URLhaus Database

You are currently viewing the URLhaus database entry for http://khoahoctiengnhat.ngoaingufpt.edu.vn/python-code-zwz62/GbP0OXk1YGgV/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974808
URL: http://khoahoctiengnhat.ngoaingufpt.edu.vn/python-code-zwz62/GbP0OXk1YGgV/
URL Status:Offline
Host: khoahoctiengnhat.ngoaingufpt.edu.vn
Date added:2021-01-23 03:30:23 UTC
Last online:2021-01-24 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-23 03:32:04 UTC to hm-changed{at}vnnic[dot]vn)
Takedown time:1 day, 13 hours, 29 minutes Poor (down since 2021-01-24 17:01:30 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23AQWPGYCDD9DZK.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-23LWP3ECASNR7IRG.docdoc 33c3b2856eefdb51dd0d8798ddaeac57d3a1b63fe1cf86732f08d2cc5b1b851fVirustotal results 52.38%Heodo
2021-01-23MEDKTWJRPGTO81W.docdoc 57d7ff4664c6bffcb350211f1d9cbc272747c201c3c784fcfbab0f49c986f53eVirustotal results 52.38%Heodo
2021-01-23I8HIYR99PUDS.docdoc 3f67cebcc062ff44206ad6b1c356021133426bcb3a4070824b03036e36ba17can/aHeodo
2021-01-234G0TKCH22.docdoc e7ee687cd06e406cad317080de4ba7a41dc9bc8ee8f8a35c76003488b502dc5dn/aHeodo
2021-01-23N3S2Z12FJ.docdoc 156db699149efcab714cb9f97ccef3b2179e9a3c53d20e6e0ad7e318e17ac1bcn/aHeodo
2021-01-234LKU42UFYRVTS.docdoc 28b78d04a0fa5ba6b6c3504f9d9a7664f16710d02d2e92be72e97f03ae3a690dn/aHeodo
2021-01-23TD2HI40YQU6H5.docdoc e3a0c8c17306e77db4fca51970cd0372508a59234fb62ae5e0cc6656e1fa5595n/aHeodo
2021-01-23TYZVJCEQ.docdoc 10dc55d6131467b2ef53cc13475499dd9f34965a9c847672f707617fc6e2e6cdVirustotal results 51.67%Heodo
2021-01-23CI83QXTHFP8V366.docdoc f44e4ec9321617fcdfcb91fa516a2c17f3d14fe21ba167f0db47e448fd37a0bbn/aHeodo
2021-01-233GCMZNPHLYT6.docdoc d25637cf316cb6635d17034fb9bfe5334c47f0ef16cc18b178f1a74a48c9b178Virustotal results 33.87%Heodo
2021-01-23QECWF84RD0H2F0N.docdoc 25f478a34fccb4ec1f646b9200c1e2a858b23019bcc5b7b82a9378297f13f73en/aHeodo
2021-01-23AFT2BKFF8B.docdoc 1d131a111ffcfdeda18316ead79206237e3684246c4cb6ddc191994737f0294cVirustotal results 54.24%Heodo
2021-01-23PU7RMK8.docdoc bda05c4ef660a15d781f9d7c44415a119d2137f46a63b124b6a154e382ad7fbaVirustotal results 52.38%Heodo
2021-01-237EM4JAFQULHNHDMA.docdoc a5e5efdf01f81fd9ba75a7f4a0f2ff53fc5f9f7b3edb6b80036f3add9d1b370bVirustotal results 52.38%Heodo
2021-01-23T33LQ8VI7.docdoc 3e2601aa7c53742f621bec3989a72e0c2db710586817cfc0067b9557e7346935Virustotal results 51.61%Heodo
2021-01-23NCTD6PVZ7BUM.docdoc ac3a231f0035c95d710e53ec6dd86a4a915dc23b12238c4d118e7c2b656cad2fVirustotal results 53.23%Heodo
2021-01-23BXDZ91.docdoc bbefec31ea0c2301e8202d73acf49ca0d72f4a3b80b6a81836e49b1591d3d78cVirustotal results 52.38%Heodo
2021-01-23683WUQ63DSOGA.docdoc a2d525c9bd8128160c64990fa84afc4da2bea8a72cfb4ca42f14cddac1343df2n/aHeodo
2021-01-23KESHJE3LU91.docdoc 76aa5ad0c47b29855238c26ef7af65678803515eeda4ea34984871a644c45086Virustotal results 52.46%Heodo