URLhaus Database

You are currently viewing the URLhaus database entry for https://ucuzgezi.info/wp-includes/sites/mkngjwv5m6l1sv17p87yx0_pknytr-75251279104426/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:197423
URL: https://ucuzgezi.info/wp-includes/sites/mkngjwv5m6l1sv17p87yx0_pknytr-75251279104426/
URL Status:Offline
Host: ucuzgezi.info
Date added:2019-05-16 17:02:06 UTC
Last online:2019-05-19 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-05-16 17:04:02 UTC to abuse{at}cloudflare[dot]com)
Takedown time:2 days, 20 hours, 8 minutes Poor (down since 2019-05-19 13:12:47 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-17LLC_136173427133US_May_18_2019.docdoc 0e06d29508e63b8d72fef84f963e5fa2c17a7898a3f763bd30e614cc359ba0c0Virustotal results 28.81% Heodo
2019-05-17DOC_2765341302US_May_18_2019.docdoc e561a0d7b7b38f5d8be3cb5e975490f9bd7c41a9a355f10f3caecae7c1266623Virustotal results 29.31% Heodo
2019-05-17FILE_783810859606US_May_17_2019.docdoc 4bb22eb17b6ba8363d24def18eb31eda7b7ef4b1ff153d0404c064f8cd678593Virustotal results 27.87% Heodo
2019-05-17FILE_509193834137US_May_17_2019.docdoc a00d938cc78698d9d5c30a475c012748592258d6a5b9a98c5760b6c4f818f1c9Virustotal results 25.86% Heodo
2019-05-17LLC_657457939577US_May_17_2019.docdoc ea33d741a3e4ad54074d248ce9d1d759470e56fea67ba20c18b6ea3142abff55Virustotal results 26.32% 
2019-05-17INC_0013822870US_May_17_2019.docdoc 1a6515b41a9ec86c47a257b04247296b888d0936032359e6595f73ac37938b84n/a Heodo
2019-05-17SCAN_3562223826US_May_17_2019.docdoc a38153871ccad831b791c726e169a8750203aae8f8543f013336a4ee02e95893Virustotal results 18.33% Heodo
2019-05-17LLC_2825973175US_May_17_2019.docdoc fe4876086c674ae402a39e5b7ddde8dac211c8cdb752ceb7a142a06450274d43Virustotal results 15.00% Heodo
2019-05-17DOC_91163580617US_May_17_2019.docdoc 185fa1380d4b9eebc11ddba1d58063b23cc6685b7d0958f12551b6a53ee8c448Virustotal results 25.00% Heodo
2019-05-17Document_495119801697US_May_17_2019.docdoc 0794d6c309ff5e047307be22373c6f9211575c7c625c06c64f9c159d9b46e207Virustotal results 22.03% Heodo
2019-05-17LLC_7634903754US_May_17_2019.docdoc 01fe579a4662383f97070270f32e36a83af02e5815de65440333cdab3d982d3fn/a Heodo
2019-05-17LLC_551532457654US_May_17_2019.docdoc 1efb0018ba2d5facf16aa1307bd349af4eaf61925d05c8e445e95a9a0db0ea74Virustotal results 22.03% Heodo
2019-05-17DOC_5648124244US_May_17_2019.docdoc e90d542a11be7c8295bd63c58d800c9acb93f1daa2504009651d9af98361a6afVirustotal results 19.30% Heodo
2019-05-17Document_678624677358US_May_17_2019.docdoc 05adb931a6a81a896f64e0d66be0fba92e7d117e660cad0dcfa1589f449950ddVirustotal results 27.12% Heodo
2019-05-17Document_085635909998US_May_17_2019.docdoc 378296ec7636eb0fd3af3bfeeecb5eb2128356f3200f50a48dabecce4113d66bVirustotal results 23.33% Heodo
2019-05-16Document_6450138112US_May_17_2019.docdoc 4e5220b3370957ec676dae90b6311b6f34ecaf519093680d7810a25aab6b9ed7Virustotal results 16.95% 
2019-05-16Document_8440992886US_May_17_2019.docdoc b6561ecfa01f65135fc314579131d0bf987443b2a2b5ccfa44bca80ab0e21b59Virustotal results 20.34% 
2019-05-16DOC_113142966661US_May_17_2019.docdoc 48bf24af5917975f48436a23e485c9b41133b0b59696627d53ab56cd24afbd0aVirustotal results 16.67% 
2019-05-16DOC_716823334581US_May_17_2019.docdoc 07984821b787fd2405eebb0ec263abafae4c6b3272c5e78457fe98c2700295baVirustotal results 16.95% Heodo
2019-05-16SCAN_49418972571US_May_17_2019.docdoc f6b6fff24c93ee8cbadbbac2b53e89087358e737120d2687c236d0eab75e53d0Virustotal results 15.25% Heodo
2019-05-16INC_982605939009US_May_17_2019.docdoc f9bf8db6e18539de0f48f521fa2e4790077956a62cb4ec640795a5548b3d0792Virustotal results 15.25% Heodo
2019-05-16Document_34367734120US_May_16_2019.docdoc 53725e0285996b913feb3066802cf1f68863ce7bfba26cc95a69324d0a2bb349Virustotal results 16.95% 
2019-05-16SCAN_064171076481US_May_16_2019.docdoc 6098cb5ca43dd95bf837b29634cc6f9b9cc1ad869f158337edbbde9a3cca0c10Virustotal results 16.95% Heodo
2019-05-16DOC_959951988968US_May_16_2019.docdoc 55d7912feb1a0c02b483b1eb415ecc99da7be934f4fef88fb0f9bc66ee4aaef4Virustotal results 16.95% 
2019-05-16DOC_009114704405US_May_16_2019.docdoc 46bce95fd19be2f4305a11aef6a5205c41b5a1803c4d3836b334951cc92208afVirustotal results 15.25% Heodo
2019-05-16FILE_2099268523US_May_16_2019.docdoc 4c3360c9380f490e271664c6508acacf697558b870d2de03bbbc95a3ce3367d2Virustotal results 17.24% Heodo
2019-05-16FILE_41118292817US_May_16_2019.docdoc 61cd585f5854f42027b4db59c5cf141677dff50ebf4b7613b9db2035f7417669Virustotal results 16.39% Heodo
2019-05-16INC_43314413354US_May_16_2019.docdoc 3d2a4eb39a96b817242b0b5f0783f1117db5053dc3d8446986387d52c8337276Virustotal results 16.95% Heodo
2019-05-16INC_88477017152US_May_16_2019.docdoc b3963c4ea3e3564940ed23e0234c98519ba7414b7a3683eff3f635a2f798f75dVirustotal results 16.67% Heodo
2019-05-16SCAN_3828649049US_May_16_2019.docdoc 0c4dda25ed91b069d0a3911bba601359909bf2b58a8f1a303d66b278100f0d70Virustotal results 16.95% Heodo