URLhaus Database

You are currently viewing the URLhaus database entry for http://omeryener.com.tr/wp-admin/oakwcoWufii0JR89G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2202603
URL: http://omeryener.com.tr/wp-admin/oakwcoWufii0JR89G/
URL Status:Offline
Host: omeryener.com.tr
Date added:2022-05-19 15:02:13 UTC
Last online:2023-10-14 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-05-19 15:03:17 UTC to abuse{at}internetsahibi[dot]net)
Takedown time:1 year, 5 month, 2 days, 20 hours, 14 minutes Bad (down since 2023-10-14 11:17:45 UTC)
Tags:emotet link epoch4 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-05-19UKqv3Y.dlldll ff324b46542fafdcb1c9230468a27a9ff532fa01d5d6f1cf6a740df07e0d5f37n/a Heodo
2022-05-19CIbMcQZFtDLq50jZ49MAMeCG340de.dlldll 7936ea2159d4e780f30a8fb4c4016f1b60fd136532e07cee1531af5ac880b7f9n/a Heodo
2022-05-19kHFvuT.dlldll 1d0dc0d9ec5441b9066969553f3282496127c80d4fb38d7a24fbb87e867dc9d8n/a Heodo
2022-05-197LkO7qs7EsejJ1G3c51cwwFS7TtGllqxq6q.dlldll 173ac65786f6abc15ddd794df13a2f7fe09ad66a1c8da8a603382fe321f01557n/a Heodo
2022-05-19ntgGqAgEo3htS0shzZMoFstUg4TzU.dlldll 01869de6af51a955d35aae0565a03652745ac56f39f3d4ace1c7997794874bf8n/a Heodo
2022-05-197nLAEfAESbNMArYOJt.dlldll 9377aefab2c5fdd1ee8fe68c5c8f619ff1381a0b57375093c8e8387e2c4100b1n/a Heodo
2022-05-194eIltbgIcvjm.dlldll 282fcdefc9a4856a43e497044632943276bd6ee80c7c55e806e6b456175ab1ddn/a Heodo
2022-05-19KoOdvmOk6kV7az7Wa60XxlgaeBH4wQmX.dlldll f8643cb335a43d7a1720e2edf1cbc13c4e844ad5fb03516091cb4cfa108c762fn/a Heodo
2022-05-19nf88VZwBf8f.dlldll 634eaa4ef022e97e521af59257d6340b7a860dad1c45b973a95092fd9a36c772n/a Heodo
2022-05-19qhiZBfe1BlEPmo99QaljP.dlldll 6824453837acb4a6521b1e413cf0b38a5c382c1cb8426ef5813696c3e4dc6b72Virustotal results 15.87% Heodo
2022-05-19hhCgxC8J9qVp8OSo4RWseaYDSP5zSG.dlldll 26b78d9464def944e5c66781c9193ddc5eb7939f57a37453f9075092c8ad684an/a Heodo
2022-05-19rUFrsgimT6bv.dlldll 519d2ad96eb33675dcbf92a3936c28d6f835c0ecbae78815071f1907a9447e50n/a Heodo
2022-05-19rssxvxqTPBwkLWTdjjKWEFO46.dlldll e9b860268f43e21c8a347e2a3ea3a85a2dfadf68e0a438f06661805a2e66c9c7n/a Heodo
2022-05-19gagl09i4IZ.dlldll 0f3e4089be9cf9fc0c027c911e7f6eb073ee7261ff27e5c3fbb7f535400578dfVirustotal results 14.93%Heodo
2022-05-19cHcpuk5yD33nqeWGPijSC1GoTDkqEnHF.dlldll 0f3b9547663cb26e51865de0c6ef096f677e7474b6993058716e718f32d72ad1n/a Heodo
2022-05-19k8BGDt6.dlldll 102c667e5ea0ca60fda0eb39575459451d65b7c9cc61fdeedb3406369c69fc26n/a Heodo
2022-05-19oroMRa1Xx1nQsU7Ih7eiH.dlldll c76e79d7666d7728c5f9c77b4bdb2729350075755e37d4a5893c18ebd10bc70cn/a Heodo