URLhaus Database

You are currently viewing the URLhaus database entry for http://www.fizik.tv.tr/ex/mlFHNKb9x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1844648
URL: http://www.fizik.tv.tr/ex/mlFHNKb9x/
URL Status:Offline
Host: www.fizik.tv.tr
Date added:2021-12-02 12:09:23 UTC
Last online:2021-12-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-02 12:15:04 UTC to info{at}veridyen[dot]com)
Takedown time:1 day, 7 hours, 15 minutes Poor (down since 2021-12-03 19:30:06 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-03hmoGE.dlldll 16211b428f9d5da08b3a0d77589bf217f34558388d52d294f7d37dfe5e44b2e0Virustotal results 12.31%Heodo
2021-12-03rAC69ByAU9h1kv9.dlldll 72856a1bde8683ad1eb96f61aeea52fef754c48efcc76de806d8b6990821aeb1Virustotal results 28.79%Heodo
2021-12-02kMDd0.dlldll 27554db03b0a1e16464d7581639695df3feb029b785aeefca85e613ff5d60f8bVirustotal results 8.62% Heodo
2021-12-02oFw1aLUk.dlldll eb9e32a1907160dac0c92f9ee3f0ff9b716201a19372f654f018f608d0176de9n/a Heodo
2021-12-02qWGPVYkJv.dlldll dbe1bdb2177fde15bbbf607388b8bf10e285ec4660b003f9cca169f20d9b4d63n/a Heodo
2021-12-022A6eejsP0.dlldll 3bd3f76c495ac0cac30d7a556867aebe0823af72f0b401e376eee6b2a100e3b8n/a Heodo
2021-12-026Y34C.dlldll ebac7ec59c143a7a62f22a003db3e03796514181e05ccf86d9e1b5d1af3ad2f6n/a Heodo
2021-12-02MHv.dlldll dd44772dda903ca21550cd263152f01a8830d0fac953b3f2e77d7d65bb6b6c5an/aHeodo
2021-12-02ASoYBvZK.dlldll 3e6c9dc29b786e0514eeedcb515c72d4fc2f974b03333913ac87bea75e38e9a5n/a Heodo
2021-12-02hMqonfo.dlldll 613af22e33dc8eec3d776f12049752a2888992638aff2519cb04adbbfa4ba53bn/a Heodo
2021-12-02iIMvLPq2sQgpQnLb2.dlldll 1ed1185b604898e89838390b763a0d4aa274f566de66aeacf7ebba313fe2f41an/a Heodo
2021-12-02Ih.dlldll 634df302bf3ece21d7c28367c6e34c812e6de84fab86658c534f847cb05babecn/a Heodo
2021-12-02W1XnWDdKlPOz3m4LoE.dlldll 184643bcb1b4fff57961cf6ab5bdba8007d022c746ab12168b07b252fb9153f1n/a Heodo
2021-12-02jwWh53G.dlldll 49a69ec8447ce9d5ec2e2723f136c83704df90b825f4dd756d6e75f9ca5df795Virustotal results 7.81% Heodo
2021-12-023V7LYRmpAT55tvKE2U.dlldll eb308f01487ba9c14410a42ac9644ca62df6ac0ab5976994837b9d9e5dc759fen/a Heodo
2021-12-02Tqi.dlldll 70147762ee565d37d15afb79299a149eb899eeffbdfe14b8238ca6340793c848n/a Heodo
2021-12-02ZkDpDNO.dlldll 279f164a15cbe3aac804fa098cff4c894a83ee2cbc4299d38227b3ba900cafe7n/a Heodo
2021-12-02qGGe6k.dlldll 8df426963a663ea33958e3972b850edbefc20db7b78452c5683507e1d0df5bfbVirustotal results 7.58% Heodo
2021-12-02B.dlldll 8cda0ebe013f7589fce148e1c37a4367d5ecc778d672b8a8bff7425259d0a2e3n/a Heodo
2021-12-02Cpn5cHCG.dlldll 97a735e4912c72f3d5f8e8dc18882948607cbdce47aac3cd406c1b157d13069an/a Heodo
2021-12-02Dx.dlldll 2ddedb1eac0f48b75369116342b32721d71633be0fe9224517a3c75927122079n/a Heodo
2021-12-02qLf.dlldll 6c03394fae411cc1f4b660aacdb1fcb03b260dbb33dc3ba012778006e58ad499n/a Heodo
2021-12-02EkBbQoGfYYyWw0D.dlldll eadadd614318616ed944e105164085083332d15fe7215669fc4c7ccc83ec3a1bn/a Heodo
2021-12-02GlVW0nVF8TFhGeOR9.dlldll 378410a74f232aeb53894be7a66c28c823f3a89be177cddd97e8d793d466f9acn/a Heodo