URLhaus Database

You are currently viewing the URLhaus database entry for https://gtvstreamz.com/whmcs1/s7q5u6a-10zs-956/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:300692
URL: https://gtvstreamz.com/whmcs1/s7q5u6a-10zs-956/
URL Status:Offline
Host: gtvstreamz.com
Date added:2020-01-29 02:57:09 UTC
Last online:2020-02-27 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 02:58:04 UTC to abuse{at}ovh[dot]net)
Takedown time:29 days, 14 hours, 46 minutes Bad (down since 2020-02-27 17:44:10 UTC)
Tags:doc emotet link epoch3 GandCrab link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-31Invoice ITT9_2116143.docdoc 0bc8fbdffdd026661700a901a68d6cff4cea5837c35fb1cab2d524f89eb8f0c8Virustotal results 34.38% Heodo
2020-01-31Invoice-KP75_7086689.docdoc 933fafacef72ddc88d72a24e9b8ccfdbef7cfff0a1e8ee8789e893e43ad6486fVirustotal results 39.06% Heodo
2020-01-31INVOICE-WVB5_816813758.docdoc 1092c9cc1b0dbf643c81898c30d3034b4db59f49a86de85ced39a5315ce4549eVirustotal results 35.94% 
2020-01-30INVOICE_ACK299_01850400.docdoc b93c176b25e95c8538cc6e80bf1dca7b57ab9a7fe306415caed9989f1c306dd3Virustotal results 33.87% Ransomware.GandCrab
2020-01-30Inv-G841_431116.docdoc 9755ef1672fe2fea84ded8999cf71bd62d9a3873bd4fa6ddafab57f59f0527f4Virustotal results 33.33% Heodo
2020-01-30invoice-NRJK28_477905.docdoc 9e5e33a967ae502e2a528fd31502336cc68f2deff565b4760bc2eee148ae87f7Virustotal results 35.48% 
2020-01-30invoice-UC126_3448845.docdoc ad23200b4b35cf861876a41444203cb74f57e2be7bfddbc92b3fc7a07ecfe056Virustotal results 34.38% Heodo
2020-01-30Invoice_WR13_3729276.docdoc 2e05dae96f07956982b9edba6d64d8668b4ff90f56d548ce2ef2feee40a6e6d5Virustotal results 39.06% Heodo
2020-01-30INVOICE WCRN702_162477780.docdoc 4b8c920544a36d2b2fe8e35aafddad4a1052e8cced8e159cf4b9753d1c1a82eeVirustotal results 38.71% Heodo
2020-01-30INVOICE_F344_435438124.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30Inv-DD580_279957526.docdoc 444380961c88bf398e9078529bf648cf7f4cc69a583fea9d036c4427e533d8c5Virustotal results 34.92% Heodo
2020-01-30Inv-TCI17_537447672.docdoc 59143f942ffc2f0d43226ecdbc3042d66ba488b6fe44506a5301169d1e6306e0Virustotal results 32.26% Heodo
2020-01-30INVOICE-W4_6493683.docdoc e88c11fe26e7cad165df54049eeb12ea47f3cbb684fb6f8a5235d4a379e646ddVirustotal results 31.75% Heodo
2020-01-29Invoice 767_078039.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29INVOICE-UQ5285_521463321.docdoc e14bd51bea91be160aefdfd75c853ce85ef348e87400f0d1e14b64c7d46eb748Virustotal results 33.87% Heodo
2020-01-29Inv_XHF7686_35368697.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29INVOICE-84_802230407.docdoc 0e7d6a780c7dedc2d2625158cde219a2df7eb7b37a509c810644085e1781eb12Virustotal results 29.69% Heodo
2020-01-29Inv-PQH5331_2836920.docdoc 7bfcb28623bb456b78495610797c508f2f0d900d9f5917557ef2e021b03f4349Virustotal results 29.51% Heodo
2020-01-29Inv-ONQY129_9332411.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29INVOICE_ZG853_66445513.docdoc 3be00db967f63065494037f5de7659deb23f83c948d103057222421fc50cc775Virustotal results 28.57% Heodo
2020-01-29INVOICE-HI01_735503.docdoc 603a04c67b941a3ff9345c94e890896e5570dd544e8ca3998f5197f45ab28f00Virustotal results 26.56% 
2020-01-29Invoice TGN68_0171824.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29invoice_F660_502098.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29Invoice-532_435657.docdoc e8f8cbc324e2601a0d32232c887aa398adfc45984b6a254666b95a1c00ef496aVirustotal results 30.00% Heodo
2020-01-29Invoice-C6_52122730.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29Invoice FO51_186204506.docdoc f51d2aa766b1b07701a52e866f50132c0fcfaad288c1aaf13c781a66db3168daVirustotal results 47.62% Heodo
2020-01-29Inv_D9655_1831935.docdoc 11b4519b76957b0758381f8e19c5e15d8744f7974716642aeb586c615dde38faVirustotal results 48.39% Heodo
2020-01-29INVOICE M92_94652151.docdoc 7a9f249978c959e1f11f2992a8ce4a70ba333c8dbdc2638c780bbbe62de4808eVirustotal results 46.03% 
2020-01-29Invoice_NCYD83_14759836.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29Invoice ZZ0_32521115.docdoc a080d763c60efd4ef2781ad3090c997d1092ac726707366d92d647f26ee2965fVirustotal results 46.88% Heodo
2020-01-29invoice C3859_724467.docdoc 8c0a8d6876a6c7fe44962883561d9f48615ee67f4544872ec98f47edcf516509Virustotal results 47.62%