URLhaus Database

You are currently viewing the URLhaus database entry for http://demirendustriyel.com.tr/wp-includes/LLC/8hrd0iaxtfca_drf3g-28237112672512/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:189809
URL: http://demirendustriyel.com.tr/wp-includes/LLC/8hrd0iaxtfca_drf3g-28237112672512/
URL Status:Offline
Host: demirendustriyel.com.tr
Date added:2019-05-02 22:05:04 UTC
Last online:2019-07-31 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-02 22:06:03 UTC to abuse{at}zeronet[dot]com[dot]tr)
Takedown time:2 months, 29 days, 11 hours, 26 minutes Bad (down since 2019-07-31 09:32:28 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-04SCAN_9148456776US_May_04_2019.docdoc 9547c3f40f790fab370c5620245c7736282c4931b82100c519746d8f3b072bd8Virustotal results 33.33% Heodo
2019-05-04FILE_764862905230US_May_04_2019.docdoc df4a1ac757ed8c6c3ed5d16d933c168b3f0093088545af5fb4abc3787e802dd1n/a Heodo
2019-05-04FILE_25508691084US_May_04_2019.docdoc e46ab44563f129dfaae10e440d99832bcc0058052c2f8452d4e22f76a86619f9Virustotal results 33.33% Heodo
2019-05-04Document_387907257754US_May_04_2019.docdoc d58c1fce018c99965fb2c06ef7c4c3e92be7290f9338741e652b99394eaf8d19n/a Heodo
2019-05-04INC_78186852980US_May_04_2019.docdoc 3d27988d2bf5995fb39453cf9a94fd9ab6319ba0ffa17f3cb3b8e8583cf2327dn/a Heodo
2019-05-04INC_646714844478US_May_04_2019.docdoc e35c59d2dc2d98f655064a3efc2e7a994e4efe4628f60a06e84fc079d8c2fe91Virustotal results 35.00% Heodo
2019-05-04DOC_607307805859US_May_04_2019.docdoc 41455b1035cfa169e177dfc169342186b612047c266be25ba3e8d7475879f99fVirustotal results 33.87% 
2019-05-04DOC_28675554660US_May_04_2019.docdoc f29605f7da73e128b8c8a3b3c984b6d2fad00a690d29fe40e88712fa1cd4c943Virustotal results 30.00% Heodo
2019-05-04SCAN_50449776437US_May_04_2019.docdoc f0160de6e608f33753cb1d6b18224e9501f0f82699d4d9c1dbcb61abd92b46f3n/a 
2019-05-04DOC_729904695589US_May_04_2019.docdoc e308c87030596d6f208f7166d05482820d0218e2d2f2dcb4d2b95044022583d4Virustotal results 31.67% Heodo
2019-05-03SCAN_96516353512US_May_04_2019.docdoc d94ff5aadd33871bf10b2316e3d14e19520506724771f95749210248b7931effVirustotal results 32.08% 
2019-05-03SCAN_651419768223US_May_04_2019.docdoc 23544cd78d845845c0170fd26d7c85639087cbeab45390eafd5d2456735e0ffcn/a Heodo
2019-05-03LLC_15799453161US_May_04_2019.docdoc ee59a77366fe8ef478b14b5d71fa3037bf7179d849c2b797cb3b43d3a65ef8adVirustotal results 33.33% Heodo
2019-05-03Document_01511743626US_May_04_2019.docdoc 06de24539ce5bd171500eb12756bfb9fc70c218145699aa30bd3ac8fad0509f0Virustotal results 27.87% Heodo
2019-05-03LLC_4484122338US_May_03_2019.docdoc 652704b888af5863f0257488f71983c3e23f71e3911227f79673a42bc0106331Virustotal results 27.87% 
2019-05-03FILE_7100374525US_May_03_2019.docdoc 0731dac1d684fd9c6150d9d0c20e52073cdf8b9a8a2afbe06578f553c315bc86n/a Heodo
2019-05-03LLC_27520179807US_May_03_2019.docdoc 89f70f1ea8bb56015eb8427c1900918320be4468fdd858cd59c410ff5f6fc1f2Virustotal results 28.33% Heodo
2019-05-03INC_087504962826US_May_03_2019.docdoc 96973059c987c115d57614d9f730f3acf54956b3c502610929bca5221e635134Virustotal results 28.81% 
2019-05-03INC_75233420612US_May_03_2019.docdoc 47ff1922c8bf5e9e4944d5d3703858836ae1acbb1387c2cf3280abfe1eb20632Virustotal results 28.33% Heodo
2019-05-03INC_148295459508US_May_03_2019.docdoc 47d5b493497550fbfa7b76608e82b40b7432ec6fd0efd5b162d1901a189133f9Virustotal results 29.51% Heodo
2019-05-03Document_943050902108US_May_03_2019.docdoc 6acdb5b39fdd7d5976ee9480efb4121c18ad2eac2c99672e44f9b1ce729d0a5eVirustotal results 24.56% Heodo
2019-05-03INC_2397285463US_May_03_2019.docdoc 84b3e186a522a0d0ccd28e31620ca28199fb3debba995f0bea929b5e9a4de8acn/a Heodo
2019-05-03LLC_12336411974US_May_03_2019.docdoc 678b5fc437b1cd3e051dbc63130bdc93a77c4abc03ad2a337b7713648aa9ce78Virustotal results 30.00% Heodo
2019-05-03DOC_165700888784US_May_03_2019.docdoc 103a9a5a879c4c02ef7d59494306068c7e013d54d01c496c3034a5d49d665d95Virustotal results 26.67% Heodo
2019-05-03INC_9815494280US_May_03_2019.docdoc 5eab415d3c6dad4d5ddf19f49aafd0a4623a6abfa80950f2a021e73cbdef77e5Virustotal results 27.12% Heodo
2019-05-03DOC_67409014481US_May_03_2019.docdoc c210dbd9324b5c7aac98391d73e4dba9b552ed32a7463c91f5ee2b2a0132ec4bn/a Heodo
2019-05-03INC_3897631642US_May_03_2019.docdoc 405e58903f88ee4859fc1ffd4d8449d2a8cb49ea316b6a7e98c6a0ca46239f24Virustotal results 31.15% Heodo
2019-05-03FILE_67870572691US_May_03_2019.docdoc 09b5fbe3c1aa5b2ea45c3c3f385a049a0b791d9768c0cb93eb13d0e4f66cea2eVirustotal results 30.00% Heodo
2019-05-03FILE_54887382602US_May_03_2019.docdoc d2d2a455578a38b9a564aaa771c3f8464d8158ed7eb6f94cb692eda8ffc5eb66Virustotal results 31.67% Heodo
2019-05-03Document_553111060732US_May_03_2019.docdoc a6c39942b4368c8042b2966a36af70a0664404a62b92f59dcd574b258946db7dn/a Heodo
2019-05-03FILE_119379376377US_May_03_2019.docdoc 102c8717b67895eb8d47a5a6ab4101ada8a8f08dfac2ecac5c3dda691a03d3a0Virustotal results 30.00% Heodo
2019-05-03LLC_2514948770US_May_03_2019.docdoc 990801c1de058647b506c19565ee7abf0c886af33defe87c185c91aa65f9b579Virustotal results 41.67% Heodo
2019-05-03DOC_9689374872US_May_03_2019.docdoc 8217083c9e4b5ff7f2e438a2e50d8fbc5f75cd170801dcbd6bf1592b4ee6e76en/a Heodo
2019-05-03LLC_35278104113US_May_03_2019.docdoc f268669cf7822cdb42f9407a39e23549e79930c64deabf9fb45acb7c33aca728Virustotal results 37.70% Heodo
2019-05-02DOC_13716556185US_May_03_2019.docdoc f38d5609ce63487e3e63cdd748f198d3e2afff98ee43ed99880ccac6a883d3b6Virustotal results 35.00% Heodo
2019-05-02LLC_45701666165US_May_03_2019.docdoc e94720b4121c2f2d41e0ee3d754100229d76b7f7085c5700cc059ac806f0a59eVirustotal results 39.34%Heodo
2019-05-02Document_9381828077US_May_03_2019.docdoc 8349b412581a466e885158f9a83aee010856a203586fe21fb479d87fd23c2826Virustotal results 34.48% Heodo