URLhaus Database

You are currently viewing the URLhaus database entry for https://duvarkagitlarimodelleri.com/42hhp/gZXakh7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2055502
URL: https://duvarkagitlarimodelleri.com/42hhp/gZXakh7/
URL Status:Offline
Host: duvarkagitlarimodelleri.com
Date added:2022-02-23 12:41:11 UTC
Last online:2022-03-08 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-07 04:06:07 UTC to abuse{at}as42926[dot]net)
Takedown time:20 days, 8 hours, 9 minutes Bad (down since 2022-03-15 20:51:40 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-13n/aunknown e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855Virustotal results 0.00% 
2022-02-25Ba5Q.dlldll b92cefce48b1e6c8e5425383e05ab2e6611ef1cbda96df9276bba56d115a054bVirustotal results 23.08% Heodo
2022-02-251G7ktaWcEQg4.dlldll 2571ea7f4a26b32996113a5f6e47f23eadccb5f27277e4a447493fd41037b874Virustotal results 17.14% Heodo
2022-02-25CMO7wwOXiR.dlldll 605819f494fcfd0912675f191e7327cad410a399280e7885185f76e3f38abb6aVirustotal results 20.00% Heodo
2022-02-25FJT.dlldll 3dee6638b9875f7a74ee46fc1841694bf91f1750ac97d6721b441ff45ba66e5bn/a Heodo
2022-02-25wyJti7.dlldll 79a800a408034c0ebabb82184a271afabec2c850fd12f8bcc38e46bf91f47dc9Virustotal results 15.71% Heodo
2022-02-25H3DiKqfnD8zkxOK7Y.dlldll 54569212b2102f696dcd2b9eaf59c1f8c5e37239d606f180df9744700c2786d9Virustotal results 10.14% Heodo
2022-02-25T0S1tXbV6Dy4qj.dlldll 6cee929cc9d8e6839fae07fa842242cef1d6ec0dad80a44fa4036f61a55e9574Virustotal results 10.14% Heodo
2022-02-25THhRBZC8.dlldll a34dd2d0ab3d495cdcd9e033498f0423222b819c9a6d7fbdd77c14997079e9edn/a Heodo
2022-02-258IrZ7tQIt05AOIvwR.dlldll e5c33feaa20133f8e2d58aa7f68d385d0ab4200a1da5457fa89cdf0a3f3d089cVirustotal results 10.29% Heodo
2022-02-24Bsv.dlldll 3c272f6f4a4488e9e586e5bede4b660aa373eb4e8bcc21731e357d34290ef25bVirustotal results 11.59% Heodo
2022-02-24hsl3MgbTmn.dlldll f819803a52a71ad32e266500bfc77171837ded4446c23c113c35f500e8c50416n/a Heodo
2022-02-24XewSIzHMk3.dlldll b2b53e8d5c47e77e001abff829f4ca98de30a8781e0e39563b8c89c8657ca361Virustotal results 8.70% Heodo
2022-02-24vi2qu6CcpUqcOoc.dlldll cd677631a2b6e471f76e251a684bcd2ff7ff99a08acfa4c4fe9e1c202262654dn/a Heodo
2022-02-24KPD.dlldll d28acc32f2cf72868ed95d783f247e0e131c9ac3a148a0af5fa572e63c48b0a3n/a Heodo
2022-02-24xztbQ5HNXTSy4SR60.dlldll b0faa29b362769afa259f919611fe0ba56db80a465cdc25717b7c3f26a8be611Virustotal results 30.00% Heodo
2022-02-24arCdzVOJQ.dlldll f7f677b5ad815dfc829b6dd54880da759dc2ee2e82bdef85db20fd34362135baVirustotal results 27.54% Heodo
2022-02-24DSgme7Y4N6EgxL.dlldll a6c111d0160824986ed6c3bd52deff9ff6a974121bcbed4b763a8d4453f5248dVirustotal results 27.14% Heodo
2022-02-24HwFqQs3STiXNY4J.dlldll 8ea2351f40030c329f57038ae8c84bec8ac4644648ca452b522b4d0e31d2a443n/a Heodo
2022-02-24jJ8XOO3ouLZtfMIBFHa.dlldll 96f7d1ca9e0c17f619efac7f3e1be7fee891af0b314ab99752da2da3198b3ed0n/a Heodo
2022-02-24UAZ0d3.dlldll b5c14e8c3fcc1051300b35a9c21aed34e3af7a6b4b32424ec3b13382e100c808n/a Heodo
2022-02-24L9Ih2qW4Yj.dlldll 662dcae666c972b915d78dbff6da1451dc3c0c3c31dcdfba8579118b74025ee9n/a Heodo
2022-02-24FXSnz.dlldll e5350263ee7736744fdc94004311373d5aec749c14b1bd412417b9012194bb30Virustotal results 13.04% Heodo
2022-02-24EOpLA8ATC6mpUlx21h8.dlldll bf456c618ae09da35a83f1f514ed11a5fe8ae89f2bde91bd105ef461438a44b1Virustotal results 8.82%Heodo
2022-02-240dltHOQfn.dlldll 5338a09ea159fcba3f1dcdd38247c99a416f377c6a256a8a3fc07993c24fdfecVirustotal results 21.43% Heodo
2022-02-24uoRevgDl.dlldll e2e883a755107abd85b837df88434713d3897e1b71f69f582eb3194a68fa1ddbVirustotal results 24.29% Heodo
2022-02-24UZmoVukGsMaZwKk.dlldll 5d7f914407ea3776307854c28499cf9fe4c0ed46be14e9de2a420a149d53d339Virustotal results 18.57% Heodo
2022-02-24N8ycABmhkzP.dlldll cb549daa5c4f4da32119f497df1950dd24228b44b08effb3b3f46071a4d4f3f8Virustotal results 20.00% Heodo
2022-02-24yR3jwCob.dlldll f748c5c86265577ef05cf0239088b1b0276db157b5433076d0c72000282fd05cVirustotal results 17.14% Heodo
2022-02-24DSgxBBhbco0P.dlldll 93b85ceffcf35ff9cf09ce7e52365fe7f03324e5b65e3ded8c84db82ca3af887Virustotal results 18.57% Heodo
2022-02-24kplixxikDSVR7E8wiYu.dlldll 232ddb788daa971e958b0b378934ec0bbf39727bad7f753df19703258a5d6f4dVirustotal results 17.65% Heodo
2022-02-2480X5n6hmbOyGrtH43p2.dlldll 05db935b840acfaf8734552d4c5ab7201a2ae05442a282ce5f09ec4af6d1ad4cVirustotal results 19.70% Heodo
2022-02-2480b8yxS.dlldll 0aad08ae72a0495287067b748e8789b00267e357b184c1cee2c48a472572bc09Virustotal results 14.49% 
2022-02-242TQ9zcj.dlldll 90763ee42fc66cc1859121372e31373f5c4b0d7d27263e1644abcfac9057145eVirustotal results 15.94% Heodo
2022-02-23aHxp5WUWH8.dlldll 16cf1336c0e629ab4bc4dde364ce13390e5c4222bd993147bd94bd259fb87aa0Virustotal results 11.59% Heodo
2022-02-23Sco.dlldll 4157534966dffa8cd96f890054dc147ed898d7b06d331cf10f4712e445d17663Virustotal results 7.58% Heodo
2022-02-23HfjQ4JMKq82T9s7.dlldll 1c3b98c99e9e3c868a4d139f1c8f1ec3e912535aa77f8266f07bddea00cd6ac6Virustotal results 11.59%Heodo
2022-02-23DVn.dlldll 13c29f2a8a0dee7281e60f19bbd0e4c435ea86d61f78d9eed18ec1ec0bcf733en/a Heodo
2022-02-23IqpGzfO.dlldll beb777e2476bb39603e649d76eb2daa6d92ceb10342fa609769ae265d4cb8dbcVirustotal results 24.29% Heodo
2022-02-23aNA.dlldll 7df56c37d961740bbf67c74759d5939891c9bcbdc6be76568e3e54c00c6eb0b6n/a Heodo
2022-02-23LhsZBzQbblC.dlldll ee40930057f52a766dad295da0edf56e77085134429df4c723ca76300b2dc23fVirustotal results 20.00%Heodo
2022-02-23TX8QiZjNiS3aKtO.dlldll 79def7a17ccd0e2ebaac2f0678a3159ab9dcdc4fe4f5be10ad335903c428e917n/a Heodo
2022-02-23GPcMjyKDOkgar8Vqq.dlldll 90ddf16ea272548311893ccfe7cb6aa2477dcabea80383ef2933c7113550d627n/a Heodo
2022-02-23gfPv4.dlldll 820c017329a816da173eac5ff4aa1d08083dd26ad753ed63c4727cd2d2a96787n/a Heodo