URLhaus Database

You are currently viewing the URLhaus database entry for https://ngoctugroup.com/wp-content/RkIbwmIKHanfVqRtHViJyBCQsepi6zvgWQ7ubJKPJeINbqyyt3MLhkeNHhTSqP6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974660
URL: https://ngoctugroup.com/wp-content/RkIbwmIKHanfVqRtHViJyBCQsepi6zvgWQ7ubJKPJeINbqyyt3MLhkeNHhTSqP6/
URL Status:Offline
Host: ngoctugroup.com
Date added:2021-01-23 00:18:09 UTC
Last online:2021-01-26 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-23 00:20:18 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:3 days, 1 hours, 40 minutes Bad (down since 2021-01-26 02:00:47 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23JBF25BCCAZ08JN.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-233VDHOUPUUCAYBIW.docdoc 57d7ff4664c6bffcb350211f1d9cbc272747c201c3c784fcfbab0f49c986f53en/aHeodo
2021-01-23PONRP1JB8NINTFM.docdoc d748bb7a8d447b8bbcbea5a3d20a404351c3ea3dacc3f332a41f44f138be5320n/aHeodo
2021-01-23NWRCSQDJPYJM6.docdoc e7ee687cd06e406cad317080de4ba7a41dc9bc8ee8f8a35c76003488b502dc5dVirustotal results 50.82%Heodo
2021-01-23U6PL0OH.docdoc 156db699149efcab714cb9f97ccef3b2179e9a3c53d20e6e0ad7e318e17ac1bcn/aHeodo
2021-01-238D6C4N1A.docdoc f967919221798935016821892199d1eaf45960045a79bf0ecb89297edf4d4cfcVirustotal results 53.97%Heodo
2021-01-23MDPD5EN.docdoc e3a0c8c17306e77db4fca51970cd0372508a59234fb62ae5e0cc6656e1fa5595n/aHeodo
2021-01-236Q5UBNA87MK.docdoc 10dc55d6131467b2ef53cc13475499dd9f34965a9c847672f707617fc6e2e6cdn/aHeodo
2021-01-23ANNUED2BQV.docdoc dcfb145c4f46a072e988cdeafc065f8116dc3b27d6bed447024677f3ea2f252aVirustotal results 53.23%Heodo
2021-01-23CF58X52MAWENI.docdoc d25637cf316cb6635d17034fb9bfe5334c47f0ef16cc18b178f1a74a48c9b178Virustotal results 53.97%Heodo
2021-01-232YBZRG51H0.docdoc 25f478a34fccb4ec1f646b9200c1e2a858b23019bcc5b7b82a9378297f13f73en/aHeodo
2021-01-23484Y2T.docdoc 1d131a111ffcfdeda18316ead79206237e3684246c4cb6ddc191994737f0294cn/aHeodo
2021-01-232QHNAX2XJTCXOXE8.docdoc bda05c4ef660a15d781f9d7c44415a119d2137f46a63b124b6a154e382ad7fban/aHeodo
2021-01-23ZI4H5OBEYAU79.docdoc 24093743cc1b5882bb6b43c3712d06a13dad73e41f2c95f44d71286d515a1120n/aHeodo
2021-01-23RRO48ZD.docdoc a5e5efdf01f81fd9ba75a7f4a0f2ff53fc5f9f7b3edb6b80036f3add9d1b370bn/aHeodo
2021-01-23OTNQC3T.docdoc ac3a231f0035c95d710e53ec6dd86a4a915dc23b12238c4d118e7c2b656cad2fVirustotal results 50.79%Heodo
2021-01-23JVX9DB5X.docdoc c8772e6f063119876caf953c8fd7fab91d44c31fae432266a35b9cb66233da92Virustotal results 55.74%Heodo
2021-01-23OOAHZHWPBOQ.docdoc 0d95efeb799d69a27255270804aa8efa5e91cd71b55943e37e88e772c961bca2Virustotal results 51.61%Heodo
2021-01-236REIXMC3NM.docdoc 76aa5ad0c47b29855238c26ef7af65678803515eeda4ea34984871a644c45086Virustotal results 52.46%Heodo
2021-01-23YT7K050PLQSXK.docdoc dc1657890758c8563c82d9c1bdb8aa05bc4c965868247d1ac28334925e1fe12cn/aHeodo
2021-01-23W97U12H97UDEWU6.docdoc 88b4e1657c14287bb263fcb0ed92b0b58b294c9b6e822cc1dcd152e08346dc5fn/aHeodo
2021-01-235RTENPMY3X0O.docdoc e621537a061ede5d0f947fecfccc7e9568fbc21942c2b64801138b227e4f23e4Virustotal results 49.18%Heodo
2021-01-23K8I22FKA2TE3.docdoc 843ac5a5070a8f77eeb150cf7963ea5a66dd5763b0e3ac3d775333219fa5b773Virustotal results 49.21%Heodo
2021-01-23GAZN1I73.docdoc 3b8c1a7288a8940c4785141389d323f7949b9639ca7821ebad1fc2182a2acf58Virustotal results 48.39%Heodo
2021-01-232FSRA11HQWI39E2.docdoc d926e60d6b78f6b07a61842aa31c25077849e0921bbb8c454900a6b1447427c0Virustotal results 34.92%Heodo
2021-01-238IS7M7M9.docdoc d24e032bf95e95b0c1325688cb50b3eab851e90b9350f1a031668dd2bbfac3b6n/aHeodo
2021-01-23KSTNUV1M95321.docdoc 56e78f5aeb76d3b2002f79b51c0344a1bc95e0c171a56f5e7bae43028543e1cfn/aHeodo
2021-01-2315MU9Y8UD2ZEPD.docdoc 20b1f1c932f9ac88685c65ca2ed2d57ba42e6cc5d643c567fbff933e64e09797Virustotal results 48.39%Heodo
2021-01-234U89D4HZK2SBRB.docdoc 1e6cf8d2575be1847bd2c4e53b2686b8346c940c315c68f3dcabe5fc53802dd8Virustotal results 46.77%Heodo
2021-01-23NQ3PGCMV6Q.docdoc f2f810ac8d53caf7b5ad3fa8566ed61610f1ef80b7a9ef571b9bd112ba745909Virustotal results 31.75%Heodo
2021-01-23A0P8QQ.docdoc d02c5f5315f50e3865102448adebb8353c06fe90d4c08ed09cbac7572a83076fn/aHeodo
2021-01-23ZTQ5L7V.docdoc 9fab5bfdf6aee085fdc28360f1a5473f5ac94a97722377c40c572e0fe20cd9b8Virustotal results 46.03%Heodo
2021-01-23UBEV7G1DQ23B.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8eVirustotal results 46.77%Heodo