URLhaus Database

You are currently viewing the URLhaus database entry for http://ecesaray.com.tr/marina2013/EkOM4/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2125348
URL: http://ecesaray.com.tr/marina2013/EkOM4/
URL Status:Offline
Host: ecesaray.com.tr
Date added:2022-03-31 19:04:03 UTC
Last online:2022-04-01 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-31 19:05:07 UTC to abuse{at}hetzner[dot]com)
Takedown time:19 hours, 31 minutes Good (down since 2022-04-01 14:36:57 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-01HBK-22781375.xlsmxlsm 1156447c9afcac33bf71aaeb14978f9e5d3d1e58c9d97e1071fa721bdf338759n/a Heodo
2022-04-01XNF-3144175853419.xlsmxlsm 17745afc954df41d2b3f49d96ab76cf85baef03d4b9acbeefb44401a89f5b9bfn/a Heodo
2022-04-01GD-761958790748.xlsmxlsm 4d52dfe6d7f72aada80362bf080ef49a439b176e7c488de69e8d6cc39feefb9cVirustotal results 48.39% Heodo
2022-04-01IF-2272793.xlsmxlsm fb304773b9bf33fc45eb1fb816a5bc5ce0e481528f81868e4fc5a81608fbad6dn/a Heodo
2022-04-01WAY-4962036.xlsmxlsm fa9f8c915e7e2c8f789e6e390d3b655689e5cb9e29f1b971fb833bad6cfdb0c9n/a Heodo
2022-04-01ZL-69057649329.xlsmxlsm 4e6c2dd2bb0183aa17caa2084632719d1b9d42cae3e0c96f6770b216822b8d01Virustotal results 46.77% Heodo
2022-04-01FNH-01269144730011.xlsmxlsm 7db1c9e26b4f51ccb88c443f45540349f048fa424afc55588186c63346616c6an/a Heodo
2022-04-01YZM-1558039735328.xlsmxlsm 2a6631c9dcb2385c65248a43d84d9d2063d4c0bec3ef9325c437a5ee31ef4dd6Virustotal results 38.71% Heodo
2022-04-01HGC-294769047229583.xlsmxlsm dffde7ff06d4b4d38ae8f02750d5c59b2a1a293d05af04210b8e79d0b3fd4043Virustotal results 41.94% Heodo
2022-04-01JO-2528972218933.xlsmxlsm c201ae0ab0516a27d14400b4af28d4189bb2c6d8b589c4fadb025c26645f19bfVirustotal results 48.39% Heodo
2022-04-01VGU-896873798856.xlsmxlsm e40bfb9b0a236fa78f9150e560fa82b899430dd6cf6da41388a30f8e09496ecen/a c8fc17ff030feb3383d8889f69abbb
2022-04-01YM-5929652528451.xlsmxlsm 764dc9c37da82215bfa8dce451fc0946c901984084015a98478a65bd670835c2Virustotal results 46.77% Heodo
2022-04-01ULF-75481428705.xlsmxlsm 9ca7e881cd1e46ca3a73efbad250390fbb3fbc92c6d90d0f25c6a218055f323bn/a Heodo
2022-04-01AUO-7750884173570.xlsmxlsm 7865998de760d97246decb7fc619579d9389e6c2cdf72097738e48a74a0bafe2n/a Heodo
2022-04-01VQY-762863698.xlsmxlsm ac237f2f98daf34d401027d9d9cbcf117b75e90e0422c4a242cdaeb25405a9b3n/a Heodo
2022-04-01DT-919816226451730.xlsmxlsm 299bb2145f0b8204975127a266633cb549cef59d4f53ac9a21aa2d9ef1adf13en/a Heodo
2022-04-01SXR-35658148.xlsmxlsm d17e95fb87ae8a3011b050d5c9c089f3bc06fddd1a61feb4812380e96b541e73Virustotal results 46.77% Heodo
2022-03-31WUJ-962781039.xlsmxlsm 5fb54e96fe17c395fa69dc06933558b083ae9cfb1391218f12c539c2645a8311n/a Heodo
2022-03-31CI-18147089623293.xlsmxlsm e9228653a673fd6de4b3fefe1e1bb7522485198e7553046fe42f97f2f58bc3c6Virustotal results 38.10% Heodo
2022-03-31JIM-0416110.xlsmxlsm 441ae7dcf7d20f39dce4201542202d7c62c067457d1476c2bda9c819979879ebVirustotal results 40.98% Heodo
2022-03-31QO-76873336777.xlsmxlsm 0baff6c11648937580735dcff8208034790a0e1ee649431e79b2b6221d825c40Virustotal results 44.26% Heodo
2022-03-31LQQ-331060759.xlsmxlsm 62c189060c43573eb24597cf25c683c10baa2d25165f5de393f846864ecefc46Virustotal results 38.71% Heodo
2022-03-31RX-1262679875814.xlsmxlsm 8115bc600c3294ed207ae6a9310eb986b107f74f69a64db674837ba2e2957ac6Virustotal results 40.32% Heodo