URLhaus Database

You are currently viewing the URLhaus database entry for http://businesscollectiongroup.com/wp-content/Overview/SuN6ENVTfpCbUa/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:626993
URL: http://businesscollectiongroup.com/wp-content/Overview/SuN6ENVTfpCbUa/
URL Status:Offline
Host: businesscollectiongroup.com
Date added:2020-09-30 05:46:04 UTC
Last online:2020-10-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 05:48:02 UTC to abuse{at}alchemy[dot]net,dnsadmin{at}alchemy[dot]net,support{at}vitalix[dot]net)
Takedown time:8 days, 0 hours, 58 minutes Bad (down since 2020-10-08 06:46:49 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30mes 2020_09_30 867203.docdoc 0dc8b5cefd0791007bbc51f60516c87fd6d938fe4d44c7f7249e47f38cc3c73an/aHeodo
2020-09-30FILE_20200930_J3249.docdoc 14f2d1d18d19afe92e1aaf65fcc49f7798d6d9c1c150d1d840895741bdd527bfVirustotal results 22.58%Heodo
2020-09-30INF 2020_09_30 252699.docdoc c2fd3ccb55360792d0d8b09904444e642fca832f64abbfc28c7a729f98473414n/aHeodo
2020-09-30DAT 916.docdoc 7d295d64ccbe51777d0ddead2fa213c37017ce33adfc3ab35ed81d988315f756n/aHeodo
2020-09-30VTY902-20200930-L2798.docdoc c2edb2ad04c0e8b248b53ba0f3cc0abd7942c1ff70d3f3b697af056d6dda904fn/aHeodo
2020-09-30Mes_2020_09_30_4854644.docdoc 96d5f51c5c53a7af3dc7d68d75b9e56fe3d1eafbac0804a201994874cda5a954n/aHeodo
2020-09-30DAT_2020_09_30_240.docdoc 665096dfe25e4e636f41d66df9cc4cfb35a0a347a0a1424b191c7b5834179dbfn/aHeodo
2020-09-30SKM7421 0919.docdoc 740e43567145812a52fc449cd0b44e6aae69157aea605122c661688f820eb440n/aHeodo
2020-09-30file_2020_09_30.docdoc e4c0e12e6e90cabe22fab698bc2684a13e9719668942b682bfaa1ea0bd3336a4Virustotal results 20.97%Heodo
2020-09-30dat.docdoc 32ec09ab815a3ca2d96ed124d841dc8dadc0f752aade3f0cd9ea04c51c6f1eb9Virustotal results 47.54%Heodo
2020-09-30Doc 2020_09_30 XC0060.docdoc 6203971a2e4b246318cba558f864664aacc3cc5dae07aa3b8ce1fa6fb17d590dn/aHeodo