URLhaus Database

You are currently viewing the URLhaus database entry for http://escgayrimenkul.com/cgi-bin/FdUYrA1SAQhjYhmuce6XHiD/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2119536
URL: http://escgayrimenkul.com/cgi-bin/FdUYrA1SAQhjYhmuce6XHiD/
URL Status:Offline
Host: escgayrimenkul.com
Date added:2022-03-29 16:16:04 UTC
Last online:2022-04-02 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 16:17:04 UTC to abuse{at}bluehost[dot]com)
Takedown time:4 days, 1 hours, 30 minutes Bad (down since 2022-04-02 17:47:21 UTC)
Tags:emotet link epoch4 heodo link redir-doc xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31GZ-4110277720.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31PXI-0984293162688.xlsmxlsm b0fa5dda99558a54917cc9a5f6269d440cd8b30ed825f72c837d6e4044d9f628Virustotal results 42.62% Heodo
2022-03-31MQ-40691725.xlsmxlsm b034cfc88c6603dc0f5519ecba2dbba8c5382b26b8c25da23f8d40368ce8e7b5Virustotal results 33.87% Heodo
2022-03-31HYQ-063754210332855.xlsmxlsm a099f9c9c8eff7049da288a1205f1c0ccd52a4954930cabdd7a00dafbe8bbe6dVirustotal results 38.10% Heodo
2022-03-30HCO-61202990253.xlsmxlsm 39bbb570609ea300f9d959dcf23f2161043c6dedc230f97e7eab2388db651831Virustotal results 37.10% Heodo
2022-03-30CWE-72993400816.xlsmxlsm 687a158c15f9b76ec9b11906e548b587dcd7cd319e90477c89b1341f5d6b1eben/a Heodo
2022-03-30XL-100966590.xlsmxlsm 168a9aa1b5fa37a354fd6ccba71dcd29cbcd503a578504c69feb38bd84a8a691n/a Heodo
2022-03-30FIJ-406685924332.xlsxls 02dcdf42ff1966a5e9b02308ee87de554cecdeb8e8bd8d58b6f95dccc8cd7e79Virustotal results 26.67% Heodo
2022-03-30KM-6015108267559.xlsxls 3d1079de218293926fad741451c1633fbb0b9c99a67d4934c97eef854bf09616n/aHeodo
2022-03-29n/ahtml 779f33e076ff9f2ebb0e3cb638cc87141f9511f771bdf08f27877b1f8649a6d4n/a