URLhaus Database

You are currently viewing the URLhaus database entry for http://ogenhukuk.com/css/RYnIOe9nU3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2201835
URL: http://ogenhukuk.com/css/RYnIOe9nU3/
URL Status:Offline
Host: ogenhukuk.com
Date added:2022-05-19 07:10:13 UTC
Last online:2022-11-02 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-19 07:11:11 UTC to abuse{at}ihs[dot]com[dot]tr)
Takedown time:5 months, 17 days, 1 hours, 14 minutes Bad (down since 2022-11-02 08:25:12 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-19Q12YnZ6e3ZrjRpTcLBjfJoW6U5y38.dlldll cfe6634a2456959354aabd19af50930135e9869dc2b045f6a76748cdc8987291n/a Heodo
2022-05-19qSyd4QLXSuG24JQjPv0qy4H7sTsq.dlldll a8ca190dd7103cfc2640a478ecb9494eef7645fe356d9d291cf1a0a6fe460191n/a Heodo
2022-05-199OL8A8IQePFTTTPjb7zm9.dlldll 0fb0b81c74b7369e79fc315562e5fb4a9be9186b2cdd4938cf36b3d967525b55n/a Heodo
2022-05-19ayLkr3w4ftE5cM3UjHf3gaiJ5dn91.dlldll 9e2d4c9e734fd0a2ff3acb6d0c667a94ed5d212ab6aa2089285f39b368d1127en/a Heodo
2022-05-19u8F5sz4HY.dlldll 8d0b6f34c38191b12286c7d7924dc549e44ed41ca6175a0a788df4a870367344n/a Heodo
2022-05-19owFOL7FD.dlldll 589110ec661f9f22489c25399ff9fc97ab8213788608d287132fc298e39a8756n/a Heodo
2022-05-19G7Yl3UKeuRB8ql9Dz66ffdA.dlldll e50aa7be058f0eb78ec2543b13cb01b0a72d546bd3cb53d883869ad92833a074n/a Heodo
2022-05-19gi8B8BTzsxKzK7g6TS82.dlldll 13cdacc11fc7eba11048354fba38e7d0388a2a3f5f11b7e0aa997a61ba1d1db7n/a Heodo
2022-05-19zcNvi9.dlldll 73933c8a68bc9a6a54e2d12b216691ccf49edb06db13340d77d780e0c55ff9cbn/a Heodo
2022-05-19QUQn5DRGw9EHJx598E.dlldll c27b0fa626bc7624e07799984382770bb69e96ffde51d1e637184a895dc435fen/a Heodo
2022-05-19r2aXARRwr1H.dlldll 8c1162e69d2cd56ec3c12ef9c4753adb4e9f5b9ab716af199c0e564e98ec7ae2n/a Heodo
2022-05-19Ya7UvdJ4.dlldll 23f555ac9c1947b7cff0d04146059b6f63bd5b93c1dc286cd765ad221bef6765Virustotal results 12.12%Heodo
2022-05-19M9cEfEfi2.dlldll 9328bfe8b191d87534ed2f821d803400de0033c665d5d707c19d4f119f74c9daVirustotal results 12.12% Heodo
2022-05-1977alQZpIGfqFozzhF8.dlldll d2ce0875b8677c8fceaef47f29c11452a9fb6eeb97c98706c64ec082a529e236Virustotal results 10.77% Heodo
2022-05-19vcNajVQ0KCh8M81r5WQiHnhm.dlldll 1adf0abde2b154ba5947318669d6a9ebc5888003b6d204efa5a033b431fb2477n/a Heodo
2022-05-19s3BZsACGwrHG51I5RyqNAbkfsop2T88.dlldll 25117e8507a93b88e315c32bca1538e1d4980da1ddc5029143db694f5a3c99d8n/a Heodo
2022-05-19ajMmm2moXGKQ11j6mUgM2azhxD89y13KeY.dlldll 16b283057b921ec0dd85e14d4780cad6c1e3c9c79bd9add48dc1dd41f64d85f1n/a Heodo