URLhaus Database

You are currently viewing the URLhaus database entry for http://turbobuicks.net/yWAvMi which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:23642
URL: http://turbobuicks.net/yWAvMi
URL Status:Offline
Host: turbobuicks.net
Date added:2018-06-26 09:17:45 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: amuehlem
Abuse complaint sent (?): Yes (2018-06-26 09:18:04 UTC to abuse{at}data102[dot]com)
Tags:emotet link exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-06-2671914.exeexe 21c9792ad7ef628b3ab19f401dfbde164e107f6851dd2f67bbec489809fe0366Virustotal results 19.70% Heodo
2018-06-2643759.exeexe 263365202c3905ae95f8a138f22317bb1db30eee0ddee0fd6ecc70f785df9a91Virustotal results 26.47% 
2018-06-2602611.exeexe 9c7eaf1042b52f56afb726a521eb907aa01092e50979f5068bde380a234461c2Virustotal results 26.47% Heodo
2018-06-265166.exeexe 204389b321b41f7276614ffa4063485df9ab99ceac283a139e2993997d3758a8n/a Heodo
2018-06-266335.exeexe 99af7caeed9579618bef7affddfad8bad7b12432499c30eecd39c1758936127fVirustotal results 26.47% Heodo
2018-06-2694863.exeexe d3b6d6d5d7f64307796c044a29bef308f3532da99ace7cd1e24a5bc18ffe864cVirustotal results 26.87% Heodo
2018-06-2660680.exeexe c15a80e25ae5ca46aa1b79048b4119979aab0d45fe4cd335c0c71b7668dd6b58Virustotal results 23.53% Heodo
2018-06-2632759.exeexe 2789e0aa1f138b65fd7df9396e16dbd580441f60fcf44486e7fa2970372da921Virustotal results 25.00% Heodo