URLhaus Database

You are currently viewing the URLhaus database entry for http://turningspeech.com/rm44r5z/usg/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:159389
URL: http://turningspeech.com/rm44r5z/usg/
URL Status:Offline
Host: turningspeech.com
Date added:2019-03-14 14:33:02 UTC
Last online:2019-12-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2019-03-14 14:34:04 UTC to abuse{at}digitalocean[dot]com)
Takedown time:9 months, 6 days, 0 hours, 39 minutes Bad (down since 2019-12-15 15:13:10 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-30n/ahtml e2be88fd3dc7349ec9c3cd296b5f4241061ee5462e7d04d5425359a27b2122d2Virustotal results 0.00% 
2019-03-151vXv.exeexe 3176ff05972f9d88ea6084fcfd9d8dd1a116b4feaf323f7dad84122d4f0bce05Virustotal results 18.46% Heodo
2019-03-15dazw.exeexe cd38a2925675abfedcf34ccee437c54e327711dfd2489250277ae9c71e7da4d1n/a 
2019-03-15kaOYpm.exeexe e4891bdac699267cecb2f39f57eba3acd6205e1a2d382da696c8522050952adaVirustotal results 20.00% Heodo
2019-03-158uZ.exeexe 1c1124a73311db421519fdacaafdacbbb65f504c876edd4bd9030be86337f041Virustotal results 36.23% Heodo
2019-03-15PeK.exeexe 33d96b8d7411af78eb453372e1167f9a16f034f4ec686bf56e0058ca099a4661n/a Heodo
2019-03-155MIIcj.exeexe 357ae58a4848b1d8f210453bfd0289b15a8f06fa5e21ea5634d8d7b9a22ca3baVirustotal results 28.79% Heodo
2019-03-15ZvOe1.exeexe 59697821c5ef906bb937c1e8bb5c913f2ff4eeface3a8ab866301e0303a4e9a4n/a Heodo
2019-03-15rgWPJ.exeexe 3b38f2b24219abcf2fba7a0cb351d607aabe53b13f85ef5409f1d035da2679c6n/a Heodo
2019-03-15eL.exeexe 0b19ac576d3d90093bdf9b732d59db5ec772ad19e0f6fbec32ed41aa7dcc33f3n/a Heodo
2019-03-15xj4.exeexe 856d5af1fc70d30e4315867215f4f085b0c5d4c63d989e43ec20ad4b58fba69bVirustotal results 25.76% Heodo
2019-03-15coEGw.exeexe 75a9e53c6df03b6570aab3044f7fca4bfc532e9b8cdde963337ce351c58df94dn/a Heodo
2019-03-15g1LM.exeexe 31fe699054df7671b3edad7b7005505a667b3682fe437330a676aeecb247c735Virustotal results 29.85% Heodo
2019-03-1571W.exeexe e3123e19730fb8956de0941c55043272cb6da28fa62c6536062ba2deb7fd8d81Virustotal results 27.54%Heodo
2019-03-15rEWD.exeexe 5d512a8cf32ca4e011ce6af313d9be115aeb20fc4e80d48195f2216db9c03577Virustotal results 25.37% Heodo
2019-03-15Ob.exeexe 745b3f844eeafe9a67162dc78f4d6320c233427941eb17b4e42956c285ea2e2eVirustotal results 27.54% Heodo
2019-03-152JbP.exeexe 2f887dd7e01e16269442428f5d6d0941b32c8c4d1cc58338a0c575b03ce162e7n/a Heodo
2019-03-15sDN.exeexe d10f0495573867205bc8fcf2913a4cd47c4c92ca0381949978aedd8a91e7fc36Virustotal results 25.00% Heodo
2019-03-15u78I.exeexe 1e44c1acda69523aabdb75b22c3c67a138f5343366c6241062e3ee5a44d9c158Virustotal results 24.62% Heodo
2019-03-1597h.exeexe 359a236e7aacf6c4ef2ee11cf625b6f3cae148b31f6bc7b53c88ecdd13680483n/a Heodo
2019-03-15BGmc.exeexe 4baa06b4c3c75c623431989780a6d6d6023a2d0b1c20799f934d902e2e8be6d8Virustotal results 24.62% Heodo
2019-03-15wUpWW1.exeexe bd236d5179242c359dda63d838e47a917ab5cde2da9a48f3aa96f761adf601f5Virustotal results 24.62% Heodo
2019-03-15xyeQq.exeexe 50efa3e7ffdb398e3af40b581b46a6190abeef3eca61ccc9c7df7bdef626b7aan/a Heodo
2019-03-15UmuGZZ.exeexe c1d4159650bffcf5210309ef9b9cb6188da372fae46cc1a447ae3b6a4de7bf13Virustotal results 22.73% Heodo
2019-03-15Nae.exeexe 4eee4aa4630ae75793f4b6cb3f06d0045288ed7468d2925970bd687c61650cc7Virustotal results 24.24% Heodo
2019-03-15B3N.exeexe 1c0c875fe89d9498bbb0f5017fa29cbbdeb0862ea5b459aa84e96e5cd04a4fddVirustotal results 23.08% Heodo
2019-03-1557h0.exeexe c5df0bb3c0ea5d0d9b5d71f7e94b84af8778e694c7786a338089c80819c49b1bVirustotal results 25.00% Heodo
2019-03-15MaG.exeexe 54b72327070ac5b2034cb14629a5dce4138763086872a637a1186226e5f5bdcfVirustotal results 26.56% Heodo
2019-03-15Cvvx.exeexe c717b0aa3df38736937ceb44765fb880c86c4c10bcc43339f9f6449c120c0a56Virustotal results 26.15% Heodo
2019-03-14u7iqt.exeexe 2ec35f5ad5bdd5deee7d2e15fff7c54ed38b8682ef9a0444df4404da156b87a3Virustotal results 27.94% Heodo
2019-03-14GU9BAH.exeexe 2ee08b758aa67e38b558bef2d97ed6456fdcd48e10322793e940a858de7590e6Virustotal results 21.54% Heodo
2019-03-1469g9C9.exeexe 10a2e2df9177d431480a8f3fe0a4f9472dacded3f3ccdff42365f1d81cad0165Virustotal results 19.70% Heodo
2019-03-14jBG.exeexe afee6c167829796f05e19f511cd0c73795936c7eaf433b10ca85001070af0b34n/a Heodo
2019-03-14LAL.exeexe 9056d3e465fcc6f14163e1a5d90e61fbd5255b4af69dff290ef8142783a30bacVirustotal results 20.00% 
2019-03-14zXV5.exeexe 1dade85a30542adb07e686182ef50a654a4961ea4645bdf5086397fee655a5e7Virustotal results 23.08% 
2019-03-14UpzM.exeexe 002126fbba172e396555d57d34903ac572c12c70a9f55c09cd85334306d91fb2Virustotal results 23.08% Heodo
2019-03-14rX.exeexe 10ea8ad5be30351e201a85fc408e0446a559f00e0d356c34550f0cc189341e1bVirustotal results 24.62% Heodo
2019-03-14xQ.exeexe eb5e02c68aa470f22900fe1051907a3674f6da6e9be7ebb9792f924056dd8386n/a Heodo
2019-03-14Cgj.exeexe 20397e555a216e08f40c2b5f5ea074fca77d61a0ab2807115ce5701d6d436ae3Virustotal results 23.08% Heodo
2019-03-140oCw.exeexe bf301895350bac4b2e0ef38955637782b49d77e1eb12e06f6e3f4d781512f313Virustotal results 21.54% Heodo
2019-03-1420aEl.exeexe 0daa1c2e8bf230ff66869bcc1f6a781a7809ea5e6ab8bcf736a3fb84cd64336eVirustotal results 21.88% Heodo
2019-03-14tDj9i.exeexe 41a4b259b7eea97003af926184d91ae5bb243157c91758bd8240adad6fc5043fVirustotal results 21.54% Heodo
2019-03-14VrBF.exeexe a2269ea055a7ea6dfc5065b6f69854b9702d94d97af43f8c2c50342f9cf62195Virustotal results 21.21% Heodo
2019-03-14u2IG.exeexe 681a087d376b51c3ad5a2b01e42797867f7846f80d5077c4dafab317c519a049n/a Heodo
2019-03-145JO.exeexe bf96688fdfe86355343cd8cf0fdab6e6563d23ad3bde584c4437e48d3c12434cVirustotal results 23.08% Heodo
2019-03-14Eteq.exeexe 7db3dab503f55572b8b336076d7a17a57cdd27f7efce578f2e334161679cd9f0Virustotal results 23.44% Heodo
2019-03-14Qmj.exeexe a6440113028bcf03e1b3157bb94e46a0d91621ac802e39f12230dab0e5ef2297Virustotal results 23.94% Heodo
2019-03-14jg.exeexe 78493aa7c5e4723ebeb6bc77804d23ccc5ea1d5129f39a03170f9e4ad6f703c2Virustotal results 20.31% Heodo
2019-03-149xdN.exeexe dd548ecec987eb64c9bd20f31f7af016f080a8a4ce209549ac2780a35d973908Virustotal results 18.46% Heodo
2019-03-14D1rp.exeexe c27abdb16492b4c1a455a23f243d8b1f9803fc5e754d9474bf155ec96cd58e3cn/a Heodo
2019-03-143TPQ.exeexe 313a39dff98376fe663cdc0a04c58ac68ff3f3990fede7760f21c8376365c9fdVirustotal results 19.70% Heodo