URLhaus Database

You are currently viewing the URLhaus database entry for http://dmgkagit.com.tr/Jul2018/En_us/Invoice/Invoices which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:36172
URL: http://dmgkagit.com.tr/Jul2018/En_us/Invoice/Invoices
URL Status:Offline
Host: dmgkagit.com.tr
Date added:2018-07-26 05:27:07 UTC
Last online:2018-09-08 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2018-07-26 05:36:28 UTC to abuse{at}cizgi[dot]net[dot]tr)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-07-27(INV)SZE29112795279.docdoc 6dce7c91395b80f9a57accf9207dcad66acad879fd7c87b24e556e230bef0eebVirustotal results 26.67% Heodo
2018-07-27(INV)YS602750497.docdoc 5b82e7f9aa125894bad57e35170732a41f6823f507f3c1a63a0adb1c0da2d6c2n/a Heodo
2018-07-27WUK413425455778.docdoc 8659f2f01f2f4addb9bcbd6f1feb58f7d0bcc511ba0188db05bba2173640d5can/a Heodo
2018-07-27TN062004580237543.docdoc 832ed863dddad68d532819ab6f7192dfc006cc10e3cad5de419ac3c955229f3cn/a Heodo
2018-07-27(INV)EWO0413403473895.docdoc 4d2e3803071a98cabe6223166203126f61056be0261f5891233b34d20b3b7fd9n/a Heodo
2018-07-27(INV)CV727904810.docdoc a1412a07eec4afb055a7fe689e86ffb62e251c2cfa12a2f0edc86262f7a7c146n/a Heodo
2018-07-27MBN46565745068.docdoc cde212a61556b35461627f054f56be277c3a5203bddbcbe526742b4b849a5bb0Virustotal results 42.11% Heodo
2018-07-27RKO2532654649.docdoc 0570dd89f49c794f3901a086dc9131a93834d7dbc7ef068af5c299874f41f809n/a Heodo
2018-07-27(INV)SMX956159294627.docdoc bbd808b9ae468f0fd7611ed28d9c32ff61116a64095ab2da02877b44b59966e3Virustotal results 35.85% Heodo
2018-07-27(INV)AP3706543320.docdoc 6e99fd801a91014662c3606af72e677b21ef291a487861c576c1d19955699da7n/a Heodo
2018-07-27(INV)NNL48081937786615.docdoc 91ec3d555e8cd980bbc636147b9bacf94ce6e2ed736cf879e2d7d30693f182can/a Heodo
2018-07-27IW6420447905.docdoc 4fd7ab625f4b444da2e5e60b7adc03a0de14c42d2357f518b07d9924eca1a50dVirustotal results 36.67% Heodo
2018-07-27(INV)KY237730342224.docdoc a04e6195e8b52db47e7e88401a4daa431ccdb00c959c3ecc2b26743ba47e97c6Virustotal results 38.60% Heodo
2018-07-26ZK6226782809.docdoc da949e88f8e20caff806d1c8201777571991a2701bdc2f3e44815d0e18ab948cVirustotal results 36.67% Heodo
2018-07-26GL54146446304.docdoc a8e856a69c9eb0074a418c67d575b91b49caea488574529a40e3b129cefde689Virustotal results 40.00% Heodo
2018-07-26(INV)IWS172658111885.docdoc 243a87a44e767e8d5b788c29bb0dbec9986956b40c407074f670bcc9b206d730Virustotal results 40.00% Heodo
2018-07-26(INV)MKW400075692642.docdoc ffc7944f16c06efdd23a4fb946eac1dd2b1a91f2d27b7cf24396a78713b17c5aVirustotal results 38.33% Heodo
2018-07-26(INV)AZ160566400905.docdoc 400d6b89b8026f39de9c80b89aae66e49afebf153c8b5b9d480307ada0f4c428n/a Heodo
2018-07-26(INV)XAU326635277103230.docdoc 7ca6572429e9aeeedaeb810c5752f1ee4f300435eedb55efc6128a3c5cb40028n/a Heodo
2018-07-26(INV)JLI660554131977214.docdoc a5fefbfa27d4704a6e5e9ee658587a63e1889d2baa74bdf7c6949a4027e2bf51Virustotal results 30.00% Heodo
2018-07-26AO9617560194340.docdoc 93bf51d8460455e19a53220feb590ad784d2282f009bc7ad393d76e3be3540e8Virustotal results 30.00% Heodo
2018-07-26RI6186904535.docdoc eb6e7d17c007d64f9fb1ed96d50967a0ab3fceb1c53f39975aec92bd8d499632Virustotal results 30.00% Heodo
2018-07-26MZ69275767727.docdoc cae201c0186ce7a7772512776f9cc768861fd18c7ac96d1c65cbe72304e86b57Virustotal results 30.51% Heodo
2018-07-26GPU645582478178.docdoc 65bb431e81b2d26c9ee42d6df63ae753c5535bdfa93942d3997f096c09457199Virustotal results 29.31% Heodo
2018-07-26PLS0259170207425.docdoc 5728aa05ef3551aa19530c31280bb3ea3c1e3a5002a0d7ff73c0defedf6d5f13n/a Heodo
2018-07-26(INV)EU109446249.docdoc 86be3911417b727fbcc98ce89b55dddefee56288a6b7b1748066a8ea0ffd75e1Virustotal results 30.00% Heodo
2018-07-26PU7222399098807.docdoc 056a4134212e57a50932041c6294b4b2ede287d700a2a0512136eacc155e64b5Virustotal results 34.48% Heodo