URLhaus Database

You are currently viewing the URLhaus database entry for http://selendemir.com/zwro/352362-be3oAUKvg1e8owI-dxoDd-jm5CprT/security-4425926-L147hz4rIHo4mQ/197716-WJxrSqNOj5jaapeL/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:417659
URL: http://selendemir.com/zwro/352362-be3oAUKvg1e8owI-dxoDd-jm5CprT/security-4425926-L147hz4rIHo4mQ/197716-WJxrSqNOj5jaapeL/
URL Status:Offline
Host: selendemir.com
Date added:2020-07-22 04:05:04 UTC
Last online:2020-08-14 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-22 04:06:03 UTC to abuse{at}contabo[dot]de)
Takedown time:23 days, 3 hours, 49 minutes Bad (down since 2020-08-14 07:55:33 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-22REP_2020_07_22_GZC93229.docmdoc 2a74172f87c79c4c2b810545defd880484c568c31ff4dd30f3ec1be571112ffeVirustotal results 26.23% 
2020-07-22inf LN1735.docdoc bda45a277d1d57050ac2f680f22b728a35eb2aa5d67471ea2b55817d66a982c8Virustotal results 26.67% 
2020-07-22arc 2020_07_22 XZ82281.rtfdoc 3df05f387f43858fdc3530301f6dc27b9ac2a89560059a40ee635b6a1f25497fVirustotal results 26.67% 
2020-07-22list 20200722 SMM6146.docdoc b35d6f30710cd9faba8bae89a03e685b49544da9744821e0123e6585740a0e3cVirustotal results 26.67% Heodo
2020-07-22FILE_2020_07_22.docdoc d3d731e1c5ed00a3123112f5f1b4d029a74b742ddf0b5a2639209b85f2930b18Virustotal results 26.67%Heodo
2020-07-22MES-2020_07_22-297.rtfdoc bf08d9f7924956f144f0211f6ea48722fea5cbcd8dff6c661dddc5a221e13742Virustotal results 26.67% 
2020-07-22doc_20200722.docdoc 46ddfb783ed7cee9d4ec3196ec9297e861503dbfdf905203eca8be9bcbd448e3Virustotal results 25.00%Heodo
2020-07-22dat-SRH650389.rtfdoc 3550a00d6cf8efb047a97d984cc26719d87014434ff444e3b70427e1b1670342n/a Heodo
2020-07-22Dat_20200722_906043.docmdoc 737f7e0557c9203033464070e06e23e7675c8325abd0083d1ebbdaca3f7eac2eVirustotal results 37.29% 
2020-07-22rep_3624454.docmdoc 8aec85cd8e1f0f312d2a3442272e4634ea845690457c6a516b51378c868a1c34Virustotal results 34.43% Heodo
2020-07-22Rep-2020_07_22-27528.docdoc eed180c709224d892fa8a82e0c51bf623d7057a65ca483d45e3d005984dc6588Virustotal results 32.79%Heodo
2020-07-22File 2319.rtfdoc 7eb51f8c4719f0171a98650b63385c15908628fc4ef7838c410fc53c46a0b8a6Virustotal results 33.33% Heodo
2020-07-22Inf_2020_07_22_BW05240.docmdoc 3e24c4373b1e2ba1e3d16925cd0d4a1752452402ae4aaa8ad8ce498bbff5335cVirustotal results 26.23% Heodo
2020-07-22file 2020_07_22.docdoc 365f2b2480d704ba0fa82cf5c25d92895a3518ed02ec36ff5f150cfe091b3574Virustotal results 29.31% Heodo
2020-07-22LIST_20200722_BI49933.docdoc 28e77291fea150f98e5ed9a57a4d4074ff204abc6e20218a7e67bb0e4b6e23f4Virustotal results 27.87% 
2020-07-22List E4187.docmdoc 09b748e69f3a980dc1064d5ead28bee9059c55a38855c781a1d1752ecca88c43Virustotal results 28.33% Heodo