URLhaus Database

You are currently viewing the URLhaus database entry for https://dhm-hnou.edu.vn/wp-admin/SGLLDSNQLZmSdycnuD6seo2wVNms4IrB5IUDvdPj2nAAztBN4N5gnOqFs3DkvDFRqg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944183
URL: https://dhm-hnou.edu.vn/wp-admin/SGLLDSNQLZmSdycnuD6seo2wVNms4IrB5IUDvdPj2nAAztBN4N5gnOqFs3DkvDFRqg/
URL Status:Offline
Host: dhm-hnou.edu.vn
Date added:2020-12-29 00:27:06 UTC
Last online:2020-12-29 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-29 00:28:05 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 10 minutes Good (down since 2020-12-29 02:39:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-29HSOLCJB8QB73Z5.docdoc 89ce07abb5363601631f2875dfa84e1589ef67f12fef2f298f3a9855bfe6b5adVirustotal results 24.19%Heodo
2020-12-29QN6BKYRTQPFEK.docdoc 848e0330cd1da1e2fb741d0be0318a12fa415811131c0a6b7c52e5cf867821c6Virustotal results 25.40%Heodo
2020-12-29OWCJRLBEAC8F349B.docdoc 84008c13a44430bcf1f708a152bd99b047e38e4f66c500d5e6c9fbe3c9fac84dVirustotal results 23.81%Heodo
2020-12-29W8KG853BOZC.docdoc eed7eb4ff2b2f729e064ed7664af159c315e5d2e1a63fbd8cb1db678af78eb9aVirustotal results 20.63%Heodo
2020-12-29WVDHMGD.docdoc 79a074f71a273b9dad370fefe33704deaf5e9b989812929e5d33900324dad3ffVirustotal results 21.31%Heodo
2020-12-2962Z5G08.docdoc 8fcc943501ddfa7e2823f4411808e41c8b64a442a12576822984f9bea555dd23n/aHeodo
2020-12-29OR27GXYU.docdoc f8558e66e35c0908e148fc2fee062a31346b00b7ef270ab1f062f17e6350a8cbVirustotal results 22.22%Heodo
2020-12-29Q4TT5PBNNV1G.docdoc b757c7ffb783759ec9464a1631212131a15f2aa4cdacb5f974e9f1c026dd4f59n/aHeodo
2020-12-29NAO4DLUTRLPXLK5Y.docdoc fcc61c1b3639ee120a6b1e8e9709614682434b8a6017bea91fef29a063f0d3b9Virustotal results 20.97%Heodo
2020-12-29S8DA21E0D.docdoc 7fc7c6555659146db226f7cf046df0b8dde431471f31038a688d0323a798a522n/aHeodo
2020-12-29EVL31VSEBYQ6.docdoc 4b2c9f87676f3cf3eb61380529d83e39e8ba3f87eaf2d64bde0dc70d75941104n/aHeodo