URLhaus Database

You are currently viewing the URLhaus database entry for http://www.hangaryapi.com.tr/cgi-bin/PVrH9X9PyARmyn3s/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123240
URL: http://www.hangaryapi.com.tr/cgi-bin/PVrH9X9PyARmyn3s/
URL Status:Offline
Host: www.hangaryapi.com.tr
Date added:2022-03-30 20:54:05 UTC
Last online:2022-06-15 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 20:55:07 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:2 months, 16 days, 18 hours, 55 minutes Bad (down since 2022-06-15 15:50:17 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01XR-651763465499.xlsmxlsm f316a9b48040c007a792f5b99f7367b7d6996c7db03a377dd159a22db01e6546Virustotal results 39.68% Heodo
2022-04-01XT-057066864.xlsmxlsm 0a23b203754e6a043fa99f6cf518c8ffa19a34557a7471edad072d54c4a76dacVirustotal results 42.86% Heodo
2022-04-01ITB-6348116952623.xlsmxlsm dd701c6097144f29f8fbdddc93a18a1c0ce3c3b51d5b4f0c6683e906ba8426d9Virustotal results 42.86% Heodo
2022-04-01FC-3617344327753.xlsmxlsm 41169580013c884c968404a805765bab464032270676b792b39ae2b521a64dfeVirustotal results 39.66% Heodo
2022-04-01NO-744153263086847.xlsmxlsm 0267b8c0e2d5e3b8d03da907a69503fd2553048e9f29aa91171ffa4ab40f2b44n/a Heodo
2022-04-01IYR-51029123.xlsmxlsm bba184efb454972191ec837362eddc4ef35f60b616033ef54cbd77d1a70f8f3fVirustotal results 36.51% Heodo
2022-04-01LFO-623330477653255.xlsmxlsm b2938e08838301bc90fa07151c54635d779bc503bf82962bf843781326e1de2fVirustotal results 43.55% Heodo
2022-04-01FW-827392531.xlsmxlsm 178e56af34b8983297784e7e795578c7567350c8ef3be2b30a43a05de59b9e8bn/a Heodo
2022-04-01MK-7847181.xlsmxlsm 23c128385a0702939e1b4bd33875e38dc27cec42b5561f54859abaa962d2930dVirustotal results 42.62% Heodo
2022-04-01PZT-92570575.xlsmxlsm fb304773b9bf33fc45eb1fb816a5bc5ce0e481528f81868e4fc5a81608fbad6dn/a Heodo
2022-04-01JHZ-93305996.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01KYJ-37542110164535.xlsmxlsm e659479a435f37e03d325154ad864519c5a6853aac0f16d605d7560f3a4a0863n/a Heodo
2022-04-01ZI-8656233964.xlsmxlsm 486f0b5ec22adfb853de19d134c1b622d189a6b833765aab0ae9c0759ff19735n/a Heodo
2022-04-01YV-862283060974.xlsmxlsm 872c806b2f7f3d9e9fa2365cf07997b152c6209d41197d5584295b3f3cbdfb70Virustotal results 39.68% Heodo
2022-04-01YH-63117659739.xlsmxlsm f9c9f51df261403227f4db33c8a418d0d9e90e02cba1b750d1b6c0cbd6b1892an/a Heodo
2022-04-01NDX-1654223.xlsmxlsm f3c06e72e6b0cddb3d66545d59bef1288458f9c106ede60b0507f095971e7067n/a Heodo
2022-04-01VX-672564939.xlsmxlsm 7347e4cf31a837aec00dd4d093a63e3f2b67a89b6af8965707c47717e8075482n/a Heodo
2022-04-01CP-7457878919.xlsmxlsm c171d718d9aecb5ad1e27309660f8da7a568f9798e03d4c6683d7825b5a122c9Virustotal results 43.55% Heodo
2022-04-01JXH-99297199.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894Virustotal results 43.55%Heodo
2022-04-01TAL-371306780.xlsmxlsm 83e4fb679d6d1c0567ea98f4800afcb2f1b36a3d0515fa429f17ba52984f6cbdn/a Heodo
2022-04-01SD-11591398451520.xlsmxlsm 7865998de760d97246decb7fc619579d9389e6c2cdf72097738e48a74a0bafe2n/a Heodo
2022-04-01SPT-525462277852.xlsmxlsm 1244e23902ebb80c6ae5adf17c25205d1695cb66181da9c2953e0f59f6207bc0n/a Heodo
2022-04-01DLF-671360188041174.xlsmxlsm 3005686dd6b770a4a0af0ba70ec91ea407d32838aa2acea56c5ab75f2a47ff56n/a Heodo
2022-04-01VR-07387074.xlsmxlsm 183a6d5a3ef111869776ad189768e9388b9c069c9da1ba02ff7fe00068819894n/a Heodo
2022-04-01NUI-728292356755.xlsmxlsm d17e95fb87ae8a3011b050d5c9c089f3bc06fddd1a61feb4812380e96b541e73Virustotal results 46.77% Heodo
2022-03-31JY-19833641267.xlsmxlsm 10ce10aeef8f6d0f3daf5292f589879e748af9adc9d29ad0bf9143c2115cfa23n/a Heodo
2022-03-31IP-59672977.xlsmxlsm aa3fff2c2d0daf56b10654b5f1f501b45c0cfd50fef9004498bca2a83c359e69Virustotal results 36.51% Heodo
2022-03-31GFA-87186989.xlsmxlsm ccd9dcb6dc115061ff6e011cb77ac0c73d785a23c2019aabe11eba9b7500b118Virustotal results 38.10% Heodo
2022-03-31OTZ-65600092008.xlsmxlsm 10281dd74601704b43cbce7093951762bfb6cc0402f747ba01250b2ebc438c27Virustotal results 35.48% Heodo
2022-03-31XA-4067757501860.xlsmxlsm c10cd4c9b699a22be539e47e16dbb91c80084b3afa570a9eb66c2206c3096b9aVirustotal results 40.00% Heodo
2022-03-31ADE-82450775725186.xlsmxlsm 0e92cfd04405b8b597562761080285f19807c04c48c7278fe7632271ded41c3dVirustotal results 40.00% Heodo
2022-03-31KW-80264003179640.xlsmxlsm d17f996f89de5c8c22e600186d7d54a2e0172758ad5cd4d2accbf22b58848bbfn/a Heodo
2022-03-31YJC-44668772.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31NZS-773100889199894.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388Virustotal results 34.92% Heodo
2022-03-31FIS-4758648772.xlsmxlsm c91108a630fb89be6e53e693ea5240bc7be18d74be099b965d92647bd239c6bfVirustotal results 41.94% Heodo
2022-03-31ZNU-753303691444.xlsmxlsm 2e1db4578a7534abbaeb0e65b01b0da5024a9e27d99c3a9b29b03cca35b3a096n/a Heodo
2022-03-31ON-86980082367.xlsmxlsm 409e55effd488af9a3d098060e33fe5d66743135fc711a07d6ce4c57e2f2c2bbVirustotal results 33.33% Heodo
2022-03-31ZX-01632778669031.xlsmxlsm 575cdc6658b85600efd2d3c07f461b8adaeb0b181dfacfd318c0806e4915c95bn/a Heodo
2022-03-31SC-588048084898347.xlsmxlsm d4f941f7232c98be2d39a4a97edcad5b4648430bb60ad5a21747b37e705ff2d2Virustotal results 41.27% Heodo
2022-03-31QN-28160912.xlsmxlsm 4f1ab8d0a0a6f8a7964b32b8a4bdd94bad95e6774501cf7685028a40efc761e2n/a Heodo
2022-03-31RCK-92661914848.xlsmxlsm a4e22b806505d549a037a67123efb6b397193d7d2ff28e32d8b73185438fb5acn/a Heodo
2022-03-31TXJ-3383791475.xlsmxlsm 638588dd97949a25ee7322aa73731204406054bf2db2043063ebfdc82d353f65n/a Heodo
2022-03-30QCM-73024306674969.xlsmxlsm 41f790fa1e0f18e897bdad1de2c9452310c964ab0c50e831d9c1150af849edf4Virustotal results 40.98% Heodo
2022-03-30UG-3921654.xlsmxlsm 51be5ff843565b3e8fe56f303452e018d305cc846181d2d79d435509b2dc578cVirustotal results 35.00% Heodo
2022-03-30EEW-50539092406806.xlsmxlsm b8a9c6cb2992b99ed3cc0c82c5cc63dc9a4a3c509e8c67399d2d7c864ed83c03Virustotal results 38.33% Heodo
2022-03-30XOC-06048442328.xlsxls bc3aadb828bf8f9442d01bb0a1d6b11b7633b19d2d0f8dc6711897611c0a5c3dn/a SilentBuilder