🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://www.gelisimcizgisi.com/articles/wxpg6fk/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:248065
URL: http://www.gelisimcizgisi.com/articles/wxpg6fk/
URL Status:Offline
Host: www.gelisimcizgisi.com
Date added:2019-10-23 19:16:02 UTC
Last online:2019-11-01 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-10-23 19:16:16 UTC to abuse{at}as42926[dot]net)
Takedown time:9 days, 4 hours, 3 minutes Bad (down since 2019-11-01 23:19:37 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-10-253oIc1Cme3LL0amJXF.exeexe 033db3f346e94c3cfdca8210a26a148506d53b5167b3cda4af1721116f38aa08Virustotal results 13.04% Heodo
2019-10-25oszedGMiL7SgvpzjvS.exeexe c134c7e27fdc8a88d1a75775b41ebf13d5a66e42050d0dc39771455c05e02edfn/a Heodo
2019-10-25THYej7r2Na.exeexe 41e0ae1c1f3137cd6a63d4dd586388878c7df93b3c9ba314103fb00991c2da62n/a Heodo
2019-10-250f2Lg.exeexe 514f013d9848a19291a2cad493a3b3a5c2f37661ff1a713eb21716b39e5afb5en/a Heodo
2019-10-255caNN7srdxsAC.exeexe bb09f54b5f0ebc879b1a9c39c8e387971ff1a2429674d10a1ed74e74736e2f75n/a Heodo
2019-10-25IMc4j0PUzXRybMYE9Hd.exeexe 6c4beb4b748544ee3dc71419a0684f42659f63ce87cc4fc9526f7634da6ab900n/a Heodo
2019-10-254YokJvvCG2Lcw8MgnV2.exeexe 5ed1d51382f493a1bd562f4716ab2b6029dda3d44587d2d3ae500e99bd1247c6n/a Heodo
2019-10-25HYynqqa.exeexe d1deb7f8195050e4412311ad96980dccb50dcbf24b61e31af577104bee2877f4Virustotal results 10.45% Heodo
2019-10-25NLdEMWSXRG7fx.exeexe b17cb9569882ab3f112045f53221caf82166325ece975280d07bb38fd2d9edfbn/a Heodo
2019-10-249n6e6QFTx4J6RFsMZLZV.exeexe ab264199a77bc7d6ecc258b5ce4a7437a7f2423e07a29cfc7721aa5894867820n/a Heodo
2019-10-24w0hfSsfAUW6V9SGC.exeexe d9266c5f3ca790f85a11a91e8c5cf847edbd3179ffc040173a527c27066a3b92n/a Heodo
2019-10-23QRyts9jczFqsFc.exeexe 5c138290815cf635fb9947f9753c73dac1dbd855a2153116cb0a3a4e6e07944aVirustotal results 14.08% Heodo