URLhaus Database

You are currently viewing the URLhaus database entry for http://dunyaaslan.com/cgi-bin/rjdweFNH5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2118855
URL: http://dunyaaslan.com/cgi-bin/rjdweFNH5/
URL Status:Offline
Host: dunyaaslan.com
Date added:2022-03-29 11:36:05 UTC
Last online:2022-04-09 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 11:37:06 UTC to abuse{at}bluehost[dot]com)
Takedown time:11 days, 7 hours, 29 minutes Bad (down since 2022-04-09 19:06:40 UTC)
Tags:emotet link epoch4 heodo link redir-doc SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31AJ-83326195537321.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31TZS-1435949.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628n/a Heodo
2022-03-31QIY-26777980.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 40.98% Heodo
2022-03-31VED-0296291.xlsmxlsm d496d617d84291189c4e523cd4b174b705c401ea76c1782f79077eca4eef5512n/a Heodo
2022-03-31LZY-6590606.xlsmxlsm 2e8dfaff0039f7b69af5f699d0efff85cca1b5dbe2a50082b7ccc49503545053Virustotal results 40.32% Heodo
2022-03-31AMT-735432617.xlsmxlsm bb415157a1b9bbe60b44a718eaed436370f6a07df786986c3adde6f5f22c12feVirustotal results 39.68% Heodo
2022-03-31FA-3085761890672.xlsmxlsm 65b87a95369159fb3d54556f3f316f9e13eadd8b95e9e13f6a8d9cc79f43a8e6n/a Heodo
2022-03-31NL-40425879607.xlsmxlsm 00ea616ce33ef49268a2d6046f588bb73c80b7a90ae6e5e5067938d72e858564n/a Heodo
2022-03-31ZY-3772559314656.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31XEX-7758348.xlsmxlsm 355981d4c8400968deaa8a13a04a79c90bf9aab795af2ff1b3273b825a477968Virustotal results 38.10% Heodo
2022-03-31OX-557951606.xlsmxlsm 0d52cf42b7a5f7ec21d78ec1ab0861571f4136b9d08a6de2c4baea447cac0a6aVirustotal results 39.34% Heodo
2022-03-30EZ-112052844354.xlsmxlsm 2b1f1f87033e83e264f05939f180b63165e067861f9c6f1253aedc9c9e1efb6en/a Heodo
2022-03-30HQ-19476013290.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30EXQ-0172889489.xlsxls a14fb7f51582ec1f9af65f4300ff4dde6a99d12bd2b08f70863ca16d508c72baVirustotal results 28.33% Heodo
2022-03-30OF-75414280.xlsxls c83aefdafdc478ffff051002d1c7b4675c068648d57fca17f788d575ce297596Virustotal results 28.33%SilentBuilder
2022-03-30OY-729285247705.xlsxls 7813b5f2ba1876b183aec911e5a55402903c7b4702fef4c3c0055557490ef04aVirustotal results 28.33%SilentBuilder
2022-03-29n/ahtml 24347e04255f6d29d53819b9310fc969ece3a6acda5ecc1ce7571011614bc508n/a