URLhaus Database

You are currently viewing the URLhaus database entry for http://berkkorkmaz.com/jSHj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422463
URL: http://berkkorkmaz.com/jSHj/
URL Status:Offline
Host: berkkorkmaz.com
Date added:2020-07-30 23:46:04 UTC
Last online:2020-08-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 23:48:02 UTC to merkez{at}aerotek[dot]com[dot]tr)
Takedown time:10 days, 21 hours, 18 minutes Bad (down since 2020-08-10 21:06:48 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01InvoiceA7349748374.docdoc 56916942bc59a1ae0cc030beaf907b54631390e0a5fa7d75bce1f120df88d843Virustotal results 47.54%Heodo
2020-08-01INVOICE XJRN756 99947252.docdoc ec39e7db8df5d0c11991de7b6482accdc4ceb42d31613c528ed2529bcd6c7312Virustotal results 47.54% Heodo
2020-08-01invoice_VGY67_356166.docdoc 03f865c1fac57f3139c7e31396f64b101ebcffaa628670618d90b51e8330cfe6Virustotal results 46.67% Heodo
2020-08-01Invoice_HY9844_916588894.docdoc 36a5f87339ba5032f9043c7785d613f0731fc93ae382bb6b942fc80e8bc48273n/a Heodo
2020-08-01INVOICE5456993.docdoc d2ad4662ecec9de8e762286aed287dd57ae7a9abe05aaf585b00df8416023a96Virustotal results 46.67% Heodo
2020-08-01INVOICE I971 310288.docdoc 5501f723697b0f6c5eb89e873828133dc1b9f465321a797930c9a071d291fd18Virustotal results 46.67% Heodo
2020-08-01Invoice 3593 229389829.docdoc 56764b6f66de3b045860f5398b4fb8f24c11ca8d959231a6b0f63d82626f5a55Virustotal results 46.77% Heodo
2020-08-01INVOICE_GYYJ6229_404681930.docdoc 7525e9c3dc222fb7e0bc897856d98ec233aabda4ecff64336788e29ad6e2dec9Virustotal results 47.54% Heodo
2020-08-01InvDJ8673834.docdoc 0457060f736d8abc01a2718e6b003eaa9b8a2c798ddc3f0b589f63f8769fafdbVirustotal results 48.28% Heodo
2020-08-01Invoice Y1 326007688.docdoc 8a3527868ae086f48fd41f40545528717f6c347ef9079185dfd12bdd868c1ce5Virustotal results 46.67% Heodo
2020-08-01invoice-649-064319.docdoc bb8c48b9c6a222384a580b5858d80961c33a1e4e5caa38e5674affb524dd1f3fVirustotal results 48.33% Heodo
2020-07-31INVOICE-VHE93-143068.docdoc 29a33547180f8a2c21bceb0424f9724b50dbdf57104000d4562a96c1c8a4f241Virustotal results 50.00% Heodo
2020-07-31Invoice-BTTL9108-691516951.docdoc 2ea8bed0ec293c0db908aa3bf66f87d74d9e1875f8ed7c5b9d354cc06d6eab5cn/a Heodo
2020-07-31INVOICE-UN9440-672133610.docdoc a61824a20a04620fcb44adaadc6a83dc12f5eb52abd4b00f4d1bb5539d27db10Virustotal results 47.54% Heodo
2020-07-31Inv-XKZ557-27027030.docdoc 3aa1391bfbe69feedf829ea95829c1273d40e363aef09bcec4c35560a4482146Virustotal results 46.77% Heodo
2020-07-31Invoice-F1334-82757149.docdoc 7ad485f73ed801fe057ee89153970c59e3dd7331d317808f0f04c7a138d6aebcn/a Heodo
2020-07-31invoice-YX4726-64513764.docdoc 6b6e072d0d18e1b1c941206ff11fb1a9126c5bc5472e7466c68ff933bfd016d9Virustotal results 47.54%Heodo
2020-07-31Inv-ERK884-1632482.docdoc c13e46d1796c767f42fcb0b83df4e4e8775ff207b91c3cc649a3fe3f4690a89fVirustotal results 49.15%Heodo
2020-07-31InvM52653175.docdoc be9580ee19139809910c67fa4e0f35bf76001f0fe80e6923b8ac0a4c6365555bVirustotal results 46.77% Heodo
2020-07-31Invoice-YUPW3-5020167.docdoc 604d8d4b25d82a9fa60525c21b4f7ff9f0edf0d00aea808ceef6bef8e9e4f4c5Virustotal results 49.18%Heodo
2020-07-31INVOICE_R8282_44621443.docdoc 9420fbed8bbf98010e41a960a8bf2314eadd6423e12163e88553e78439867a83Virustotal results 45.90% Heodo
2020-07-31invoice_D3377_53362382.docdoc 56e8a51e917d57655dd5612da8b9618280c29273e601c8628c787029996d1823Virustotal results 48.33% Heodo
2020-07-31invoice-CUZT45-68183604.docdoc b2671d67c068a833209094947cc1f15c6169a854e02006f116cd342528850f15Virustotal results 47.54% Heodo
2020-07-31INVOICE GO65 8400168.docdoc 527f944dd4527a40856fb21937f1dae339f1e6a6b1b1fb1f3aaea15220d261e1Virustotal results 47.54% Heodo
2020-07-31invoiceP0383420862102.docdoc 7d45b681bf88eb9dbaa17bc604d6aa7df3cfc0c3bfaed371a08d5c1805df192cVirustotal results 49.18% Heodo
2020-07-31invoice TWH8 6092987.docdoc 541a2147a3dedf8a670a6f6db27757358e9762a15c2b2ab8f8aa7b384158cb76Virustotal results 47.54% Heodo
2020-07-31Invoice 3894 57546182.docdoc ec21525a8852265e8892193f896c9002e6f4a525c42e980120cdfce6e8ab3d9fVirustotal results 49.15%Heodo
2020-07-31Invoice 3894 57546182.docdoc ec21525a8852265e8892193f896c9002e6f4a525c42e980120cdfce6e8ab3d9fVirustotal results 49.15%Heodo
2020-07-31Inv_XNID7361_260326.docdoc 286e883e3fd7042dd61a284aafd1bb8cf55e274a5a5cae78da6f6c2e8084a24bVirustotal results 45.76% Heodo
2020-07-31Inv-KXWM125-80621057.docdoc 1610113eacc5e61b5d26ffd007e56edd58fc824c44c0c235f6f8f434acc125deVirustotal results 47.54% Heodo
2020-07-31Invoice CI92 8078366.docdoc 8d4a6bbe8331ba2970792f5e37e044765e5a0c7df74b1e26d8e0af16b6390bd9n/a Heodo
2020-07-31INVOICE GZL2521 322486.docdoc 74ea191fd9dd8739f62ffc1cb8d3ba2aad0b198006c5e8aab604e362798cdd45Virustotal results 45.00% Heodo
2020-07-31Inv-EW3-956617.docdoc c1750c95a8c4d6fa3ace82fdd29e4da91bc8ae1612124941dec4b06310e9a00dVirustotal results 45.76% Heodo
2020-07-31INVOICE-GN0739-0317014.docdoc 1e78d834b4871e8021b0bdbff55c32e9a28bbb0f6901965f9c2bfe6c2ee9eae7Virustotal results 45.76% Heodo
2020-07-31invoice-HVQB8-80809590.docdoc 26a1feed3df8164358b5997371f3ccad341b539859c7ed75914f15c59df315ddVirustotal results 44.07% Heodo
2020-07-31INVOICE AT2780 913601134.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31INVOICE-DYEV917{:REGEX:.docdoc c7ed06b6f4284ba3fd857f03875187654aad78683efa88d3ed984fe057d484abVirustotal results 50.85% Heodo
2020-07-31Invoice DHNO247{:REGEX:.docdoc c66fa17e4f5d76079707aa28d126feaef92ac1245b1ecb420e7e632e8eeb76a2Virustotal results 50.00% Heodo
2020-07-31INVOICE6302{:REGEX:.docdoc e3c6519f7b0b581bc58ccec2a76f8bce09e09658d05624ef33b7c5cce0197b6bVirustotal results 50.00% Heodo
2020-07-31invoice-5109-5443377.docdoc f554d67a1bac2a6fc64ec282706c416190d555857ddf80e8b243366b8b738987Virustotal results 51.67% Heodo
2020-07-31INVOICE-C425 476750.docdoc 9d87ada7dcb70d012d66826ec3f4f26a2f853edce07b15282c119048283a80edVirustotal results 50.00% Heodo
2020-07-31Invoice 58-02998732.docdoc cb27bed9b173d425693fe6c19d0d7502d62645a8fff074790841a362952e9936Virustotal results 50.82% Heodo
2020-07-31Invoice BWP995{:REGEX:.docdoc 1e253d59d5ef3aaf08431b406cd5c024476603459b847f6b40dd0f86827492c1n/a Heodo
2020-07-31invoice-9-477589.docdoc c8e498b47aef6cfa8fe5259b40faf397127d496992e126c2f4f6026f7945813bVirustotal results 50.00% Heodo
2020-07-31invoice LSLR0 12142528.docdoc cee085d16cb1dec28ff7ef5bd5399111ba8a5e26623b17902866e886144c228fVirustotal results 50.85% Heodo
2020-07-31INVOICEYQ79{:REGEX:.docdoc ea4ec66d739ec6c93a0e5890743a01a5283b804889147308ba45d35ee1f2247dn/a Heodo
2020-07-31Invoice-U4_283970.docdoc 2ab3a5f443403e9ed1928d27e4e551ab95a6532d540b98d5103f0ed8a45a75cbVirustotal results 50.00% Heodo
2020-07-31Inv-4 3564200.docdoc a766fc0e20a4f8cbf281aef6bb29f7a20a937044d7fd4e008c1097cf266c24beVirustotal results 50.85% Heodo
2020-07-30Invoice-91_89541863.docdoc e42656550ed8d746cb8b453d28e1ca374da03e76bdf6b65633f3b1bedd1e051cn/a Heodo