02864a62b4c0d59675625c1801a231461a0bVirustotal results 25.40%Heodo
2020-12-237JJMYK7DNRU.docdoc 525689f16129765cbfcab859edd5d99fbbec461ea04160605819b2f4b6150042Virustotal results 27.87%Heodo
2020-12-23R0NTI66AGZGH9.docdoc c80244df2388e37d8c799e9968c52c9ad8c72b789ad85a2a91c35f8c28b0afd3n/aHeodo
2020-12-23RF3YMIMXZV.docdoc e9c79c389f9e0132834f2da34cf19158e44330446302146e5636b0516d65ed51n/aHeodo
2020-12-23NIG1W2BIM1GDEP1S.docdoc ef1b1013a1aee1aea1889ea4f3f736bac21dca5f8d940f13dbd2c332a8c8ac69n/aHeodo
2020-12-23FFVOMCN1C9YA3G.docdoc 6983d0de072547b29fe27502cd474096e7831a387d6980280fd1519c1cd86025n/aHeodo
2020-12-23YQ9LHY2NO.docdoc 58d4bd6bd7acaf8809df8354441ca6b7b0045d93c96f73c90736c23bd06f2563n/aHeodo
2020-12-23LCY94NX840XAAJ.docdoc 80eec607b84d6c759ebbb5743e91d1ce1581bb83128c11b70467d1dd2e4beff0Virustotal results 26.98%Heodo
2020-12-23PHXJEVZG.docdoc e56e47b889fb43e8b9f183ee7abca3a349cede2826008e189de20df4b7bb481cn/aHeodo
2020-12-23B4KLEUXH8.docdoc 9a8b914d6bb8ae09a04b32fc897fdb9a9ffc073975b436b031ac837b7eeefb0bn/aHeodo
2020-12-23BSLQE89H.docdoc ec49319ad4b8ab163292c8a1332640a715616436de18d6b1124f4cc51b3cb4c4Virustotal results 26.98%Heodo
2020-12-23HZA0KN.docdoc 1f5a0f7a62383b576ac6f661f97a2c035e72d6f054e5b63ea53123ed9081dae6n/aHeodo
2020-12-23L2QERIN2YCRF7Q.docdoc 31f327ab8307786ee50af20aaf5c4c2b6ecc974b69a584c78a2dce04fe5d327en/aHeodo
2020-12-23LW9EQ6Q.docdoc b1903f421885c0c1f5f9750dcdc985ec86a256298113e4c14360578feece4165n/aHeodo
2020-12-2335PGTGAFFWN91.docdoc d4b572062438c3b6331322be310ee0209e104c180931c63dab258983c69f6dadn/aHeodo
2020-12-23A0VF4KUXK9YVB9H.docdoc 64e04bddf27b3d535ea895f4dc08267a98a4c401edadc68e3caf7f6f850c4f64Virustotal results 25.40%Heodo
2020-12-22FAB1OQAE41C.docdoc 5c4cab29ee87b07eb6a57ccad782631b9281fa4db8f0a1b12d2672584426ccceVirustotal results 25.40%Heodo
2020-12-22NN8W5H4.docdoc 32dbb92d892c9f50e99fc70db5b9f3efe0721a6464984a3f84e6592cda81684cVirustotal results 24.59%Heodo
2020-12-22GI2ZYRFSK0EMTBB9.docdoc 05c57f48c8b1958bf16f64a292f9aa05a43f6185d02c54a0d8cf03b2fbc56ab5Virustotal results 25.40%Heodo
2020-12-22DVGQIG.docdoc 893d0822b033e0d5ea0484d9a61ce0354833603684cfb54e8e493f2740641784n/aHeodo
2020-12-22HSHAD9I.docdoc 2d523850bbd1d5abcaf76fcaceba272f038d954a97263941a3375c3301a1e2eeVirustotal results 20.63%Heodo
2020-12-22BD19VJ29G4HQBXJF.docdoc 1c0233deb27fbf738f72f7bc6e49a858f4c60d68ac5f45e12eeb8e25696d79e4n/aHeodo
2020-12-22YU1TYCG28S4.docdoc 3341a695c836613d9bba02fa005f2413c407d48a7fd940180b6d4c38788fa592Virustotal results 20.63%Heodo
2020-12-22IVUJR4SFV0W4QTCT.docdoc ca5ed41e13462908c3e7441204044d8519693a667e88e9ffff1cc566247f915fVirustotal results 20.63%Heodo