URLhaus Database

You are currently viewing the URLhaus database entry for http://btvcash.xyz/ohlnsco/http://Overview/wMG1AUd4O3ck7woZ0Dd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:497224
URL: http://btvcash.xyz/ohlnsco/http://Overview/wMG1AUd4O3ck7woZ0Dd/
URL Status:Offline
Host: btvcash.xyz
Date added:2020-09-14 14:40:05 UTC
Last online:2020-09-14 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 14:42:33 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:5 hours, 54 minutes Good (down since 2020-09-14 20:36:49 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14DAT.docdoc 8014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15Virustotal results 25.42%Heodo
2020-09-14Arc-20200914-34218.docdoc 621854be435f34253592256072e4f2096b4563da99bb985bfe8f72101513aa53n/aHeodo
2020-09-14Inf_20200914_7824.docdoc 3ec8c65f7865d9da20c13828f591798b9a38ca5e70f07ecab7ab158c5a38d319Virustotal results 24.14% Heodo
2020-09-14FILE-Z70845.docdoc 707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340Virustotal results 24.14%Heodo
2020-09-14mes D598.docdoc 0550e42b951f268a6645fba06b0586997fba7d6e8a514f8e0014581e4c34c190Virustotal results 24.14% Heodo
2020-09-14UNTITLED 2020_09_14 K436889.docdoc f78ba6e7143af7a8549d3d722acda8f15318007b2caa9697e827ba958a52f7aaVirustotal results 21.67%Heodo
2020-09-14REP_20200914_436.docdoc 2f46a6507c4618f36225ba5ac1cdbe970be8c8842f309bb8ae5bfe88eef8e805n/aHeodo
2020-09-14Attachment.docdoc ce54a53423908a8f338e9d1a5878d5d856c5be7a77a9f73d6696daf5e29af60cn/aHeodo
2020-09-14Untitled 2020_09_14 0195939.docdoc 30dd2df0674e842f8a3bfd8880f538175f2f42045d66060984f720b865acd353n/aHeodo
2020-09-14LIST-QK037613.docdoc 383354c8056fb386a9af9f40c354846726ff04165ca01390075eeefad8c28faan/aHeodo
2020-09-14dat_2020_09_14.docdoc 5a5e616ef0e077c753837492dbeb00f61df923acd5103b9401b1cde6b30dffdeVirustotal results 20.69%Heodo
2020-09-14Attachments_2020_09_14_26794.docdoc 675544804d4d0a4b6fee00293125ce806c6c7e42e57930fdb1e4c0c74bcdc62fn/aHeodo
2020-09-14Doc-GIA2812.docdoc 01eadb3756ea05c08742edec4e0c8b5afdc3eff88ca45d5acc9e9e73ac0946c9n/aHeodo
2020-09-1434912 2020_09_14 319.docdoc abb33e749d19441d1a0df5771f46504b9f56d1c363e2bc5c1dbd26b40a81d937n/aHeodo
2020-09-14Inf_424.docdoc 0b783948053f5f1dadd529527bbbea3e2ed5e25f1cfa250aca3b6620aac9c26cn/aHeodo