URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ocyoungactors.com/NzGucd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:35569
URL: http://www.ocyoungactors.com/NzGucd/
URL Status:Offline
Host: www.ocyoungactors.com
Date added:2018-07-24 15:13:04 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2018-07-24 15:26:44 UTC to abuse{at}godaddy[dot]com)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-2507280.exeexe 3303ccbc6fcfbd3259c77eb78bfeaa4d886f0dd93f14ab40a783a3b91ccdd480Virustotal results 23.53% 
2018-07-258478001.exeexe a0989578a8b6d5d904fe50eef223d6a7719a06a879b8bc6d322a08fa98e88828Virustotal results 28.36% Heodo
2018-07-2504993627.exeexe 280a41de78f0ff60089d14f45e034c117344dcc4bfcde4f2d0919e4a63bd134dVirustotal results 29.85% Heodo
2018-07-2544.exeexe acca71af44949e0cd13a00c8a1a5cfb2a17a64a359ad7e74695063d296d9e17eVirustotal results 23.53% 
2018-07-253122802.exeexe d6165436f66922fa040582b024c9eb4ce90f8dbb76e3cbc9f7ba5ee85f8ca029Virustotal results 20.90% 
2018-07-25382.exeexe ca87f8bae15f0f6fc826671beba007bc5f507dafafbc26d1f2b32a7d846d35den/a Heodo
2018-07-256500168.exeexe 20905342140a5614554596d1219af85bc7085379a24ce61698e2ea108e770258Virustotal results 23.53% Heodo
2018-07-2438272731.exeexe 16b8a5a34391c1ee824a1e4e2551cf92e67b9cd0f6d37c3ebde26c082566a548Virustotal results 22.06% Heodo
2018-07-2474.exeexe d9f3f588c3b6d7ed14103f2ca5bcddbcaeaee2fc5dccfecc111588f861b5d882Virustotal results 20.59% Heodo
2018-07-24791.exeexe d41f5cad9cc0742b3536f87e4cc25ae3fdae0bea6d632b89741bc978cd6b0307Virustotal results 22.06% Heodo
2018-07-2415697.exeexe 417c880a895e2f10df6add57d48b6deb97b8bd64d162733eb8edf2c3e5e12295Virustotal results 25.00% Heodo
2018-07-24250.exeexe 83c7c3b1b5ecbc8e157ec9f322c11d5614121110169c2896a8275b099b98f26aVirustotal results 17.65% 
2018-07-2431615.exeexe 5ebca36ff08a8b755e05bee6b726a10687c417b516f6b7fa049ad142e285f996Virustotal results 20.59% Heodo
2018-07-2459652.exeexe 3249aa85ca32276dc782be08be5a20bc81b0e76e94865f0aa5d22e53836e4400Virustotal results 27.94%