🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://www.gelisimcizgisi.com/articles/swift/an60jqee2hhr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:271299
URL: http://www.gelisimcizgisi.com/articles/swift/an60jqee2hhr/
URL Status:Offline
Host: www.gelisimcizgisi.com
Date added:2019-12-18 05:28:04 UTC
Last online:2019-12-31 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-18 05:30:04 UTC to abuse{at}as42926[dot]net)
Takedown time:13 days, 11 hours, 39 minutes Bad (down since 2019-12-31 17:09:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20O58S9AOG42.docdoc 9d9500698184db7afd0bd7e940c75d296e258565869dc4931e8929163d36144fVirustotal results 36.07% 
2019-12-20LV9CSXA3ARE168Y.docdoc cfb0cbb56627739ba234e9269d51ffb4a8b5b96ecffef88cd1cd54dbb2230622Virustotal results 35.00% Heodo
2019-12-20REP_FIW_120119_IZJ_122019.docdoc d4ba52d9d0bafa44d2f58ed37b6da8bb06cec304debfcded6063335cf8bcd452Virustotal results 31.15% Heodo
2019-12-20INV_17748573.docdoc f917dc0d1080638f16e961715423d9abf2e22a9256b0e64c77561e0a0596dffbVirustotal results 31.15% 
2019-12-19BAL_178559019271.docdoc e035da04fbd305db668030d579d817ed3b697f8c15deee9e348a68d0e2fd2c34Virustotal results 29.03% Heodo
2019-12-19DOC_PO_12202019EX.docdoc 06d4827e5508a4231a77970993b617250ca0ef8dd422fb86400ba454b5f84510Virustotal results 30.65% Heodo
2019-12-19REP_26965496.docdoc 7a2ed8fa46f8f6c6f5ebfad8d9b345a5a4dd4e8f65d8e416f2a88faa6d17d327Virustotal results 30.51% 
2019-12-19COU_53116719.docdoc 418448a9e03c300d29a1442db6c5a6b38b0458ea72f09e6cbce326f32b95b84dVirustotal results 31.15% Heodo
2019-12-198939247217648.docdoc 0908d13ba6aceb7e348c10b662dd734230f6e170eb9e10d6c0f8ec6351835e37Virustotal results 26.23% 
2019-12-19ST_MA2000038605AS.docdoc 7cb2aa92217f3090d559ea14541ffee7c4c4234cb1f7626ae797310c978928d1Virustotal results 25.81% 
2019-12-19DOC_PO_12192019EX.docdoc cab558382c472327262ec622f65f4af66a95270001ead6dd4872294b51f7c426Virustotal results 26.23% Heodo
2019-12-19FILE_08813146435.docdoc 680e2b8bdd4e9ff629943f71f9520e38d77b6357396863dc1912acf559f0f181Virustotal results 26.23% Heodo
2019-12-19FILE_75516525678945230844170.docdoc 1735d3c1c0d1500169d6a078c16216336af67c126f9dc97046f18d8f3c5a7d86Virustotal results 25.81% Heodo
2019-12-1985783470.docdoc 983bfe2db0099f8bedff111f84e467d8ca14e731d3338a79aab5573d2f2b8412Virustotal results 26.23% 
2019-12-19PV0439704509VV.docdoc b0ac17faf517301d9a4b18edc0f4a7879335f2f225e2dcdbe4a6377f598a3f99Virustotal results 22.95% 
2019-12-19RP_PO_12192019EX.docdoc b705c6b11ce5c95ab6e45a9063da6bd67b5418f1be7a7168bffca09db9e958d3Virustotal results 22.58% Heodo
2019-12-19RP_CVG_120119_EQS_121919.docdoc c47d8b26bcc8321e79d13181ef292f44c1498910dcea8e76d9d2043654a79ab7Virustotal results 22.58% Heodo
2019-12-19RP_Z3HTFVMTYV.docdoc ddaa319d0b931c3544584f2791ec7129d32602e2deaee2296e1aaa740ac7d300Virustotal results 21.67% Heodo
2019-12-19FILE_PO_12192019EX.docdoc ec2cbbdaa442e182f9375cf3860d8ec64897319a62aca277d9f3c2cc5005d888Virustotal results 31.15% 
2019-12-19DOC_190001992268306394.docdoc e4cff33774c6680c4f2e21c49fd53035033df8960dcdd09ab257f157f3bdbd09Virustotal results 30.65% Heodo
2019-12-19REP_XR0855183283GU.docdoc 25c2ee71d3634d4faae32d7a915af893e09b1f36fd93acb0b76e310a9c307758Virustotal results 32.76% 
2019-12-19REP_AW6QNS21.docdoc 111fba0d860fd979a1989e2b6e69b9acc88907a853d66c088c5194ffbac8fb55Virustotal results 30.65% Heodo
2019-12-19ST_ZIL_120119_GZY_121919.docdoc 5858055c94e91c3d9d3c04d19ec5f4b2e741b26353926166833f40ccf4e4373fVirustotal results 24.59% 
2019-12-19INV_PO_12192019EX.docdoc 22ff57b28ae475c76cda6b53efe3c641c2c32a74f593b7f7a7612cd8e4fea151Virustotal results 24.19% Heodo
2019-12-18EJG91ACE8MZFYQP2.docdoc 2f37a55acc32e7d59e31d6c98effdc3171e447d51f5aceea59451fe493461b9eVirustotal results 25.81% Heodo
2019-12-18REP_48939670.docdoc d697c45ef339d7418ae7caf0bf640fc4055605c8892508d825c21c701364930cVirustotal results 25.81% 
2019-12-18ST_PO_12182019EX.docdoc 3c343dbc7eda88227ce41d5722e11d89a0c4edad93a4d82a954fce768e563d79Virustotal results 24.19% Heodo
2019-12-18HTM_120119_VSN_121819.docdoc 8b974a004a4926372021ced18f1b480e32367d38fb9e5e8e29ef08f9b03232f4Virustotal results 24.59% Heodo
2019-12-18M_PO_12182019EX.docdoc 233febb887420830d6a0beb5286cabf162f8b1eaefd9cea4ac5b6b9b6d9e79f9n/a Heodo
2019-12-18SW_PMT_120119_CFJ_121819.docdoc 72851487d72a6a77325466baa49993729a1f37c30e7cde22654fc795d3e5e09en/a Heodo
2019-12-18BAL_7CYNP46JTF.docdoc 658be9f7b3eaba8e95ca6c2b0fd9ea9cfa05b51520638825f555de13e3dcb88fn/a Heodo
2019-12-18LAAP_OI0878006693VL.docdoc 267c6b931989c13475cfdd22641b07a8fe42059c916f87d6c3f186981e675709n/a Heodo
2019-12-18ATL_STV_120119_UVB_121819.docdoc 5757449785632b624ff738f718b04e00758e864f469378b8c513d55346c5d3a4Virustotal results 20.97% Heodo
2019-12-18UBME_PO_12182019EX.docdoc d19458049a137e1bfcd3f580aeef39686b6e1ea204dbf4f4a3abf79bcde08016Virustotal results 42.62% 
2019-12-18L_724195953450929.docdoc aaf3e3daf13c96071a436e0b71879423e317e159aea31f016f469790375c4954Virustotal results 42.62% Heodo
2019-12-18BAL_00334656.docdoc 643bcda55b227fb21e766e8e1e1faf4471239a6f4e7236c1a7a1b979183abb65n/a