URLhaus Database

You are currently viewing the URLhaus database entry for http://uzeyirpeygamber.com/wp-admin/6n14u-oh9t7w-wklbt.view/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:153348
URL: http://uzeyirpeygamber.com/wp-admin/6n14u-oh9t7w-wklbt.view/
URL Status:Offline
Host: uzeyirpeygamber.com
Date added:2019-03-06 14:26:15 UTC
Last online:2019-03-08 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-03-06 14:28:07 UTC to abuse{at}markum[dot]net)
Takedown time:1 day, 22 hours, 56 minutes Poor (down since 2019-03-08 13:24:11 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-06269599338482139337.docdoc 5005088103260d1d2149858149442272583db34919c2f6f11eea20664d167265Virustotal results 16.36% Adware.iWin
2019-03-06ACC37827665293.docdoc 359ab6aaafa05c98c0da6b23e0a8b057922c97c5e364e736c6945e2fc393053fVirustotal results 14.81% Heodo
2019-03-06US5954388987769932825.docdoc fa68465139cb3da5cb093f19ddcf39047bd324ea08cb2ad36af99ec4e8d6127eVirustotal results 12.28% Heodo
2019-03-06US97129173938077.docdoc a9154dd6891e0227892030a3cd9897d0868b73a1e72681541b9b575f35f7d9a9Virustotal results 14.55% Heodo
2019-03-06PLJ8882647339277896.docdoc 2e32ab622e0bb34719b101d8ac76a3ec3265e91563708abf0b47f8403480df4aVirustotal results 12.73% Heodo
2019-03-06ACC47373207182054285.docdoc 916f4911f9c09eae3127a2dcb7ce85515499201a6f3027869bc0e356ee6753a0Virustotal results 17.24% Heodo
2019-03-06ACC42897783641516.docdoc a6247e8e856ae22c4ae371398431d8bcc3fae22a7d7138e08917c27a8ac96eb7Virustotal results 15.52% Heodo
2019-03-06INSTR53475603082150670903.docdoc 983d287bd30c3768f81a0f9fab8504d2549836c8c9f7fc23202c0dbefe09be8eVirustotal results 14.04% Heodo
2019-03-06PAY32678576352.docdoc 9061d2afe2327733c5cd003d12e78a866b6598ce71df72f8631cbd0034d528e9Virustotal results 14.29% Heodo
2019-03-06ACC2272182640.docdoc 2076f5955c1c2d0db23f20bbe0690602bd624e4c4a44ef36b93526211f4d709dVirustotal results 14.55% Heodo
2019-03-06INSTR2956212789.docdoc 59547d6832a253fe4924046454129f76fd4652deebea172997b32b61a84fec51n/a Heodo
2019-03-0620879550669777734.docdoc 56405f40b6e2feb7000409b3c7e1ecef050282885d884107c5a1d32cf595a6c7Virustotal results 22.64% Heodo
2019-03-06ACC812451815569282.docdoc 87abf75443eb85de2808da03b26d4403fc7a550f2107eb651ccbcd701c481082Virustotal results 17.86% Heodo
2019-03-06MLGW882157070004.docdoc 2c59004b86ea03ce674d1d043405ce778ae19e05a58cd7f72dbb0df5c299447fVirustotal results 17.86% Heodo
2019-03-06ACC41395141354.docdoc e1075d72bdb7a44b4780001492dd4cd2fd1ce53dc0e9c7b7d6d815c988e26c47Virustotal results 18.52% Heodo