URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: nurtandemir.com.tr
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Control D HaGeZi :Not blocked
Firstseen:2020-08-25 17:06:34 UTC
Total malware sites :2
Online malware sites :0 (0%)
Offline Malware sites :2 (100%)
A record(s) observed :1

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-08-25 17:06:36 93.89.20.293-89-20-2.static.internetadresi.comNot listedAS43937 PTNET- GBno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-08-28 15:02:05http://nurtandemir.com.tr/n/Offlineemotet ext epoch2 exe heodo ext Cryptolaemus1
2020-08-25 17:06:36http://nurtandemir.com.tr/blog/invoice/lb4dp6b8w/Offlinedoc emotet ext epoch2 heodo ext Cryptolaemus1

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-08-28 16:24:142c6b043d45764a9009211c7dbfab4a8aa0aa8a8dbb459535224ed9bc4c398853exe Heodo
2020-08-28 16:02:32389eff273bedf8f0cda12d05b777d12107a17250fb8f1fd849b794fafaae6ac3exe  
2020-08-28 15:39:35c4c4d8cce22d07f6853c2d9a73b880e49f2f2c8d74970b8dad68b8c9e9cc2d16exe Heodo
2020-08-28 15:15:293a8b80dacae75e172b4b2bba3fadede9ef58e679e31f85ba0df66109a264e6c6exe Heodo
2020-08-28 15:02:054ca3f3d9bee3d73daa585eaeba5b7474598ebf0bd60385b425cb4f2143120eb5exe Heodo
2020-08-25 21:02:1352d5f65c1708917e116f0217caac8d2a8ebdc93b3b349f9f42b7d7c1b13d69d6docHeodo
2020-08-25 20:29:5496eef74c59d9b8b47979fbaf2552a9735dcddef28df0b5b87655a4c849f9d853doc Heodo
2020-08-25 20:02:56c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266docHeodo
2020-08-25 19:38:46ebf572465108b8645ca9637d9c17b4fe717d4d99f3d4dd29046a22a8f608bcebdoc Heodo
2020-08-25 19:22:115419b1d842aa8d13493c5ac67bfd2839472947b3345c2f6552dc69521575959fdocHeodo
2020-08-25 18:59:542005da08cf5f5e5489e2eee91a32b61ee7c2da83fcbd47f566eb7a3a29388151docHeodo
2020-08-25 18:38:05cd5de7d65b2e9b1096050ce5dc17eab61c74558a8570d384af33e78dd2d9b025docHeodo
2020-08-25 18:01:122585dca9439553fc132aa07924ab669bd0ac2b0efb4dc154f3538472be3d5425docHeodo
2020-08-25 17:44:17d5f40d452d9a860469d5230c2770b2dd97806bcf9734af4d3f76218dba8e5c8cdocHeodo
2020-08-25 17:26:56a739a31e32ab7fa601d4f3c3b816aaad621608deb572db4c84030ea4f4e8df20docHeodo
2020-08-25 17:06:365ea798c77e148ba56c705159bad7572cc32b08d35f1490759356a6d114d50a2ddocHeodo