URLhaus Database

You are currently viewing the URLhaus database entry for https://blog.tqdesign.vn/banner/uW/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972523
URL: https://blog.tqdesign.vn/banner/uW/
URL Status:Offline
Host: blog.tqdesign.vn
Date added:2021-01-20 17:49:14 UTC
Last online:2021-01-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 17:50:08 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:23 hours, 27 minutes Good (down since 2021-01-21 17:17:53 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-20JQgLMYUd9Iavg.dlldll 03ff40768f2c5dfb8c60c977b173ab72abc0932ccd13d139115bf7f0ddcdb323Virustotal results 31.88%Heodo
2021-01-20S5Dm9Gv.dlldll 9c11f342fe01daf29eec259b987042ce1c9201d2ac2196818552c8fcdca4ee7fVirustotal results 44.12% Heodo
2021-01-20mmHvgo2zZ.dlldll 0c536df734e5a977a974350951bcdc0f70036f32255cd88505446b0eb3c5e19an/a Heodo
2021-01-209aCwc0sy.dlldll b7f4bb9f024afa150cd10992ae89e648b5d7e056df175775963aad1ecacbbb79Virustotal results 46.27% Heodo
2021-01-20x73uO4LCOEJX17PaN.dlldll 058bc12e279ec16f5207ce4b42273b77201fcecb5b7e39ec191ff28f3a948d54n/a Heodo
2021-01-20zs0ckk9xR07S.dlldll 539183ea970d7b804e288bec1469186579e3990f644f7fe9427ed724335d0858Virustotal results 42.65% Heodo
2021-01-20R9yeMhjTA3pq3a.dlldll 8a0075a5ece8acca85dcf370cecfccb970143ce416b426c98ee023dd52d9d7aeVirustotal results 42.03% Heodo
2021-01-209nk6G.dlldll bd5f574091cbc8bb03ac25a4964f5080c4b4a0a61d06d639857acbd99ca99cc8Virustotal results 42.65% Heodo
2021-01-201l1RwE.dlldll 64457efec4cb33cbbeda408da1490ccb13a04598eb7bbef74c91eabaf4a6f86en/a Heodo
2021-01-206OU.dlldll 083d8c9dfbfe2e395bbb0567c6f992f55264be98af888c410a707e7e9c9f1436n/a Heodo
2021-01-20ZNwA3FZGA.dlldll d268e565311b27d0fd049aea289ccb499f69e774e3c01bc246a1598112b1d767n/a Heodo
2021-01-20zE.dlldll 1ad26d1721683a213d40280383b761c20152a1595c22721b2f79a71f1a53d693n/a Heodo
2021-01-20lUgO4JJ.dlldll 356eab7d35d2a3889b67b6849a9c715f74aefc55ab76f880bb4cdb5c478411feVirustotal results 42.03% Heodo
2021-01-20Yk4vvI.dlldll 36b8d1ec76e7d2bb24cab0f41f421b5ac1555707d998cdb7ae611cd9eb3b48d2n/a Heodo
2021-01-20Dax.dlldll eb30c7cd2fcbe118ae4526b1ee0c1df77c30ac19271743c454ed5f68aecfa302Virustotal results 40.58% Heodo
2021-01-20JrYeZZ38re.dlldll 7ba9e6f169f3e7d08ee64e70a57a56f64e1cebecb0b71bf051f4bbafefd4b2c0n/a Heodo
2021-01-20OYw.dlldll f5e7be3d701e66419cf99103aee3638799fa7027b1ef55fa1ba0161405e08285n/a Heodo
2021-01-20TzgWL5BHn0.dlldll 7af4612c0540759482dfa5d3257dcfde095be45a87bd749330f2996e0477146fn/a Heodo