URLhaus Database

You are currently viewing the URLhaus database entry for http://rahatsozluk.com/6s0r3sk/wYgBh/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:299408
URL: http://rahatsozluk.com/6s0r3sk/wYgBh/
URL Status:Offline
Host: rahatsozluk.com
Date added:2020-01-28 02:55:11 UTC
Last online:2020-01-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-28 02:56:04 UTC to abuse{at}megatrhost[dot]com)
Takedown time:2 days, 12 hours, 38 minutes Poor (down since 2020-01-30 15:34:43 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-29INVOICE 0_919492.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 22.58% Heodo
2020-01-29invoice-QJY897_120237133.docdoc b82cc27d4efc099b3f0ddfa40b78099e3185deb087ab2d9528c5ef61c063950aVirustotal results 33.33% Heodo
2020-01-29INVOICE-UETU02_6245142.docdoc 8f114fa9732298d525aa216d90905f24142f129d79e62500f139a3c09db00fd2Virustotal results 29.03% Heodo
2020-01-29Inv-RNP868_7601347.docdoc 70b79f7a9104113770865d6b9495150c39a6d3f9a5f98750ea69871f38ac5566Virustotal results 29.51% Heodo
2020-01-29invoice-662_748035.docdoc f05b69f2090c678691d6bfab44a03a47063763690e1cf3d704561f60de935219Virustotal results 28.57% Heodo
2020-01-29Inv-B72_93840984.docdoc 7522a47f398818f54f95582e8d122a7bbd81f69c9807cc61fa12d0fc15a2e39bVirustotal results 27.42% Heodo
2020-01-29Invoice-68_4667085.docdoc 603a04c67b941a3ff9345c94e890896e5570dd544e8ca3998f5197f45ab28f00Virustotal results 26.56% 
2020-01-29Inv-TLRI316_40297209.docdoc 8818a20402dc42c2d1240599c78d231d98ca26c9ea369787386b2a10d8b5a109Virustotal results 26.98% Heodo
2020-01-29Invoice-QQH031_397055970.docdoc 19f29957bde797c4505244aec4c78ca3ff7e264967215abd6444d9f7c31da7edVirustotal results 25.40% Heodo
2020-01-29invoice-2230_406510.docdoc b14d70827d5d668aeb31e94be512fea9fb38ead8ec12cdf7617616801c76b6e9Virustotal results 32.26% Heodo
2020-01-29Inv-VYA14_789842993.docdoc 7cbcad4d6e9ad8438e5febd3830bff9aef4729b98d23935ad7f9e6d290272732Virustotal results 32.79% Heodo
2020-01-29INVOICE FH0400_325999.docdoc 7cf8f24d7e8b1e2f63bfa7a18cd420a03fff44126e80aed8cb90fba3c4e986acVirustotal results 52.46% Heodo
2020-01-29invoice-FV8_39781270.docdoc 3a7a8518b41dd6c05289a08974c95a0038be4e5d1b0588edfd0589fcf22b0c8fVirustotal results 49.18% Heodo
2020-01-29Invoice-501_071140408.docdoc a286e3be694b9525530ec6a65b71a8a91e04042c3471e8a9e440f503fe8ce995Virustotal results 46.77% Heodo
2020-01-29Inv_SBG6_51117526.docdoc 722a60dfd59a595daa487f2fb759ef6f9ccaabcdf20605d5ae9450cba4a9b9b2Virustotal results 46.03% Heodo
2020-01-29INVOICE-H970_547835.docdoc f6879431b901df789082452c1c4ffa29e857d247886e421df6dda5fb3d81ca5eVirustotal results 46.77% Heodo
2020-01-29Inv-KZ42_5012642.docdoc ea3a0a223474592635d1fb7a0731dd28a96381ad2562e3e064f70e2d4830c39dVirustotal results 49.18% Heodo
2020-01-29INVOICE-N14_3619646.docdoc 01dc8f2a419b640e733d067267aee6135ea117fa9704348547a0a2a0cc32926eVirustotal results 46.88% Heodo
2020-01-29INVOICE-CJ0_1968701.docdoc c25db0a6d33ba3de2ea0ea992b98117d92ef8cc0a1dc6d9ff79788db6ce7e06eVirustotal results 47.54% Heodo
2020-01-29INVOICE PUQ02_025817.docdoc 0d1de45954adee600bf2a41e5b1de25ba4ead4b3938d1c987f6bdf8e48fb9a42Virustotal results 43.55% Heodo
2020-01-28Inv-TF1_02727286.docdoc f9a330484e52de8ab57a920eb93d6308dd150ba0001e7ba7cfb2a50edfec5ca0Virustotal results 43.55% 
2020-01-28INVOICE 1807_62450041.docdoc cbb70b343a501720d8750b792ce9ff7bc424725205f02f2f7a68ff00f8064229Virustotal results 43.55% Heodo
2020-01-28invoice EVTH1102_588509.docdoc b7109568a2beba7e63236e9fae5d014d43ea3164de3e4149790c89356b10766aVirustotal results 39.68% 
2020-01-28invoice_PHEP490_77966661.docdoc 85e978955f2d5b46e50d3a259f837643be8e5b3e0c643465881342f1cc7f3d31Virustotal results 35.48% Heodo
2020-01-28Inv-FK07_481599.docdoc e6551fa9814756f1d99f86fe2713d695e930e5930e397affed4aa07d4ea63ba6Virustotal results 29.69% 
2020-01-28invoice QSF3_905220.docdoc b351412551b1d480fe50603de72c1d23a0afa22991461d2b812edbf5ad7d6021Virustotal results 25.81% Heodo
2020-01-28invoice_5865_695206.docdoc ff71f06910cdebceb665fef3861262fbabd9f92ebd7285926a1b3d4ed3a7c166Virustotal results 26.67% Heodo
2020-01-28invoice_E6076_143864.docdoc c72d3a18baf0023ac80353b06452c4fd43e003247f97c3aa98cee47b2f4bc27dVirustotal results 25.81% Heodo
2020-01-28INVOICE-GJXN30_9446749.docdoc 160fe2d4287a96770020461a685816eb0d9ba8b3a3275b86f708784b778f380eVirustotal results 22.58% 
2020-01-28invoice V95_32211239.docdoc a6b9f25b3f632a071e548d1e092d8557eedd074094e5e1a2dd684a724fb07fe6Virustotal results 26.98% Heodo
2020-01-28Invoice-GQLL84_5548075.docdoc 9b0e9e86d03962166bfd95e228298f990b3eba16ea40c18077b1c0921bac5d3dVirustotal results 22.22% Heodo
2020-01-28Inv-H5698_969683.docdoc fcdf9154d769d5e1f3935355b39b57010d978fd2dc9ad24a1df12131f7d34155Virustotal results 26.56% Heodo
2020-01-28invoice-HAQN55_4842186.docdoc 42cf3dc2c05800ee63913c2437b824f17dc2999d761edc2c318a7b94fd9ac4a4Virustotal results 22.22% Heodo
2020-01-28Invoice YSB7283_4951566.docdoc 0f30073111c54d8f89bd3d4c031b77db7d32447f0bee27914ac94ffedc2baef1Virustotal results 23.81% Heodo
2020-01-28Inv-8_105240.docdoc 37f7008209b0cf19267afa8ccdab629b76f4bfa992d7f77ce2c098e5e473c8dbVirustotal results 40.32% Heodo