URLhaus Database

You are currently viewing the URLhaus database entry for https://www.fmworks.com.tr/57czgh/protected_array/special_02938513_h8Qw49sV/2X5bNtp5H4Bs_cGi12azvgriJJ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299230
URL: https://www.fmworks.com.tr/57czgh/protected_array/special_02938513_h8Qw49sV/2X5bNtp5H4Bs_cGi12azvgriJJ/
URL Status:Offline
Host: www.fmworks.com.tr
Date added:2020-01-27 23:02:04 UTC
Last online:2020-01-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-27 23:04:02 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:1 day, 14 hours, 25 minutes Poor (down since 2020-01-29 13:29:08 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29File 2020_01_29 B9616.docdoc 66ecd1fbf53f10ac6f349605be071821abddb87b684dbf9e12b5add72eb5a61bVirustotal results 26.98% 
2020-01-29file-2020_01_29.docdoc a4edb0742bb50f5c20c88508ef0dd1028d985dcf0b9ced6c6c9bdf800e1c6748Virustotal results 25.40% Heodo
2020-01-29File_20200129_48178.docdoc 9e66ad03e7885710b534addc2f0c5637987970b3c6185b27cb42a4fcfa06dfc9Virustotal results 24.19% 
2020-01-29inf_4314051.docdoc ab46f8f9b1905e64a35d9db9e9ff84df5eb21679b53d1291553d1b6a936554a5Virustotal results 23.81% Heodo
2020-01-29MES YJL47252.docdoc c2b2cd3b90f72db2fc325fdac1161626765153b7cb874ee42bea9fe3caf0eb6cVirustotal results 25.81% Heodo
2020-01-29File_6974902.docdoc fb8b1e69574f8ec2121b612f1339a516d01536a2174f432585e94c98fba7ab8bVirustotal results 44.44% 
2020-01-29LIST 2020_01_29 306.docdoc b40831be7daa247208f2f37c223101e825eca3eaedbae7a72de040e21852ae00Virustotal results 42.86% Heodo
2020-01-29DAT-20200129-7526730.docdoc d7bcb9c0a8ff27400a3e2a846976dd062129a404c432e34e4fd885f734300144Virustotal results 44.26% 
2020-01-29Rep_X0437.docdoc d0587297f7b5699b364592f59c0d93057b42defb42c714d6381d54a6142953edVirustotal results 44.44% Heodo
2020-01-29list 5606476.docdoc 623303d6b597c92e43276ac21c6338a64cb078760e9a74bd08050666a3aeca13Virustotal results 43.55% Heodo
2020-01-29Dat-9757478.docdoc 85359d87138be58de0c049e5c520f4de37adde9310893971769a0c640ba0a0fdVirustotal results 44.44% Heodo
2020-01-29mes_XIQ738218.docdoc e26c4466ac96339cf441036fb05d86cba2f624e2c7481c1ca86209c19122cbc6Virustotal results 40.32%Heodo
2020-01-28INF_NAY2557.docdoc a5b8d8907e0cf3e09b5a2e7bd993dca67975830d84b0ff832334fdafe4f656d3Virustotal results 39.06% Heodo
2020-01-28arc 276.docdoc 4b4867516d0fd10fb9b46f9474a7db95edf90a09b41086aaa1eef12ed73664baVirustotal results 41.94% Heodo
2020-01-28arc_QMP27198.docdoc fb2b108e0a60dd86b0478caee0c19cb0056953fbfdf00e100184e1a53a031948Virustotal results 36.51% Heodo
2020-01-28list_20200128_7137.docdoc fcb69f15a7e0e60e6d3b818f8c82d51c5a011ff2fa5097c6e85fdccc1781049fVirustotal results 35.48% Heodo
2020-01-28INF_154999.docdoc 76288b03aada28f313d41a8856e42320372dfc03b255335b3d8c0427cb01c4a1n/a Heodo
2020-01-28DAT_DG858.docdoc e973fec4c3e5b5f599c5defe0c00df33eae0e9b00f1f8a1d8f9479d4e343e446Virustotal results 25.00% 
2020-01-28LIST-UT1382.docdoc 59428bbec1459b7f3517f508013242a3dd7f4dbdee059380b5ff1c265abc6197Virustotal results 26.98% Heodo
2020-01-28mes 360.docdoc 17de704a282307408b556e2328dec5c5715d0cd7136dcdc1d6fe54f841dc2bc4Virustotal results 23.81% Heodo
2020-01-28Doc_20200128_G5132.docdoc 45f4837dd3c4164db2df0fc600696eb225eff9a66e0dadffa9ff07c9f797a8e6Virustotal results 22.58% Heodo
2020-01-28doc_20200128_PWH53034.docdoc ff3030128824873fe504c15ecf0cd7b700b36b02bee75fad21ac9d45ea20fa58Virustotal results 30.65% Heodo
2020-01-28MES-2020_01_28-YBM83350.docdoc e3ba2559956e5915407cc1fb85cbb6d4a50bfb9d028a5ba9dd33505953aa5ddbVirustotal results 29.03% Heodo
2020-01-28MES-2020_01_28.docdoc 1ac8d894b4e2be7cb2d7fc3dee2346677c5fdc5871be74589848518155c5ff8cVirustotal results 25.40% Heodo
2020-01-28Doc-2020_01_28-732569.docdoc 68938178a947046088472c9c687caf7843271233fbba2b888ada13c2bb5a5e5cVirustotal results 22.58% Heodo
2020-01-28REP_887.docdoc c5666d80df3d2361122568d511e336c58a58b27576a1cd78b434c425d8b2e809Virustotal results 22.58% Heodo
2020-01-28FILE_2020_01_28_550.docdoc 12934d2c01ab4c7e7639e04a3a27c545f2501b1f835fc9ab5ca4f1ba97c63e38n/a Heodo
2020-01-28Dat_W75025.docdoc 9cb664f1e4189925744979c21e305e2af11f98b2fedd6d32c4e3d5745b51ce07Virustotal results 22.95% 
2020-01-28List-2020_01_28-DRF58508.docdoc ae1c2a1ebc838f4092123a0fed626a10f1325e7796629f6d370111fd50d8154dVirustotal results 22.22% Heodo
2020-01-28mes 2020_01_28 0642.docdoc 61d0d2aa3f2b0af2db0d2e4037ac0753965f1d03e0231b17a3695337b66ddd79Virustotal results 40.32% Heodo
2020-01-28List_33015.docdoc e5f579ac649c7d63c79885d849d0631d7a0fdddabb60cc9fe78f0583a9d00396Virustotal results 41.67% Heodo
2020-01-28doc 5060032.docdoc 20cdcb97c92b8c58397ab1170823f96ce0db2c3e93d4859bd06fb23302687d30Virustotal results 41.27% Heodo
2020-01-28LIST 20200128 F179.docdoc f79992105131cff7dd4570db1648129b246323085d2843087e402a966d52503aVirustotal results 41.27% 
2020-01-28INF.docdoc 96a0ac595e820c4d5bfc99b40a351899b392f86b66e38142a1b6925a95424fa6n/a Heodo
2020-01-28ARC_PG195.docdoc a021057a2d983bc13e1f6b1516cac0041546aa046e6822c87e09c6c8ba870b1an/a Heodo
2020-01-28list-20200128-DRD4557.docdoc 15e7acb25aa2624c378b3a89937810c058af5ebec4e48fd733ccb400b783b1a9Virustotal results 36.07% Heodo
2020-01-27Inf_20200128_NG5722.docdoc 8a5d48bf4570d69fd4c9398857cb6bde479600de838113e497e4d139720ab207Virustotal results 34.43% Heodo
2020-01-27mes 2020_01_28 297.docdoc 8b7ef999bd43bd5a7ba58037188e99f78c17edb4637473f61f8be3d7270f7906n/a Heodo