URLhaus Database

You are currently viewing the URLhaus database entry for http://www.forensisbilisim.com/ankara/bplsmKfaKAwAyavNj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2117595
URL: http://www.forensisbilisim.com/ankara/bplsmKfaKAwAyavNj/
URL Status:Offline
Host: www.forensisbilisim.com
Date added:2022-03-28 17:00:08 UTC
Last online:2022-03-29 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-28 17:01:09 UTC to abuse{at}myloc[dot]de)
Takedown time:13 hours, 31 minutes Good (down since 2022-03-29 06:32:47 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-29sTBV6nrihxvPfoEnSf4ralQpw4.dlldll daf54348b95c5b63167b24182f94a4ef9afabd3dbc29ff43271e62a07d1eca12n/a Heodo
2022-03-29hPTNKW1yP45IOdJ.dlldll 58675904f83ace403bc5ae5cdb756dae1ca2322f7260e1d9323aab17a7e39325n/a Heodo
2022-03-29XxcQm2HQvt8R3x.dlldll fd69662fd7aa5cd47683225524577e599942fc30f75535e75c4f1d0f930e9453n/a Heodo
2022-03-29jVnUmPt.dlldll 9fd7954a9bffcd6e78ca99240ca21882e932ef16b69cede984e28d266732b59en/a Heodo
2022-03-29hSRIGUNSyOX8IIiG.dlldll 5a12b02c09670f9d261853bf16d642840849acf8717d4dc9bcd8ac21775428ben/a Heodo
2022-03-29gO6t2I3KCA9.dlldll 1c419ce1bc8275091f3de334cf53177a429d99f532096a8a561366e5348df8c1n/a Heodo
2022-03-29URutaNM.dlldll 980769e2e1d200adf6142842a73c68c4ac7ecf772994c74d56e7fed1e7685af4n/a Heodo
2022-03-29HzmtzL4fUbH0.dlldll 31762011da740ca794da7ad49a5299abac5db1065b7ae56f45d4b320eb08b952n/a Heodo
2022-03-29vxQJlFob4yyqdd70kBhnXUMY.dlldll 4c491a83e9f324712cd7b9bf21037296384ec79b17cfa9aae809d0ca4e12b014Virustotal results 30.43% Heodo
2022-03-28KXXobn1C.dlldll d9efdd3d1d06496995e67c21a58af4e0fe760abf55632bf5a575900c4a290d2cVirustotal results 27.54% Heodo
2022-03-28yEiiMpaIIQyWy.dlldll d4ca02bc38171917d74589dd8c1c55dd66e6ae4bb91099271fb8aad0173f95f8Virustotal results 26.47% Heodo
2022-03-28w7pZxnn4BtWiC9mcJ37zz.dlldll 57e1e189f2ab914a544959c8f11fecbbe5fba46e67519526f2016281b8d343ccVirustotal results 26.09% Heodo
2022-03-28YTjIoHDCE3LB7dJIm5sRNGGB2ODQxJPz80.dlldll 99b366d9c6f367fb847cfe6dc512317597859098d25bf6bf37a971186dceea85Virustotal results 20.59% Heodo
2022-03-286qiMaIseltkLsGe3XTXZ4t6U.dlldll 985c5bf1e6ed220b98c89719e6cb0502628b9a86c48efb4b02bfe635c19cec2bn/aHeodo
2022-03-28KepmUFMOV29m11jUCA.dlldll 6d3f403bbbaeee0093cef555604d07ed06c52dfb4a5f1aefd5bd3ea0ab297eb1Virustotal results 23.19% Heodo
2022-03-28PcBiCfuuf9IZOn5PA4tiIB.dlldll 7cc203ad156ea3c549432ddbfdea044349cf481fe338e62b3b3144596af3a21en/a Heodo