URLhaus Database

You are currently viewing the URLhaus database entry for http://www.cankamimarlik.com/b79b/statement/6b9zy2/o-387360640-231081923-1n87-3ezq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288705
URL: http://www.cankamimarlik.com/b79b/statement/6b9zy2/o-387360640-231081923-1n87-3ezq/
URL Status:Offline
Host: www.cankamimarlik.com
Date added:2020-01-15 02:25:03 UTC
Last online:2020-01-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002246075 created on 2020-01-15 02:26:05 UTC)
Takedown time:6 days, 15 hours, 49 minutes Bad (down since 2020-01-21 18:15:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17FILE_45919306.docdoc be035f21045625171a259dea7ec7b6952cbc49b4be98c46341560e28ccd5b605Virustotal results 38.33% Heodo
2020-01-17PO_01172020EX.docdoc 92f80243e6766c07a9eb3c8ef28eff839d1f23a112c0387911cda51154751b9aVirustotal results 38.71% 
2020-01-17RO2307743179CV.docdoc 48844b331c7b74aac980dd55bd8d8388d187e2d3041712303c59644ef3fa16b7Virustotal results 36.07% 
2020-01-16XC_36387513.docdoc ec7daa97138174c5878ea751f64fc280edd5c475f1ad353be67afe6c74b2e857Virustotal results 37.10% Heodo
2020-01-16SW_PO_01172020EX.docdoc 6251dc8ce7ed89205baf4e6a3d316ab1e4fd974b5507a102fe8a8dbbddcc47c9Virustotal results 37.10% Heodo
2020-01-16REP_31193675317334516.docdoc 1f3e3d25e4bf6b2abe937cad881f13233701da7dbd9a165f895856e56e0e0ee3Virustotal results 36.07% Heodo
2020-01-16DOC_TQK82CYG1.docdoc a9c48a4f2a96384b1fe947448cb44eaadeb7c0a7754cd17a6899c7f6ae31f2e7Virustotal results 32.79% Heodo
2020-01-16RP_266562405422561192085560.docdoc d2ce1838da599f490397183272a746696999155f408cdd5da5d82c3ae1df24faVirustotal results 29.51% Heodo
2020-01-16ST_71674SSD9.docdoc 8bf5586fdf5c09bd987b2246b8a60988842d2b3ca683a4fdd6f0a698d17909b0Virustotal results 26.67% Heodo
2020-01-16FILE_SQ5XV5CG.docdoc dee80fcc93fdf28fb6d796015785e587e2fbc779c948f6ebc6f3a5628d54f905Virustotal results 26.23% Heodo
2020-01-16REP_OR1870199099FT.docdoc 743632f16eaf4dffd8109a5ea7c14e341db9af20a96f44838a046b9c6b183fdcVirustotal results 25.86% Heodo
2020-01-16NG_75771623.docdoc fe6f474786ca7ae00ef0969337551f4f2b639e640014ba936d413e532bd994cbVirustotal results 24.19% Heodo
2020-01-1680721964.docdoc 21222de7dc129cc2ceb960d884aab5660f053b0186d85f48f302257ae6075bd5Virustotal results 25.00% Heodo
2020-01-16INV_VNC_010120_MOW_011620.docdoc a7d3f5474bdca4af088225b9280da969e8678960b6768ab6944a72866252c9dcVirustotal results 25.42% Heodo
2020-01-16SW_9480163113508.docdoc a8daa5abd8b28562b74c89b4eb926bba5e5bfddc7746e95a5d4055896680ea69Virustotal results 22.58% Heodo
2020-01-16FILE_ENL_010120_QZP_011620.docdoc 1811c88cd612722c68074102f9a909b3b8fbd412f4c6aa68837ad23c3162d166Virustotal results 44.07% Heodo
2020-01-16INV_14476881.docdoc 95b02c0e112270751b5fe7a49866ed9d31594f0b8d26e823e2242bcc3b902b26Virustotal results 42.86% Heodo
2020-01-16VGZ_010120_TOH_011620.docdoc e986e2699cefda7e454ff5fcc49b5189f28820627ec920d2f4c2232d5412e64dVirustotal results 42.62% Heodo
2020-01-16FILE_LPJ_010120_JBQ_011620.docdoc 6356502847f02747fde34ac7489acade27cd431984d33bd7800cbd4ea1bade78Virustotal results 41.67% Heodo
2020-01-16RP_LDC3RV9DIHQXS7JQ.docdoc ce8d4dd1617fb895654d24feaa3f6da3c4408ab00f22ec1c7adf958c9425c89eVirustotal results 41.67% 
2020-01-15014K8V1N.docdoc 2c40438076c3f7beb36d70f56c99baf764aa9c3936060204d6fdba9f27e6c847Virustotal results 34.43% Heodo
2020-01-15FILE_PO_01152020EX.docdoc 785feba560f2467465e64cec8a888b0ed5d477f94ce139eae8f6448508942595Virustotal results 33.87% Heodo
2020-01-15PO_01152020EX.docdoc 60d2c8f3e62e237ab3c9d9f1e822485b7cb0751b9c389cb2230222adfd189a97Virustotal results 32.79% Heodo
2020-01-15RP_PO_01152020EX.docdoc 33c109c33a748ebb55fa788c5a5f0b4e575d51e007a9961f0026ea079438091eVirustotal results 31.67% Heodo
2020-01-15ZT5524572284OD.docdoc f9e2be2a0caa6cefaf4283589b74bc8522504fcd989307520c9d9c9908cde5a9Virustotal results 18.03% 
2020-01-15V_AKRXC717IV.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15INV_67254376.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10% Heodo
2020-01-15ST_NK5780837369ZW.docdoc a5ab4f49f85a942911907bda864337b1506a94af7fcf9b00838fca0315e0b7a6Virustotal results 32.26% Heodo
2020-01-15INV_JS3266355539ZY.docdoc 17cbb232fc64e8c775b7ed47a28ec7a2cfaf6cca790994fad3c41fb60a648062Virustotal results 33.90% Heodo
2020-01-15A_WBT_010120_WIC_011520.docdoc 958b22bd337775f2226fecdcadf9125b8bbcad2518c23d026fd87b0714af1b63Virustotal results 31.67% 
2020-01-15ST_PO_01152020EX.docdoc 14623bd34509c1ac8a864c3fe625904e41f5487ff211bb55fefc880db03eb83eVirustotal results 31.67% Heodo