URLhaus Database

You are currently viewing the URLhaus database entry for http://btvcash.xyz/ohlnsco/http:/Overview/wMG1AUd4O3ck7woZ0Dd/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:498608
URL: http://btvcash.xyz/ohlnsco/http:/Overview/wMG1AUd4O3ck7woZ0Dd/
URL Status:Offline
Host: btvcash.xyz
Date added:2020-09-14 15:33:06 UTC
Last online:2020-09-14 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-14 15:34:22 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:4 hours, 42 minutes Good (down since 2020-09-14 20:16:45 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14DAT.docdoc 8014f6ab3e277e6346b2e49fae79962948c0b264e7000be259601b0b715b3e15n/aHeodo
2020-09-14Mes-2020_09_14-4793108.docdoc 5171e0e602e27c4122239e9c7833c603beebb69bea148c5d29341990af469f55Virustotal results 25.86%Heodo
2020-09-14Inf-20200914-H84147.docdoc 80eefaacbd3208a12056ef722a8b67470ed5f98065369568ade5990de349718bVirustotal results 23.73% Heodo
2020-09-14FILE-Z70845.docdoc 707c1063c30249706f5b47d56c8d6b057f13c1ba249b6fb0a9e86fced1ccc340Virustotal results 24.14%Heodo
2020-09-14List 2020_09_14.docdoc 566cd4d5b217367ca4bcd3a8083b4b0d9d54a60999a8ca7d736d696bef39e9e3n/a Heodo
2020-09-14UNTITLED-2020_09_14.docdoc 41a5219800a60a147e301cb5ee472f45de2130aa095d82a52fa81121b5881860Virustotal results 20.69%Heodo
2020-09-14REP_20200914_436.docdoc 2f46a6507c4618f36225ba5ac1cdbe970be8c8842f309bb8ae5bfe88eef8e805Virustotal results 20.34%Heodo
2020-09-14Rep_GS920.docdoc 058568562f8c6749027b88dae3474806831d476254f079261558c9f229c83495n/aHeodo
2020-09-14Attachment.docdoc ce54a53423908a8f338e9d1a5878d5d856c5be7a77a9f73d6696daf5e29af60cVirustotal results 20.34%Heodo
2020-09-14Untitled 2020_09_14 0195939.docdoc 30dd2df0674e842f8a3bfd8880f538175f2f42045d66060984f720b865acd353n/aHeodo
2020-09-147876783 20200914 121.docdoc f0c1a9d48ad6f8875ac4feceda597cfe6c010133f9bd30147f9fae3cb6663bc1n/aHeodo
2020-09-14List-XHN244.docdoc 0a57a981b3f9ff07b93b6d4ee241f3fe439ae244ddde2afaa7447c7fc23e841dn/aHeodo
2020-09-14Attachments 2020_09_14 9234805.docdoc a76e5f0c9067cd2cd19e85c30f44b763df4d42a5fd1c12cd4fe75cd8835de43bVirustotal results 20.69%Heodo