URLhaus Database

You are currently viewing the URLhaus database entry for http://www.cuneytkocas.com/wp-content/VSnofpES1wO2CcVob/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1968492
URL: http://www.cuneytkocas.com/wp-content/VSnofpES1wO2CcVob/
URL Status:Offline
Host: www.cuneytkocas.com
Date added:2022-01-11 21:09:05 UTC
Last online:2022-01-13 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-11 21:10:10 UTC to abuse{at}internetbilisim[dot]net)
Takedown time:1 day, 12 hours, 28 minutes Poor (down since 2022-01-13 09:38:35 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-13BjgK3dYsPAh8.dlldll 086f2a9bab2c1c39b45e011a03eef8a4ee312a6a3b8afe1e599666f5a60e52ecVirustotal results 38.24% Heodo
2022-01-12mRzW8xRRtt18I1qS.dlldll ba45088a1f01a16b0bbc467606953602b6a3f39497ae6fa0f8da6a170ca8df5aVirustotal results 19.12% Heodo
2022-01-12BE1S72f9YD94nh.dlldll bffe7ec73990324d1170d654f5dcc8f91d3b8cf6abde436480e69f09200bc4e1Virustotal results 20.59% Heodo
2022-01-12PzyIWRtOVGye.dlldll de89406bf40d187a8cc4986ad3f22470834908b94974c046e322664ca2473fb6n/a Heodo
2022-01-11tJ2zR.dlldll 4668a109474974a3766c18ed6abb889cb4c62b9b69a14fb8cb3542293d828d85n/a Heodo
2022-01-11GUis3dT8qQYz.dlldll 4ac67a7984da2e5005fffd3f343ef194ac62eacfd8444b95e76fd07bfb039bb3Virustotal results 21.88% Heodo
2022-01-111YEvagRKqS2Xg.dlldll 07c358900c9a05eeea10df4535b1d454f245b389238bafbb500a1845a09539ebVirustotal results 15.15% Heodo
2022-01-11ZgLHz4ua5E33l5OKI.dlldll e5650f2d6905af4d73924f5da282b7942055f3203aa4881efbe72d6fafc8e761n/a Heodo
2022-01-115gbqFtNsM.dlldll 77078cbab3e28c532cad6ab369c7e6b793cd7be87a783fb824a323d6c98ec55cn/aHeodo
2022-01-11Xc4IpZRM0q.dlldll 1e27d22dd63c88615d4599ec8a946f5fa9c458331977318d5c86e613bf613aa6n/a Heodo
2022-01-1131ic3jV1.dlldll d0c0518c30e727e197a97b52b3e8409364195d2b61951958c4fce7a4a97c0de3Virustotal results 15.15% Heodo
2022-01-11j6StJU3Yu.dlldll 1ae6a00a02871e86b7d73d27772ed676a191030169f7bf87daa449f4000e854fn/a Heodo