URLhaus Database

You are currently viewing the URLhaus database entry for http://adentarim.com.tr/cgi-bin/UP4HV1WD/q8-6184-85-ofzekyz-5aizbjhypp6/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288945
URL: http://adentarim.com.tr/cgi-bin/UP4HV1WD/q8-6184-85-ofzekyz-5aizbjhypp6/
URL Status:Offline
Host: adentarim.com.tr
Date added:2020-01-15 10:38:07 UTC
Last online:2020-01-21 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-15 10:40:04 UTC to abuse{at}dal[dot]net[dot]tr)
Takedown time:6 days, 6 hours, 25 minutes Bad (down since 2020-01-21 17:05:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17ST_BUB_010120_YDJ_011720.docdoc 5451e1f69314addd99d5271ca08be2b86b149648a0aee6e472c4a070691bc4dcVirustotal results 19.67% Heodo
2020-01-17SW_58504674767.docdoc c09c7c6d5294ba3e6b09892d5972b1c7fc98cacc844c424632a73592e3cdbc03Virustotal results 20.00% Heodo
2020-01-17FILE_1523042852461064035624779.docdoc fe932814b9fb95baf473284ceff4af5ea1100e4893f5a8edfa54b607ab6cd996Virustotal results 18.33% Heodo
2020-01-17DOC_PO_01172020EX.docdoc 37278a792abb805166b18e71b5ff929822059156a73f739e9633dc16984d28ceVirustotal results 19.30% Heodo
2020-01-17L_ZE4OU8ZZFP.docdoc 7bb5fdc2f055e22227b6471aa23ea22c95fa0235bc96bb40893513d1fc6e6d76Virustotal results 18.03% Heodo
2020-01-17DOC_AFUWI3QJMYA9R3.docdoc b5b1a9c9342c9be2197fc3f9fc5c0a9138b052bfc06583f9719773397f567e34Virustotal results 43.55% Heodo
2020-01-17RP_13T9QDCTQ6E.docdoc 7fa223be816eecc1cb7c1193221b48e9168524b565439f844ee97934774953ebVirustotal results 40.98% Heodo
2020-01-17REP_IYKV0P9.docdoc ebd7311c5dc78aa03e65a9b555f31969fb3a6c72f8988b3a667d6b6e002bc437Virustotal results 37.70% Heodo
2020-01-17INV_PV3754897863EZ.docdoc aee82de11a80817171ad5f8919164b13551cb4b3bb15b91362ce6626d2c067e5Virustotal results 37.70% Heodo
2020-01-17PAY_UEM_010120_UPU_011720.docdoc 48844b331c7b74aac980dd55bd8d8388d187e2d3041712303c59644ef3fa16b7Virustotal results 36.07% 
2020-01-165773658625864621626.docdoc 8def2ac70c2cb43d56c337a19ca6897fbf20b5b6807070d75a50964408de45a9Virustotal results 37.10% Heodo
2020-01-16DOC_TPI_010120_WIM_011620.docdoc 862b4995090776854a12fbf924213919016691e4c85ccfa384c7fa92e02e8591Virustotal results 36.07% Heodo
2020-01-16DOC_QZ4784895433JV.docdoc 197816a9e68e03158bf632170ced910411b22478535810022ec413afaa23be3fVirustotal results 28.33% Heodo
2020-01-16DOC_BRE_010120_OZK_011620.docdoc e01f0d1e2f3493dd4ae4dce4cb3f9756c92ad2d7d28ffa495fd8abe649418e4cVirustotal results 24.59% Heodo
2020-01-16ST_CF12EN2NEQCZSMJE.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42% Heodo
2020-01-1670308082.docdoc 865c9a15553f021279913a615733b64a3c7afc750d307d2913a5a12543ba9af5Virustotal results 22.81% Heodo
2020-01-16ST_XX5472156981NM.docdoc 8cf507a5d6fd40526c9419ace90c17b9d91a6949229cd0f5c8afa750836dcf62Virustotal results 24.14% Heodo
2020-01-16INV_PO_01162020EX.docdoc e986e2699cefda7e454ff5fcc49b5189f28820627ec920d2f4c2232d5412e64dVirustotal results 42.62% Heodo
2020-01-16PO_01162020EX.docdoc 6755b22aabcd9dae95e3e99cacfe217231c85f91ed30953a1afbeab582aba025Virustotal results 40.98% Heodo
2020-01-1601182814.docdoc 01d706d0a5e27c62abe9a72200925c5e23ed3c309ea88354dfcb55b36437c3eaVirustotal results 40.98% Heodo
2020-01-15BI5754707744OY.docdoc e763d67d538e1928f4e54ed83171e2b9495156d4c51598d1ef77162faecac2d8Virustotal results 40.98% Heodo
2020-01-15KGT_PO_01162020EX.docdoc 12ab5cc68abfb6224f3a261e8f75acfceb88288023db49fa25ccda6e6620bc76Virustotal results 34.43% Heodo
2020-01-15RP_QNYRK63PP180CCW.docdoc 785feba560f2467465e64cec8a888b0ed5d477f94ce139eae8f6448508942595n/a Heodo
2020-01-150101340554197873886104622.docdoc d791ee2aac6bb4ca4437d45678f50c6ff87d5e6c41ec9a707a183a50be2c7f52Virustotal results 32.79% Heodo
2020-01-15FILE_DR6510111321VG.docdoc 3bd995e4229e3d5adb81c3572c5278e730524b0774cc7a8c4ea710bc4be1ae33Virustotal results 32.20% Heodo
2020-01-15DOC_FX8633344916AA.docdoc a083e27319fc4272f5dfc596e80b48cc91875ba5a2c29787c159929292ebe02bn/a Heodo
2020-01-15INV_PO_01152020EX.docdoc 1ed83f7ed0265fbb7fa1006f405773d31c4b7069ebfbbb6086f0196160f3d143n/a Heodo
2020-01-15PAY_SG8242341602BA.docdoc cd776c68266bdc9dc86cee87e3c792b2100546c13632f5404c8ab9016484c8feVirustotal results 26.67% Heodo
2020-01-15INV_RM1475337437PI.docdoc 04f04f3107a199ae3c5a4ffb960173fc3be31f5c86183d0cb27a23c927d6af45n/a Heodo
2020-01-15PAY_OHY_010120_FTL_011520.docdoc e9f1c310320479dfb1302c7fff4316413d8671df442f0b3552ecf6d9561db46en/a 
2020-01-15PO_01152020EX.docdoc 0e0a399c81d33e87b7aab322fbf562d8c4aae27cc067a553ee092f13bc71221dVirustotal results 24.19% Heodo
2020-01-15N_FK2918356845LC.docdoc ae23c3284230d31527a8b2f8a4721cfa9d31535c93604fcd9be10894eeffc01bVirustotal results 18.33% Heodo