URLhaus Database

You are currently viewing the URLhaus database entry for https://ucuzgezi.info/wp-includes/esp/mwTGpHuNuCwkchvAOD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:200908
URL: https://ucuzgezi.info/wp-includes/esp/mwTGpHuNuCwkchvAOD/
URL Status:Offline
Host: ucuzgezi.info
Date added:2019-05-23 18:42:23 UTC
Last online:2019-05-24 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-05-23 18:44:02 UTC to abuse{at}online[dot]net)
Takedown time:16 hours, 21 minutes Good (down since 2019-05-24 11:05:16 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-05-24SCAN_0815528912US_May_24_2019.zipzip ec665e21427c1f3e745f41563e34337ec3a5b1053048cc08fc81fef68aa6d7e8Virustotal results 25.00% 
2019-05-24Document_1489676808US_May_24_2019.zipzip e6b9bd51370dcb185a1ebdc49bbb002b35352f58c44fe424cfc4d05712b61bb8n/a 
2019-05-24LLC_71802627048US_May_24_2019.zipzip b53842c345aa4d53bc6273d5ae946aef72a47f47d597bef5bfdf181b5b7c117an/a 
2019-05-24DOC_77833170248US_May_24_2019.zipzip 44e683a3bae8ff32a2b48a0830e048b84f21d996fda93531f377ada9b91bdbe0n/a 
2019-05-24DOC_90271131925US_May_24_2019.zipzip ed28bf227c2668ca1fb176cd999e77161bfbb17924544be49db1655fcac8a99bn/a 
2019-05-24FILE_397216207519US_May_24_2019.zipzip efa4002879c9f51bdab2fcaf849dc7ee3ff7a2e1c5649b18470028a4f94810den/a 
2019-05-24Document_59360608653US_May_24_2019.zipzip 4fb86706e6f3b39ac57d3fb066b746d64bc8a98f0dda6f823f9845cfe161db93n/a 
2019-05-24INC_4846677545US_May_24_2019.zipzip 1ae5d1d067fbe8ef4a1cdd4fe1761a7d48f7611ab45e0ccb736ec1bd52330a4cn/a 
2019-05-24INC_0804144194US_May_24_2019.zipzip ad580bdf8ddff31959e96a39009b58522194de1a463b5b5eceb54e68b0032536n/a 
2019-05-24FILE_215124259585US_May_24_2019.zipzip 5e7ec253cbefbbfc7bbfc4a36e960b0695478edc44a73bcb3fa79959f5eb912an/a 
2019-05-24INC_641236666694US_May_24_2019.zipzip 1b50d40ae144b9b01056f26eaaa5df05fbb136b7745bdba6d2c22fae2f2eb6a5n/a 
2019-05-23Document_5429631611US_May_24_2019.zipzip 17fca95f998b74f701e6653efc601259a1008db4daefcb71d6f60a2ad4de1308n/a 
2019-05-23FILE_459428327694US_May_24_2019.zipzip 4741ac7883bc3d20d7ea0028263516f8596caf2d9f94219e59c9ccc267724303n/a 
2019-05-23SCAN_10813364523US_May_24_2019.zipzip 71869d80b411448c7b994f5167de9aca9e549563964eac1771c01afc40fff72dn/a 
2019-05-23INC_9847644700US_May_24_2019.zipzip 1304d12d1b2b4a0090ecd9b8ee5b538376bc21784d3f8c8ca831e0c272da8292n/a 
2019-05-23DOC_1424822844US_May_24_2019.zipzip b7dca09f25d17f64dc766985df8cdd16902b71564feeabf335fede07a2713138n/a 
2019-05-23DOC_0420472057US_May_23_2019.docdoc a2cb13a6e2fb1f290d52f4e0dbb57286832cfce1f8f7d77225d1d23c9b1b45fbVirustotal results 20.34% Heodo
2019-05-23LLC_474412069771US_May_23_2019.docdoc 402821d48b97ccc79c95a8ae5a3afb09cad7168e842ed5a9513185b575ff3623Virustotal results 19.30% Heodo
2019-05-23DOC_23455558874US_May_23_2019.docdoc 37815c87ae9995774d6e49be94c9c9838391f0ca5fb088aff1b8902ec5293bb5n/a Heodo
2019-05-23INC_35460472742US_May_23_2019.docdoc 7f74ef7a47cc278b40c37aa4b344faeb5c4dd9cd826dc2cf06ad2b489664b39aVirustotal results 17.24%Heodo
2019-05-23SCAN_1046260148US_May_23_2019.docdoc b44ecb38a5eed68f75ccf9b8f5901599f5ad5ac74125fdb66459a3e6727702d8Virustotal results 18.03% Heodo