URLhaus Database

You are currently viewing the URLhaus database entry for http://demirelmarka.com/wp-admin/vMmu5VHyAbUgIU/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2403148
URL: http://demirelmarka.com/wp-admin/vMmu5VHyAbUgIU/
URL Status:Offline
Host: demirelmarka.com
Date added:2022-11-07 10:43:11 UTC
Last online:2023-09-08 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-07 10:44:12 UTC to info{at}veridyen[dot]com)
Takedown time:10 months, 5 days, 8 hours, 47 minutes Bad (down since 2023-09-08 19:31:17 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-08oDE9WxJQz.dlldll 0562f10701dac4c3c318b2605e5c04a04e5ec5ad03b9d4c8c6df2786165d403an/a Heodo
2022-11-08Yeg8VUCZyzWav.dlldll 05948f9bd3d7e561ff10dc11bc8bc326166cebb545242dda4b24676e723f867fVirustotal results 10.00% Heodo
2022-11-07eV8UFHr43tgK9VJEy.dlldll 70b101f870dc935e9c48d6df37f3d1d355e48fc174a77c64f2c21844bf39d880n/a Heodo
2022-11-07RKjR9.dlldll 331c817d68174c56d17bee5614bf49a3e23a60227d85d04b42b493b2dcf09f02n/a Heodo
2022-11-07YjcP81AD.dlldll 7f893c8441abab911d74645bb3fa5d45ff2e10ccb698ddd609f3b3ed2986521en/a Heodo
2022-11-07Oi9moYCYgrdv6bhF.dlldll b0c80e2c04cec07b0e0409d2167d0bf4903abf7c1c5ea1aef2cb4ba97350a0bfn/a Heodo