URLhaus Database

You are currently viewing the URLhaus database entry for http://www.cankamimarlik.com/b79b/fw-03-518/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290628
URL: http://www.cankamimarlik.com/b79b/fw-03-518/
URL Status:Offline
Host: www.cankamimarlik.com
Date added:2020-01-17 04:23:02 UTC
Last online:2020-01-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002252366 created on 2020-01-17 04:24:04 UTC)
Takedown time:4 days, 13 hours, 52 minutes Bad (down since 2020-01-21 18:17:02 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18Invoice IZJY03_895753.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18Invoice_SK176_43110239.docdoc d4d29c6cfffdf351ad541d65a634554e0a99a4486477bb307f318499af87904bVirustotal results 24.59% Heodo
2020-01-18invoice XPXQ281_006500.docdoc e4def16e9897c04029e960d9ba6d20e17757ac6084e0e9ecc6cab31c90669e8dVirustotal results 22.95% Heodo
2020-01-18invoice-EUEZ062_154539188.docdoc 315f3d156f10ed289ffac2ac3873448cb7c7dab3d36fc8039414f1b9e1dcc8ccVirustotal results 21.67% 
2020-01-17Invoice F4_1034055.docdoc b09c1b973c6ca799fe7817c241a0a1c56f907feffe6ecd63daa615be18c7b077Virustotal results 20.00% Heodo
2020-01-17invoice_WXT8061_528169.docdoc 562abea095cfa78a34b3896d0d1c23bb11525f5c7691852026b0aaa3d97151c8Virustotal results 19.67% Heodo
2020-01-17invoice_9670_19074341.docdoc 3f227c11e8835a6cb877438bf4628c9b105553fa1fc681389fcf5bd5574dcfa0Virustotal results 19.35% 
2020-01-17INVOICE_BMB8778_76091177.docdoc c2a34f2fa198fdede9e3fb3fc4e57fce58804b1c011c6e1c2b17df401892c5dfVirustotal results 19.67% Heodo
2020-01-17INVOICE-JRPP7_22188281.docdoc 75da7c2a84d8e27223752a60ebe7fafcc97c8f989ab0a73e6563907e6acce897Virustotal results 21.31% Heodo
2020-01-17Inv_IS3918_4074635.docdoc 4cf6b6c5e758de95aefdb0fffc36013c29fbdee525c30ebd1b85f19870f12963n/a Heodo
2020-01-17invoice KA126_683867.docdoc 8a6ec05e42e466376aeceae1546dc1bcebd46533c261c34cb081fc6c9c8d272bn/a Heodo
2020-01-17INVOICE NT2_1057523.docdoc 00f75724fcb4f68254a9f4fe7f165b94256863fda19aff094ac9899e4d4ae4c7Virustotal results 19.35% Heodo
2020-01-17INVOICE HUA472_168354.docdoc 559a07cd9e86fcb6787310e586b5f97ad4ecd0cbfad46d213673d6f8c9618999Virustotal results 20.97% Heodo
2020-01-17Inv_ZO955_6694627.docdoc 1779c3feb91fa26bb312d90acfb4a4638f6c19436efc7da51d6ae616b512aaaaVirustotal results 18.33% Heodo
2020-01-17INVOICE 726_0616148.docdoc 27cb856a1ee8a5bd2e6aba631cb7a1fd851745d719ccc87aad0e3fb7e586975fVirustotal results 19.67% 
2020-01-17Invoice-ZVTC7854_496445492.docdoc f5afbf6f6037177757cc1129985541003a253d7798a2120e9c1e823d252f31a5Virustotal results 18.03% Heodo
2020-01-17Invoice F9_041725318.docdoc 705c0fe4297531835d50b0458ac82dd33ecc2372332fa70d25d6f723ee898671Virustotal results 19.35% Heodo
2020-01-17Invoice-RY53_460502.docdoc 454860d7029b74eac669dce8ec4024888e3e19b85e5a8a07f56fc2e0e7b96d81n/a Heodo
2020-01-17Invoice_KJWY6261_76933381.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo