URLhaus Database

You are currently viewing the URLhaus database entry for http://infraturkey.com/wp-admin/ttjg1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:248225
URL: http://infraturkey.com/wp-admin/ttjg1/
URL Status:Offline
Host: infraturkey.com
Date added:2019-10-24 07:33:13 UTC
Last online:2019-12-03 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?):mail Yes (Ticket DCU002040704 created on 2019-10-24 07:34:08 UTC)
Takedown time:1 month, 10 days, 11 hours, 47 minutes Bad (down since 2019-12-03 19:21:42 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-28gfjakyemhhdjtz.exeexe f21e46975e3d04f9785987421ddf864535d214f24d2023aa8358002890db190fn/a 
2019-11-25gfjakyemhhdjtz.exeexe cc91e384901f0ae821d0c74335dd452ea3ffa5fb56f1cb652414ac9dfd32d675n/a 
2019-11-25gfjakyemhhdjtz.exeexe 570cca22f1bc2c114e3f37f91c9017705879b616c5a4365c17eeb1a785f188c7n/a 
2019-10-26gfjakyemhhdjtz.exeexe b8d2bbfd4494ba96c903644f454c10c237c2c38ec9a7eb1ac9842a469dd4ee52Virustotal results 18.57% Heodo
2019-10-25o8zki0jd191fcqj.exeexe 5b512041b1908d57fe6dc89144ead211fab6840dde16abb98b136db7dc42c7f8Virustotal results 14.29% Heodo
2019-10-25cqm90z8sthnkwcw.exeexe 17914740b20cedb3ffca023f666e769a97f453ef2ec88609d36e71668c5bf9edVirustotal results 11.76% Heodo
2019-10-25rpnmyhp5v.exeexe c395aa1a3ab75c42127ed5d1a7c75dcaa853da800f06dcb69ad47721f0d334aeVirustotal results 14.29% Heodo
2019-10-25fm99d21g0ipk.exeexe 0e86995520e5cc20f856bd0b5bc02cfbd922cbd4ec856589039637099f66c9c1Virustotal results 15.49% Heodo
2019-10-25vt5zb1bw5.exeexe 9146f341cefcf16f7f8c4b0c3647731d3181352c8e61435ffb075e9b7f4ec3e6n/a Heodo
2019-10-259a505iovi8.exeexe 0f95da7c4d36f03172f9956cfa6357292b0da168016ccf463d6d46ddcd0fbc4en/a Heodo
2019-10-25u2zb571.exeexe d3550f12944b33beeac2a7863622d8a01bcfe8011abad3705b99527af4fc109aVirustotal results 19.72% Heodo
2019-10-25j1ype96i1g9g.exeexe 7a9a0765efbbaa137f27ab7a3c5ac7126e1df4157f914ef6f97c63d4d5431087Virustotal results 24.64% Heodo
2019-10-259vwio79.exeexe e51d170990852e84bfc70b68c3fe02da33fe6101d22330307baf2fbd21ef2871n/a Heodo
2019-10-25kkf0brq8jup.exeexe 8ed59a61fda9d98eb2908557c7f6084c1293fffad1b06f6d960a865e5be39752Virustotal results 14.08% Heodo
2019-10-25lvmeoozy369d9.exeexe 24728ebb6468219b0e9bc31935210489fc186259a4f2f2fa95e241d64ae312e5n/a Heodo
2019-10-24spl2mb7u.exeexe d54aaf2f8697762e2099d81c3d37f7f9ddde8e1c6fc39e7648af4a6bfa30a723n/a Heodo
2019-10-24eoy50qtyle.exeexe b3983894fb45e602b20393e681f18ac928e71d8538c0ddaa06471b190e6002c1n/a Heodo