URLhaus Database

You are currently viewing the URLhaus database entry for http://www.cagataygunes.com.tr/stylesheets/uqK4kfhG4RAuRIA2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2101665
URL: http://www.cagataygunes.com.tr/stylesheets/uqK4kfhG4RAuRIA2/
URL Status:Offline
Host: www.cagataygunes.com.tr
Date added:2022-03-17 08:58:12 UTC
Last online:2022-08-20 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-08-20 09:11:05 UTC to info{at}veridyen[dot]com)
Takedown time:5 months, 6 days, 0 hours, 49 minutes Bad (down since 2022-08-20 09:48:27 UTC)
Tags:dll emotet link epoch4 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-22erFvg0lqZYL8UFyPCFdJTVzRNaNr.dlldll c87e02b9231dc1a28fb81171d340c58ed38dc0186d6790cd3abd0417254f1fe7Virustotal results 47.76%Heodo
2022-03-18bgow6YHPQMLyYDaX.dlldll 4388f9d45b12f5afd9f92e164bc5e868af3aee40d74c9f12313d55bccd7b9b48n/a Heodo
2022-03-18aaYMPk9h6Pc5xOrGQZawVjk2Pj2cvC.dlldll ffc83f06cd8a7503e6031d2eff7cfbb24b471d88a8eafe63b958d4dacf2e3768n/a Heodo
2022-03-1820PCYrhDcp3MKTNp.dlldll 77673e22682e640b48ad0a7b37ecccfc0a92132b283613e634bca120317c911bn/a Heodo
2022-03-18iU2TCGUXzCmpQq2.dlldll e3fa04ad20e136e420eea716a76975f1b92c1fe8f44147276c0ecf6ef0e7daeen/a Heodo
2022-03-18rxA775SjxL5NkQ.dlldll 3197e38aeafc6cd4d59651046d1f1203485f8bdeddc818902dac9de6b69a031an/a Heodo
2022-03-18Xpq2pQyywLAlj4zuw1yHoTAdE.dlldll a3f5607cdc2c8a82a2139ad6ef153f418a95f9c50f34ed9e2d8989af422632d7Virustotal results 19.12% Heodo
2022-03-18MHIDY3b.dlldll 71de63fd706d213465cb869d5a3974679263b14c41baa5f75cdbf256f6d2568eVirustotal results 19.12% Heodo
2022-03-18eKIWSLyvfL.dlldll 46bf7fdb84707d939d6f2a360e187635276dc4a6db4486d12c4a7c498e147023n/a Heodo
2022-03-18sRRBB8ZZFGR.dlldll c7a47f6342147ce40be8e65cc59f303d7bb623107773bf3c935a0e4c57063cd7Virustotal results 16.42% Heodo
2022-03-17Poi1bsTgw0JZFUErCo5CrKdY5Dq99dXzVJc.dlldll 28e2d4b92dc6bbfff884d5775802e9efa6297ae5d98018bcf5ac412f68a264e4n/a Heodo
2022-03-17TMfkpTCeYoaQ.dlldll d1906875e56bce33b397e21a26bd7811afd1c88c25e44011f1c9184c14564040n/a Heodo
2022-03-17oowypJA6CYvsILh.dlldll e9439b75b18c1f480f85593bcf8dcd2bf1ee769b01e4cbe2977d8236c4985616n/a Heodo
2022-03-17jHYhhA0xxOVLVNfMt3UTO4.dlldll ea815f5f1da71117a4ccec467db0327b617bd83c7158eeac18e6d4a4f87dc919n/a Heodo
2022-03-17rV7ITTy7OOtD6O3uf9NUCSrXMw.dlldll 20359aad273456a8f40880025e16aa1c78ead3e5584e390a471abd2efd1f60ffn/a Heodo
2022-03-17ZcAmwiQbuJghfaWib9uiPxd1lrsnz7I4.dlldll f720702e6d5999dbc1c85af4b55e28024f32d4c09ae49af58b6ff206871ae116n/a Heodo
2022-03-17RURrVYnPtBtLGlfObuGZ.dlldll 2ea75b69f4bf4cf68905ce260e92869bd451d6c8056ae46b63919e3a1d420a15Virustotal results 23.88% Heodo
2022-03-17pzvr93Wsb5Z2a5ixP3jjagLdfAce5vldU.dlldll 674945eb76ae705b4594009dd9f511fdac6a99e7787d063c84dd56c7afb4c46aVirustotal results 20.90% Heodo
2022-03-17OvJ54Bpgi6HNfcUXbDT2uQUckQH6r2wz5Ih.dlldll e4a177a0154b44db81e2550e48f16027b772b7c6873b8d536618de66148b1e42n/a Heodo
2022-03-17Of0kXc0ssUzrb.dlldll 64faec9d13ee750867df2116d99cf6f5a1a438fcb4b2014145e6449de3c29c03n/a Heodo
2022-03-17T4R2xwweO2rjQB0j.dlldll 1cf28f10fdc9860a6e275f7c1e27045e6f0f74c4440dbd6434c110324d8e0713Virustotal results 25.37% Heodo
2022-03-17877IZsOzm0CmIiO9UPFLGCTU.dlldll a6fad7e45b335872ff7032fd23b23a53b50670f195886f24720c278bbc0d1586Virustotal results 25.00% Heodo
2022-03-17Qw3P6WEgu3ffXB.dlldll a6a1a644aa953689fd4eb7a7782047627a6960770999aea3077c4215b931aff8Virustotal results 22.06% Heodo
2022-03-17grt8V5UqYmLaETT3VH.dlldll f0181c54929dd828b966fff8ea459ec9c41fe8631942561424e72e1e7ef93acbVirustotal results 19.12% Heodo
2022-03-17AE20MhZj.dlldll b6f2869534548464f51af77ad2448c3dd2788ddb4c43689a43c5389662f39fafVirustotal results 22.06% Heodo
2022-03-17Xrskna20HA8kWkVvjvDjCIZzm.dlldll 9a99cc8c5f7cd2efe791ff0efb8471a29f326a6f8ddc2101e42076871ef7ab72n/a Heodo
2022-03-17tyDnk79.dlldll 410675c280aeaef270ee147df9a023b84a1c8dd9e559dd00b4492e0e4172a315n/a Heodo
2022-03-17ZzIGwcpEz.dlldll b9cd075d04d0c400be2fe78b8ee93c53e4b8a3f74e42b240c10e015a1f091c3fVirustotal results 11.94% Heodo
2022-03-17lOf5lcRhDMfzy3Qri.dlldll 14c55f6736bd30fe78d1cee846ff91eed07d3aa66da399b7cf2cc4611cc7158an/a Heodo
2022-03-176M7NakbasUJ6TssbJCNt.dlldll 40ebe054234b0f867c289356a66a5aa15073b0696474a829806dc734516d686bVirustotal results 14.29% Heodo
2022-03-17eOPRkw.dlldll 4730b5e274397abd91bee015753198085f9823fb315e68b5471344b0cf563b98n/a Heodo
2022-03-17DJV05ZxR22bLRJugkZCPCT1oMYTzgPjdm.dlldll 55c8facea29867f4233d0a71a6e16b2b4f1699b532ac2b66e81275ca2d541752n/a Heodo
2022-03-17ivu7Uo0WNO0G25JGUesAsHB.dlldll 76a761e551789849a214e68651f3c4a136dcd168b679c7b72ab167449da1b3e3n/a Heodo