URLhaus Database

You are currently viewing the URLhaus database entry for https://volparts.com.tr/css/paclm/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415296
URL: https://volparts.com.tr/css/paclm/
URL Status:Offline
Host: volparts.com.tr
Date added:2020-07-20 15:20:35 UTC
Last online:2020-07-21 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-20 15:22:02 UTC to abuse{at}ihs[dot]com[dot]tr)
Takedown time:8 hours, 48 minutes Good (down since 2020-07-21 00:10:25 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-20BAL_68255889.docdoc 6f07729a0d38233363651ce3760f506ded756ffb5010218df70d03bba767e7d5Virustotal results 27.87%Heodo
2020-07-2074217889.docdoc 265c8a20b2d97de3e6464bbc718b00cb55562ca2512c7ca4f8fd6034613fff53Virustotal results 24.19% 
2020-07-20INV_89FAUPO.docdoc 021aa9ae780b058779de8a93eb224c78e1d856ebd0bf6a3de8810e1b20e88f7fVirustotal results 26.23% Heodo
2020-07-20BAL_D7NTQRCLVZZZ.docdoc 9ed5c3020adcc781d330dd21b20134e4ae6fec3d1eb087be0d8f89e1c7af99cbVirustotal results 27.87% Heodo
2020-07-20DOC_570009304461996.docdoc 69167697c3c077b3ca6449ae55750d1712c20bc33196537fdbbe05e463aab195Virustotal results 27.42% 
2020-07-20REP_5G7NCVGAYDM.docdoc 2af9360b0c34eed7913f05bb4d71151b7e9439e871bb7d1efbcce6b30dd59635n/a Heodo
2020-07-201189242785445.docdoc 9ea223e9251e17c155c00e320f9f1008c6872573da7a16d524213225ebec9addVirustotal results 25.81% Heodo
2020-07-20G_5S8WXMGPR7JSY.docdoc ad9dca4af2d2d6f62c8b873811f39187935fc52ac33c53abf4fc5a0d618dd659Virustotal results 26.67% Heodo
2020-07-20INV_345499174814730768524.docdoc 16a986a19d026da35781703a1baa7901b7c796b6a56c4cb47d21b741c9b47291Virustotal results 25.81% Heodo
2020-07-2075729973.docdoc 1a328aa48b0ba77e6965043cc7dc2d97edd5ac325b193b1f102a50a492444948Virustotal results 26.23% 
2020-07-20PO_07202020EX.docdoc 6184126e3453b754392ed6f6123957890870d807b6f67d16cac4116de881e3bcn/a Heodo
2020-07-2067369719.docdoc 0fee9dff045cb53ab19cad51113a8af4f6b38c19b46c50150f606626fd1a42c9Virustotal results 25.81% Heodo
2020-07-20DOC_335306819968.docdoc fdc3a5d1febd58ec001ec2e119bc2756b8518c289478484bae758ac45c964e59Virustotal results 24.19% 
2020-07-20DOC_VWQ_070120_TMZ_072020.docdoc 15fe975d4b69b43d4f2a72a301e2eb1beb12fb709d0cf36259e10950b30d0fa6Virustotal results 25.00% 
2020-07-20DYN_GG2105240279LH.docdoc 932c549927ea5c0ce827253fcb26978c1361cfbee3495d9dde5130ba190dd3b5Virustotal results 24.19% 
2020-07-20N_VT0107554491YC.docdoc 9916b4a492b19650f59d73747d3b28cd2e996ea9e6ea86675534a17b52c01bb9n/a 
2020-07-20W_IUZ_070120_JQT_072020.docdoc 80b106f0a5ee76807f30854146ca7ec399ba3a278a7d7b2dabfb22df35ffaafdVirustotal results 24.59% Heodo
2020-07-20FILE_DJY_070120_GVP_072020.docdoc d6c1502d578381d10d02294a46e4323750b275cfc12809251a3c4cf9ab3a5d3aVirustotal results 25.00% Heodo