URLhaus Database

You are currently viewing the URLhaus database entry for http://www.btreesystems.com/wp-content/GJgoVGMW/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436904
URL: http://www.btreesystems.com/wp-content/GJgoVGMW/
URL Status:Offline
Host: www.btreesystems.com
Date added:2020-08-19 22:01:29 UTC
Last online:2020-08-21 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002876427 created on 2020-08-19 22:02:08 UTC)
Takedown time:1 day, 21 hours, 50 minutes Poor (down since 2020-08-21 19:52:16 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21FY-080120 OBPX-082120.docdoc b79c89f1882c609b4abca4db5b83aace234943227d1cc9c3624f1f063d348e41Virustotal results 26.32%Heodo
2020-08-21invoices 3719 & 5993.docdoc 9c3f81236f7fcb19d6e1304ad6c89255461a66f783e372f62c8fc93fa4bfcd8eVirustotal results 25.86%Heodo
2020-08-21Form.docdoc fa793702b351ab1f22fa5ff1d20c7f6bf822bd6954f637389577767a163275bdVirustotal results 25.86%Heodo
2020-08-21Electronic form.docdoc b7e0ba8f8567d8ee7a59765814c534ba0c4b1044ae4dceca564f53124b45aa36Virustotal results 25.86%Heodo
2020-08-21Invoice 0080749.docdoc c6c8fb9bb0d155bb4fe8b4b7904de586efbf5c79f49877313b380b848ad12da1Virustotal results 27.12%Heodo
2020-08-21invoice.docdoc fa73c7c4709f00943c0995e1c8b64edce7bd0443e3a2fa1c4940c978d35fa794Virustotal results 23.33%Heodo
2020-08-21Payment status.docdoc a2ea0e47b148324c482d896b2341907e780e4e32f4b801e7422bb1b6a6520819Virustotal results 22.41%Heodo
2020-08-21August invoice.docdoc 7bf19f22efc3105310b2bf37df600a6d3bb4d2136d4ae4c7e0454ffbdb3939aeVirustotal results 21.43%Heodo
2020-08-219682227.docdoc b6626dc337993fee7f16f75e84c6cf42a738e50d76806571f2f9b4a8efec49d2Virustotal results 21.43%Heodo
2020-08-21Invoice.docdoc e8b022037ce9db5f0d89c476b1774684986ea2b643baead908f4a06f22012bacVirustotal results 22.41%Heodo
2020-08-21Payment status.docdoc 13fa777481b0ef753826e2f217ba603567e9cb0b86cf7560b440caaa935e829bVirustotal results 21.05%Heodo
2020-08-21invoice #1704.docdoc 403c11dfcd14c01cf91b6fc45cb7ef0a55919e8e5e0292399e1cbe734bb9d2a3Virustotal results 20.69%Heodo
2020-08-21Inv. 00766241148.docdoc ba4bb5f049cb59a1eb23f083cf22fe726a7d87f12e9b577f2eb52102b55496bcn/aHeodo
2020-08-21Invoice #109932.docdoc 119ea90f9ae4392e35ad517dbab4465ac0f0ae12cb58b0e85f007e105bb91036Virustotal results 21.05%Heodo
2020-08-21Electronic form.docdoc 4da5e980866878da930be670800361fd6b9b6ec73983dd60cdba9eb29bd09ab6Virustotal results 22.03%Heodo
2020-08-21invoice #9765.docdoc 1c8f1124a4ccfc01bfc51367aeeda6685df4fc2ffc245deca3430582af9e816aVirustotal results 20.69%Heodo
2020-08-21Payment status.docdoc bfa9030c4923b22a26ab343f17ace0c0b90cb5a79c02e635937d73b994c50b42Virustotal results 18.64%Heodo
2020-08-21INV_9532.docdoc 1379c04142852211fa0a0fa5b67d4f96ec3109824d6c39002d6691ffc2c7b9c7Virustotal results 20.00%Heodo
2020-08-21D8415069131EX.docdoc 8ffb84f76b863917f3ef52c3c75dfa70bc77599b7deb86067b43c413c8ff681cVirustotal results 20.34%Heodo
2020-08-21Invoice #851429051.docdoc 13d2079b2caabbd56dc776517810d9dbf355138869ff3030314e9f4905e68192Virustotal results 18.64%Heodo
2020-08-21Inv_799448.docdoc 0d9f1f173fd3806d10312760c50f85b6fa23b65193732358ef675b670c84f5eeVirustotal results 21.67%Heodo
2020-08-21Invoice #93541.docdoc 27e58aecfab42bc8d94aee0b51ae82f1f6364e61e448956650480710e64596f0Virustotal results 21.67%Heodo
2020-08-21form.docdoc 97b387cc7ac53574e95b7d09f100821989778d4fc076acebf7b546f24b500280Virustotal results 18.97%Heodo
2020-08-21invoices 938 & 9621.docdoc 3d0173175bbc0f83d9a5a2b8324c817f6a433756949f63691ec5374d82859a6fVirustotal results 18.33%Heodo
2020-08-210090017.docdoc 1956596f7ed909a0c2291a2a8b6ce38918255ae87ced9b557c898972bcce4d42n/aHeodo
2020-08-21invoice.docdoc 310dc3ae17963a0ac8df3cda0697749f205c3c01787d4e24026bc30ccb7f90b5Virustotal results 20.34%Heodo
2020-08-21Form - Aug 21, 2020.docdoc be0c986b37c30a192c9f2e62d6c85b635a3e25bc10cb8a8b4ddac390bbc93163Virustotal results 21.05%Heodo
2020-08-21Inv. 006569991940.docdoc ad61f377cd0d259cfabac17a4a874cd5dbd88b076e00680d5fb1d31706816ca7n/aHeodo
2020-08-21FX9277836554ZB.docdoc 1313ff749e2cbb39eb12cd00b080dc06159270b9309b7211be0fb2223b924d1fVirustotal results 20.00%Heodo
2020-08-20Inv_72858.docdoc ed8f3cd480b6fef9996f65e02cc1cb3d295447728fd009032ac3838d32e01f37Virustotal results 33.33%Heodo
2020-08-20Form.docdoc 9c2952185499dfb564607790c299bf8a01a0bd16d64484be1812bfc88c5f5a06n/aHeodo
2020-08-20PO# 08212020.docdoc 7e65999218e740149ebaffa84725ce3f6f0cecd5b565bf4f0e3c5f546785513cVirustotal results 32.20%Heodo
2020-08-20Electronic form.docdoc 4e132ba6d019767be2f8156e367e5c0f60ee91db33f3517c525d22cace8bfa9bn/aHeodo
2020-08-20invoice #19563.docdoc 8396ea542554b554875f9a90fc2135537f7d8c95b5a3cde99df06bc3686ac5cen/aHeodo
2020-08-20invoices 30344 & 44657.docdoc 0ce1f9eb5a77c80202cc0a91a877c8385bcbc61b6c7c2a5fd5a093a7b181fb1bVirustotal results 32.20%Heodo
2020-08-20S082 invoicing.docdoc 0c9bdaf25bc6465c491f19c920faa56544188ae9d41c7a0905bda06a835b6ec4n/aHeodo
2020-08-20Payment.docdoc f457c31693c17d7acdb742f48c6956eacee52a2ecc0a3e126b6741050d067c58Virustotal results 30.00%Heodo
2020-08-20invoice.docdoc acf06f69fc335f401184ad3a218aec5075641fe29bce91e0f71b698c062b3e0bVirustotal results 30.00%Heodo
2020-08-20Form - Aug 20, 2020.docdoc e79f874f85e1c3d9217c3f5c561ccc6fedc03704529d9b29e5908a7e61b1d847Virustotal results 28.33%Heodo
2020-08-20August Invoice.docdoc dfa76e9900bf8cbd12e33296a77b645201adf2d0fd4977e777eb203cd11f1b3dn/aHeodo
2020-08-20INV_9162.docdoc ae09a760faec9e5c8f9d147329271cb1fa3971b119943d8cc9e16ce71c8e5fd3Virustotal results 25.00%Heodo
2020-08-20Inv. 6380020.docdoc 91c3f7f249f29faae299c119c3c8c07ad2bcbcf4e572530355728f63309e4f5eVirustotal results 25.00%Heodo
2020-08-20form.docdoc 722219128e30ae7a17fbcf0d24147c7713f628e28f3af2117130c95e0d75005dVirustotal results 22.03%Heodo
2020-08-20N-080120 ZNPB-082020.docdoc f1e4e7a1d71c377899c94ab6ba2c70968064a086ed611861df47c68a51b56deaVirustotal results 21.67%Heodo
2020-08-20Inv_4520.docdoc fb7cec2bb2ac4c31c65e299f198a586f5c5918f975075467063f59d48d28844bVirustotal results 22.03%Heodo
2020-08-20form.docdoc b98c8587312b2674ec04ec4c3cccd572e53475f8c51922bf5418d51f07b006b5n/aHeodo
2020-08-20invoice #54797.docdoc 5e6920997e99874f5e30251f342e96229bda71fb517b0b5ca632cf948b8972ecn/aHeodo
2020-08-20Form.docdoc 7177e2e37fc39a2e6a83875aca9a3ee888a88d8bc6538b81556edebfe11067ban/a Heodo
2020-08-20form.docdoc c2860e92b00a96df1031b68a98c104f55bfdc472da83ab5c7d4ebfada4a70383n/aHeodo
2020-08-20invoices 77772 & 64348.docdoc ce4cd4d124a577ac6f489568a077a53e6745170cb71a64c5b4bcba502af51347Virustotal results 21.67%Heodo
2020-08-20Form - Aug 20, 2020.docdoc 6d84d53acd4a3905be6deb9ff50cfefa0681838bc7906ade311e113fb5d02bf1Virustotal results 22.95%Heodo
2020-08-20August invoice.docdoc 65d358d5c25eda27078f168b3fd190c5250bfdf1b58bceb28681f2535de96423Virustotal results 41.67%Heodo
2020-08-20Invoice #01831.docdoc 35cdbc32f50870b20e2cd551f4805152d7ff4c9a9977739de4036d9fe76a6e0cVirustotal results 42.31%Heodo
2020-08-20Payment.docdoc b462b6985f21115db5a18167bd1701f4a2599116fe237a0156cc2cce93e96edbVirustotal results 38.33%Heodo
2020-08-20form.docdoc 1ded2d7cc228ed55fcd64164252d2a2da11cf10ad774d7315bcccd449336ae72n/aHeodo
2020-08-20Electronic form.docdoc 65888689126472383a73d6085058a25ef793eee01025368fa775fceb4d8b0f0cn/aHeodo
2020-08-200038412.docdoc 210f3cffbbc984d2b04c012fb54991ba7cec609aaf5d6e97c4b7715fa179a770Virustotal results 40.00%Heodo
2020-08-20Inv_023868.docdoc f378d52ca240609ddf42cfd7fe5f3c83ed70ce0e560a3e669e0e8c229a9c1f28Virustotal results 40.98%Heodo
2020-08-20Form.docdoc 252905fc07b8d4de77b22dd1c68bba23716cb7bfbf56bae15a624f59b7e69c70Virustotal results 38.33%Heodo
2020-08-20August Invoice.docdoc a0601dc3c3afeb7471b9fe739ce24e0b476d100c3f2ee756df211888184f67f0Virustotal results 36.67%Heodo
2020-08-20INV #0711245 FOR PO #09491662.docdoc e10d9e51f37cac947f9dac20f25fe6c9cdbc9a27072d1f54575087d0d63179fbVirustotal results 38.33%Heodo
2020-08-20Invoice 02865566.docdoc 3873789add951f7faaee58644422e134440be2903271725124cff640acd0ad4dn/aHeodo
2020-08-20JNF-080120 LMNZ-082020.docdoc 416a4f17b5bc066941020cd43640276363268db7cb067a8cc7f1d27c3cb3cdb2n/aHeodo
2020-08-20Invoice #909.docdoc fa10393ccc08487ee9b80a41d01c9e5e87c3c7690a74327b1b19e47f3638b66cn/aHeodo
2020-08-20form.docdoc 2cceef317fac265bf56fc5819196f6a58b95574e8085a889f61ed9cd5c6c387bn/aHeodo
2020-08-20PO# 08202020.docdoc 741eedc40d043df1d8abba1e18fdeab3d276fd970087ad3b980243aba3c4878fn/aHeodo
2020-08-20invoice #1553.docdoc 04a14a477cf1d1d2e5a426b932542d931d6264a101a10da26141be2752db8a72Virustotal results 38.33%Heodo
2020-08-20August Invoice.docdoc cf817564329bd4a2f3c9cdb4ce0609048d648917967fa9f9ff5c05a656ee3cbfVirustotal results 35.00%Heodo
2020-08-1900309667.docdoc 8fef0fa03aec63f50c5f6c1b055fc5c7c90f092a2b4549ef022e6696d49c9bb7Virustotal results 35.00% Heodo
2020-08-19Copy invoice #771907.docdoc 2fc56ee5347ed1b4ccad0bc19cb9e09bac40d9fb5bc0accb8bab80a2eb7d86bdn/aHeodo
2020-08-19INV_1161.docdoc 2a532523cb09773c9d7a9dcdd27af27c026dcf5a433abf13c392fa73b32b8fb2n/aHeodo