URLhaus Database

You are currently viewing the URLhaus database entry for http://ozzpot.com/OCT/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:452594
URL: http://ozzpot.com/OCT/
URL Status:Offline
Host: ozzpot.com
Date added:2020-09-03 17:14:34 UTC
Last online:2020-09-03 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-03 17:16:03 UTC to abuse{at}dreamhost[dot]com)
Takedown time:1 hour, 11 minutes Good (down since 2020-09-03 18:27:41 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-03Z_20249453.docdoc 2c0c601bfbdd05a5814ab7e8e49d11c6b756c405fe78e7e6d9d331578f042df3Virustotal results 24.59%Heodo
2020-09-03BQ6182203909BA.docdoc 38744d77a23730fa9e1cf2d522d54454cb590bb3af3b2c8de76f1c6ece672478Virustotal results 25.42%Heodo
2020-09-03I1RSB18YS0P3J6W.docdoc 65a803b10719f7420467e6a66a5dbe9f9dea0a8dada387e1022e3e3c8340f750Virustotal results 25.00%Heodo
2020-09-03BAL_PO_09032020EX.docdoc 448d42fb988b0cee5d2d02a76289f90fb79c84487b3b4041bf183ddea8ca39d3Virustotal results 25.00%Heodo