URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ocyoungactors.com/bcfDx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36560
URL: http://www.ocyoungactors.com/bcfDx/
URL Status:Offline
Host: www.ocyoungactors.com
Date added:2018-07-28 16:24:03 UTC
Last online:2018-09-08 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2018-07-28 16:32:16 UTC to abuse{at}godaddy[dot]com)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-291.exeexe 998a2883d9e00fce19047fd7d22fad820511fd87fcca343ea3e68e41f3c7f730Virustotal results 27.94% Heodo
2018-07-2835840392.exeexe 4d0ebbb2428d7afad4449d56c30c6e96ed6e30d82cb5b3c559ba9c178e625a53Virustotal results 26.87% 
2018-07-284514.exeexe 587dbcd1a27ce5b81c42b71915d212d6d4657aa58f9a14f2db975878d0703d59Virustotal results 23.53% Heodo
2018-07-2850.exeexe a4784cf8c910d4e643b184a750526e2d4d96989c13f70291f4621dd73cb6fd58Virustotal results 27.94% Heodo
2018-07-288.exeexe d6ae527abe65dd8c2fa5b7c2a523bdd7a1c1242f0fb8357496f14b5b7f652002Virustotal results 31.34% Heodo
2018-07-286726.exeexe 705e1cd235874b28f256179410495803bbe01f1a41ba394b266fb28d293629daVirustotal results 25.00% Heodo