URLhaus Database

You are currently viewing the URLhaus database entry for http://burakbayraktaroglu.com/RRM/TfNOozAF/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290166
URL: http://burakbayraktaroglu.com/RRM/TfNOozAF/
URL Status:Offline
Host: burakbayraktaroglu.com
Date added:2020-01-16 16:56:04 UTC
Last online:2020-04-07 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-16 16:58:04 UTC to abuse{at}as42926[dot]net)
Takedown time:2 months, 22 days, 4 hours, 57 minutes Bad (down since 2020-04-07 21:55:06 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18Inv_YMJL3_628806130.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18invoice-DQLG426_3747505.docdoc d4d29c6cfffdf351ad541d65a634554e0a99a4486477bb307f318499af87904bVirustotal results 24.59% Heodo
2020-01-18Invoice-TT93_01841866.docdoc c0ddf7ec4f4905aaafd9371d7d00d8bd21bf9f5d9d49403591e1cfbde36925ebVirustotal results 24.59% Heodo
2020-01-18Invoice-OAJW0417_91334427.docdoc 47a9f8a44bb8dfbc68d6920020a9ccc2114c63bb81227c2fda6e23ba2e42f689Virustotal results 21.31% Heodo
2020-01-17invoice_924_357078946.docdoc f95984ef535315242fca3fc45cb952c5918ca8fecb789f8a803e4e1471a25c94Virustotal results 22.95% Heodo
2020-01-17invoice_KZI228_370540.docdoc b09c1b973c6ca799fe7817c241a0a1c56f907feffe6ecd63daa615be18c7b077Virustotal results 20.00% Heodo
2020-01-17Invoice_QVLD0_304705.docdoc c1773292833e3d31b42687618328bfc2e893bc2262b9d3ddeda0dd585eb5446aVirustotal results 19.67% Heodo
2020-01-17invoice_AQ37_349376.docdoc 3f227c11e8835a6cb877438bf4628c9b105553fa1fc681389fcf5bd5574dcfa0Virustotal results 19.35% 
2020-01-17INVOICE HRJ1872_931866061.docdoc a08f21468d7c8a17f7379336e83591e128cc052dce7b176093e31c5d1474faffVirustotal results 23.33% Heodo
2020-01-17Inv-SIFX2148_5595517.docdoc 5b5d276c15b051d7bd90d0a94065b9989ff8678436c073df253abb3dc9d5f2c1Virustotal results 22.58% Heodo
2020-01-17INVOICE-791_9087829.docdoc 127fbb144e09a37a3fb74478730d2c431fc0876897035497e7dce1c49d3d539fVirustotal results 20.00% 
2020-01-17Inv SBO32_1385964.docdoc 298a10ce8a9fe8dcc5947d02585a549d1c9d0609c7d11473ff4c8dfbb3a9f801Virustotal results 21.31% 
2020-01-17INVOICE_EK467_0124698.docdoc 52a35085b05a7fac898644b7e69c83730e819e568480c29301e09e9a19dc2578Virustotal results 21.31% Heodo
2020-01-17invoice_F660_0879066.docdoc 559a07cd9e86fcb6787310e586b5f97ad4ecd0cbfad46d213673d6f8c9618999Virustotal results 20.97% Heodo
2020-01-17Invoice_13_78574570.docdoc a841b264457a4ff7ff83a9b12a0f80c9902edff2f134497e5906e16a3b5b77adVirustotal results 19.67% Heodo
2020-01-17Invoice_B67_79971403.docdoc 73d84770b9d67293fc05f7ecc0a3b786460733830a371c72da8f40bd81efeb71Virustotal results 16.67% Heodo
2020-01-17Invoice_Z16_251347656.docdoc efef469ac7e82a2301e3e2da0c734792182828663bd6d178f0d773bb4c37f07aVirustotal results 19.35% Heodo
2020-01-17Inv-YXG7134_72087766.docdoc 49d1ed63fb1865194aa945db313813714c58aaba9e0fe76dc98e5238f0625c3bVirustotal results 19.35% Heodo
2020-01-17invoice_XTI637_910710672.docdoc 30c567c6efb9fbfe69f1689efbf61d25a4e8eb9c44018602a7bbbb699505ddb1Virustotal results 19.35% 
2020-01-17invoice-BLH56_557216553.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo
2020-01-17Invoice_QP68_2334607.docdoc 197af116115110512c62798ebf269522be366efda960b47d38c99064a6d9f373Virustotal results 37.10% 
2020-01-16INVOICE VE9372_92030347.docdoc 8cf5201a2f5adc4ddd6ec8d61ae4674d9c4df7554ef49f76052275f95db6a3a6Virustotal results 36.84% Heodo
2020-01-16INVOICE-J345_31777292.docdoc 2e1f347233bf11c5e1231fd08171ba3cd797101180810eb5984a728f282af86bVirustotal results 36.07% 
2020-01-16Inv 4763_4168241.docdoc d13f1552e6310f6d13bdc787f2cbd5b72fe9bb53581b6b833d8d6f5352673e08Virustotal results 35.48% Heodo
2020-01-16invoice C2918_43340757.docdoc d138359ab7543bbfedd4895fb0e815b5a41453c87e601a5a4ab2d04363a3aec0Virustotal results 31.15% 
2020-01-16Inv-NXP0_8875660.docdoc 3733fb5c12eb91bf990e79b83409042accf206318cc69a2ba170c69a7fa2da30Virustotal results 30.65% Heodo
2020-01-16INVOICE-DFOW36_87953776.docdoc a9c149a3e340636d38664f3cfdd5fd4fb95a2fd330c0c1623096b9fff0629a44Virustotal results 28.33% Heodo