URLhaus Database

You are currently viewing the URLhaus database entry for http://genccagdas.com.tr/assets/MRzxnRKVcE43yeQx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123270
URL: http://genccagdas.com.tr/assets/MRzxnRKVcE43yeQx/
URL Status:Offline
Host: genccagdas.com.tr
Date added:2022-03-30 21:24:05 UTC
Last online:2022-08-11 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 21:25:06 UTC to abuse{at}trdns[dot]com)
Takedown time:4 months, 13 days, 11 hours, 24 minutes Bad (down since 2022-08-11 08:49:32 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01YQO-16018997564.xlsmxlsm f23c909e93da5046220289a169b11f2e4425e3d46a97ac879fa01d36a223d366Virustotal results 45.90% Heodo
2022-04-01AWF-388899394719873.xlsmxlsm a068e4ae3d4eb8e24837270bf32d462f6abc2a28b5f416520cc5874085ab533an/a Heodo
2022-04-01KYM-6715888929.xlsmxlsm 0b569b4831594fab8660fe3693ef3035fd3a732d7d1a7d52d3a953fedf83408cn/a Heodo
2022-04-01QK-9839514458753.xlsmxlsm 8d85241fa9e4b815618a159681381b11248ae1d6ebac31af9036814028b205ecn/a Heodo
2022-04-01VAM-9807491610.xlsmxlsm dd701c6097144f29f8fbdddc93a18a1c0ce3c3b51d5b4f0c6683e906ba8426d9Virustotal results 42.86% Heodo
2022-04-01VPK-71866622247.xlsmxlsm de11fbbfacd6c871dc2033f96f1dacb1815ef7122825f3a2fd1fbcc9459ce4cen/a Heodo
2022-04-01PBU-5697547.xlsmxlsm b67f378396a813307cf0d9d7c4f272be83010272fcfa9af1791b517cf4f1ba05Virustotal results 42.62% Heodo
2022-04-01FJ-6699448182.xlsmxlsm d5e9766c94d91e4da90999a0ea0d9a7b3918973c857c7f9faca5686288b53db2n/a Heodo
2022-04-01MAU-95912431.xlsmxlsm 12defc6352bb846667f7048ac22b5ba0a7bededbfdc06aba79c5629671d59f33Virustotal results 44.44% Heodo
2022-04-01EG-4747201148044.xlsmxlsm f29f0ba02cb498dad7d65453ecc558f159db3694f8f5cdba8d96fe63fb61d986Virustotal results 41.94% Heodo
2022-04-01KYX-465825731613391.xlsmxlsm 4ae4ca72fe760544514f37bb851baa845776b0dd55a78172d28a1d9ad185bed9Virustotal results 39.68% Heodo
2022-04-01MRB-63135391048.xlsmxlsm 606cbdc0ecdc8c68efea96696850b401a2f42925109a960adc15b100ad3c8175n/a Heodo
2022-04-01JTY-5263001.xlsmxlsm b25b9d420c3585bd014abd2e590a74feab98bbb0ee612c465a5e152b28c67e0bn/a Heodo
2022-04-01OQ-139719188892276.xlsmxlsm e487c02def7287335acf2278332f27a4a585960d8ba68a14c0b8370535440c3cVirustotal results 43.55% Heodo
2022-04-01EB-6011828.xlsmxlsm 4fe9cdc6b35e9992d206f5a0bb6ebcb063618ed502e651ba2f5c014a2aea5776n/a Heodo
2022-04-01WKQ-8875399254369.xlsmxlsm 525f6667c0439d7c21905eb0aec33c64c4b4ee34d0f3896f67f5140927b44d90Virustotal results 42.62% Heodo
2022-04-01FF-0239187786.xlsmxlsm b42ac7850efc6c39b4c7db61d4be9a131d78b545eaaa868dab373c45bff2fd72n/a Heodo
2022-04-01BZV-65256839814.xlsmxlsm 2a6631c9dcb2385c65248a43d84d9d2063d4c0bec3ef9325c437a5ee31ef4dd6Virustotal results 39.68% Heodo
2022-04-01WOU-3752375241.xlsmxlsm 7347e4cf31a837aec00dd4d093a63e3f2b67a89b6af8965707c47717e8075482n/a Heodo
2022-04-01WL-6781526854.xlsmxlsm 9ae3ff917d99c0e0ba1f6dde3bcfebd781ab332d65552b032855ca627606cccbn/a Heodo
2022-04-01HF-7729163609.xlsmxlsm dbf83f486a7c984113454c8adbaf67592ca234b8918c265d2f37e174aa0bc1ean/a Heodo
2022-04-01QVJ-90682976938561.xlsmxlsm 4c7b060bb7b1693ef3943692ce9c62204426393f9af92ca39c4c57e09b03cc25n/a c8fc17ff030feb3383d8889f69abbb
2022-04-01GET-2668019323675.xlsmxlsm 73dc0a16c8430b50b28054c9e0b1e54cc8174554e7b63b4e2fa4be17c3cac1d6n/a Heodo
2022-04-01SA-33327655.xlsmxlsm 3390185d81ea6becb7bb5c59f26400a3c75b99da77bd95eb76e9417ca984b4dfn/a Heodo
2022-04-01DO-23341110599.xlsmxlsm 55af29e8285944f573d931d856bd099dac92ab1868000f8346d13a0bce7f1e3dn/a Heodo
2022-03-31NOY-55569119008.xlsmxlsm 172069d53028518eba0b857e88be2520acea926685cda54cc456c55d3f94d5f3n/a Heodo
2022-03-31NB-2165089211514.xlsmxlsm bbf1ee7ac4c4ec95b8f5be027d6d0063d9067480f0bd4f7efcdbeeaa827dceefn/a Heodo
2022-03-31SE-88247930227.xlsmxlsm 5144b4176d2f9e56ad483565884642378be09039de1f2a353cb355c00dfa1894n/aHeodo
2022-03-31CAE-8831640798945.xlsmxlsm 441ae7dcf7d20f39dce4201542202d7c62c067457d1476c2bda9c819979879ebVirustotal results 40.98% Heodo
2022-03-31RTT-4231026162.xlsmxlsm 0baff6c11648937580735dcff8208034790a0e1ee649431e79b2b6221d825c40Virustotal results 44.26% Heodo
2022-03-31PIF-199524063861.xlsmxlsm 0a23b203754e6a043fa99f6cf518c8ffa19a34557a7471edad072d54c4a76dacVirustotal results 42.86% Heodo
2022-03-31QJ-04608238367.xlsmxlsm 46c4bca622e4ec244f8999280567cf11b73d31d875ea21c347d737e6605992abn/a Heodo
2022-03-31OAO-75766535015058.xlsmxlsm 48f3f48c930933448b555efe67aa364e098504f2273ec2a4792803cb4a21b8bdVirustotal results 40.98% Heodo
2022-03-31FML-236090074564.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31WVQ-8160928.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31JY-2263843461.xlsmxlsm 9098c46a233798193c0587711f5a9be2a4aa97567db08504452748dde516053an/a Heodo
2022-03-31TWJ-159791160022044.xlsmxlsm 96fac13010c22cdd9510ed06c70ed29257b59aa3fc3be17a9515bdcf3596aa51Virustotal results 41.94% Heodo
2022-03-31GBZ-4597027.xlsmxlsm 484ac30b71e02b553efb54dd38ddc6e86610a68995e280411a4b9f30c8630c77n/a Heodo
2022-03-31WDN-6750024.xlsmxlsm d4f941f7232c98be2d39a4a97edcad5b4648430bb60ad5a21747b37e705ff2d2n/a Heodo
2022-03-31WAB-968757715849.xlsmxlsm 4f1ab8d0a0a6f8a7964b32b8a4bdd94bad95e6774501cf7685028a40efc761e2n/a Heodo
2022-03-31QIA-469254818762533.xlsmxlsm 162637428037d1f8f3bd675b122e5b830107b9ea7352c8c765e97a3afbce1231n/a Heodo
2022-03-31FHZ-844142324105724.xlsmxlsm ecfb46439586ddfd60ed5763f7b103d7487e94bf095208d8967dd838c5a68c27n/a Heodo
2022-03-30WJR-78510898301.xlsmxlsm b4f7a7bd6f99c0ea09617160e6bf753419f6d731901828662049ac8abfed4959Virustotal results 36.51% Heodo
2022-03-30BW-0010140621520.xlsmxlsm 533372e6130ad44ced6eae30ab3af8be4ae172cc7585719b61074bb861f2dbben/a Heodo
2022-03-30OJD-733223345900694.xlsmxlsm 168a9aa1b5fa37a354fd6ccba71dcd29cbcd503a578504c69feb38bd84a8a691Virustotal results 30.65% Heodo
2022-03-30NZB-488255079.xlsxls f3101b6d16751623f8a025bfbf75ae9a32c68b534dccbab4452ee72a9fbe0f5fVirustotal results 28.33%SilentBuilder