URLhaus Database

You are currently viewing the URLhaus database entry for http://berkkorkmaz.com/jSHj/57487_5I8aps_zone/verified_448694_RQqoRXlFzlSwl2s/187060184138_Uznb2zdbhJ88b/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426841
URL: http://berkkorkmaz.com/jSHj/57487_5I8aps_zone/verified_448694_RQqoRXlFzlSwl2s/187060184138_Uznb2zdbhJ88b/
URL Status:Offline
Host: berkkorkmaz.com
Date added:2020-08-06 23:55:13 UTC
Last online:2020-08-10 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-06 23:56:02 UTC to merkez{at}aerotek[dot]com[dot]tr)
Takedown time:3 days, 21 hours, 10 minutes Bad (down since 2020-08-10 21:06:29 UTC)
Tags:doc emotet link epoch1 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08Mes 20200808 621.docdoc eef845456d272cc56be852f578b2a6f86b8763235174a5558477d4be45f4c088Virustotal results 40.98% Heodo
2020-08-08file_2020_08_08_MC83853.docdoc dbbfe251ebab8c3e19de23d3e0aca5661d1e893f34b9a123699fa7f2d3d5b8abVirustotal results 42.37% QuakBot
2020-08-08MES 244.docdoc 31674d9d2a53c9407819aec8731838ed678f2d3317a2a4a47680fcea72536fe0Virustotal results 40.98% Heodo
2020-08-08LIST.docdoc 6d851aa91fb4cfef84903c3d1926892f45b06e662077f5fb62434768f44e5ea0Virustotal results 41.67% Heodo
2020-08-08FILE-20200808-720.docdoc 62112657085b9dc12429d5002978a67b6a792db61dca0bfd23db9d5370717ec5Virustotal results 43.33% Heodo
2020-08-08DAT_20200808_828.docdoc a5b4fca70c16e40a7c4bad03de3c8f0448aea24ebbf989026202c94a9eeee7f8Virustotal results 40.32% Heodo
2020-08-08doc_20200808_821.docdoc cec603db22ca641e772ad1f3912383a2b3c73d6210e966c3b6ab9b4ab6695362Virustotal results 40.98% QuakBot
2020-08-08LIST_20200808_HRQ076036.docdoc 4be780211b5eeca427c252f629f2ed5b1e7062193463819a056e705ffa9df1baVirustotal results 41.94% Heodo
2020-08-08LIST-20200808-1485696.docdoc ce5d6aa5b1cfe76e48ec485669e784f6e6fa115c5c008cd89c499726b2a74652Virustotal results 40.98% Heodo
2020-08-08doc 20200808 8492643.docdoc a2c4d99f84b10b57c46b0bd1ea0fdd817fbaec3ca977b5b71f62b8ad2896f3d7Virustotal results 40.32% QuakBot
2020-08-08ARC 20200808 2931.docdoc 424cf5c4a91c06c70e70f85621afca02a6335435bc3aca17a07b860ca1d9cfb2Virustotal results 43.10% Heodo
2020-08-08inf 20200808 6197.docdoc 7749011322a1fa88e88ac29e4663fc961f0b6ca6432e1257aefaceb28252a4c3Virustotal results 40.98% QuakBot
2020-08-08Doc 2020_08_08 Z7430.docdoc 93ec25c002b55c38fb31a036675ae4137bf12ddff82518ecd596e4282c2d08d5Virustotal results 44.26% QuakBot
2020-08-08List_2020_08_08_55596.docdoc da431f9f7888ba7c9912a4ddd22f7d4bb12fcb99f9003d0e5b37a30ba731462eVirustotal results 42.62% QuakBot
2020-08-08mes_2020_08_08_316.docdoc 4749be0b925b0d49c831813a68772865cc0448b80e10fc43d06b81c93c5c9e34Virustotal results 44.26% Heodo
2020-08-08File-SR397106.docdoc 2ef95fd9c222a0b299b53659e79526a1281e9d076b75aafaedb447034237ba36Virustotal results 44.07% Heodo
2020-08-08Dat-2020_08_08-3051737.docdoc 1ec0aea3e7613086f550e01f5014835b55ac12b7d35ad781c2173dd150a0eebaVirustotal results 41.94% Heodo
2020-08-08Arc_20200808_Z423.docdoc 8d118098701f23422ec3560934134ab170767e28ea66c8a336be4dc8ec102987Virustotal results 44.26% Heodo
2020-08-08Doc_20200808.docdoc 70d75d5cd67db6987e30cdec0ba5856d4d7acaedba8e771af42a12151b44295cVirustotal results 41.94% Heodo
2020-08-08Dat 20200808 RN795322.docdoc f7d99e7dccbb7f860f4188ef450ddaa922d31492887b916a96a802c556303f5fVirustotal results 42.62% QuakBot
2020-08-08MES_2020_08_08_M25167.docdoc f1c56fe29cd7e0ea2967af2786c10bb6830fed226a6920d8905396bb8fd4e2d4Virustotal results 43.55% Heodo
2020-08-08arc 20200808 WJ97769.docdoc ec11d3cebaa5d4d05ef93c8b88ab79e34d82fede8daa5a821d119d12de060ffbVirustotal results 44.26% Heodo
2020-08-08Mes-20200808-85618.docdoc f3be0b911d44447b80b1337f332187ad596fbfe6a0739cdacdd2f9d759e12114Virustotal results 40.00% QuakBot
2020-08-07mes-20200808-P52738.docdoc 53ac99d5826bd318da8d98fc65d4b28ee61fd3f4cf67cdf387cc88e35a0fed86n/a Heodo
2020-08-07inf-2020_08_08-IT0069.docdoc 5d2b88e4fefb1593bca1de5b27276ba0d00140416c91339fc6fd44431c8ccbd9Virustotal results 40.00% QuakBot
2020-08-07doc_20200808.docdoc e8cfc1ea617361564b695bbb732436a5b497bec2660b878ca91e398406298900Virustotal results 36.67% QuakBot
2020-08-07List 0709.docdoc a69000df0de02fa33f76a39760c10e3b343cf3987577aadd182e361f49d7f5ebVirustotal results 34.43% QuakBot
2020-08-07DAT_562.docdoc acf64b8e97e3201f06314a33733d479adef77620d8c569663be2e02c3ef38e98Virustotal results 33.87% QuakBot
2020-08-07INF_20200807_3344.docdoc 4b39fa084ea8f5d975c810381f01d41410db01bb2491e4b3466dd97647f1685bn/a Heodo
2020-08-07Mes_20200807_33082.docdoc 72e7b1f1f982d507c7ffcce28b3d49cd61c6ae305f47ade10cb7da5f3210ba5aVirustotal results 33.87% Heodo
2020-08-07mes 20200807 05456.docdoc 7ba25693e2acb9afa6c453839ed62fb82efd94369f13a1549a0b57b8949cf0ccVirustotal results 33.87% QuakBot
2020-08-07rep_2020_08_07_Z96006.docdoc cb1f2bf4578f29a20e8d2870d56795a1b2ebc499d05b0b2398af82735726cb6fVirustotal results 34.43% Heodo
2020-08-07file 2020_08_07 NQ39390.docdoc 9bb646dd5265b86eba5c799d25dec0df4d675cc6e841b5487f22f53532ec4c74n/a QuakBot
2020-08-07list_2020_08_07_FRI310.docdoc 612b33cca81c88e812436d48c987273b54a73bdc04a908102beac2aaf50b5825Virustotal results 26.32% Heodo
2020-08-07File 20200807 955133.docdoc 8e2bbe860f81156cb3f65c53cc9e82ba407d702856b895049330baf81c76a673Virustotal results 25.81% Heodo
2020-08-07Doc 20200807 74002.docdoc 9f3d4befc75b49a5e090558b5cf953d5da87bfac56db564bfdde1d36d6ad7b74Virustotal results 25.81% Heodo
2020-08-07REP GBW090.docdoc e557c9d2cc0e3f2aa2355b58c657834d11c61fe22903ea0800713dc9e09632c0Virustotal results 26.23% Heodo
2020-08-07Rep_20200807_XVI113.docdoc b4bfa9abdc1af9d31045f6c98499ccfa5e332945a2b269c064bc108023673a2en/a Heodo
2020-08-07rep_20200807_7114573.docdoc afcb2dbd3d6efa8401aabfea9622280306122ecbd80ca129f6930db9b4b87dbfVirustotal results 25.86% Heodo
2020-08-07arc-20200807-II754.docdoc 5758ab9165be010ed997a923a16d1d5651b13ede3b6ec4c96faa236f8591759fVirustotal results 25.81% Heodo
2020-08-07rep 20200807.docdoc 11a879a7d8dec97462c1c9185051ef6a793dfa91fa064697aebc8e58839b888en/a Heodo
2020-08-07Rep-20200807-F89396.docdoc b584a5aebf9d1ad385649f724d7889be3f925dbb7a40ecce452d88f63462e44cn/a Heodo
2020-08-07list-JPA95826.docdoc af8ca0fa1d9fa19974e76b3491741aec5421ff068ac5b8fcb364b9fa30edb3ccn/a Heodo
2020-08-07Arc-20200807-268.docdoc d8b1512c883ce8a757dc12b9a48423d6f6854ab429004ae2435ed470a397dcf5Virustotal results 25.00% Heodo
2020-08-07list 2020_08_07 6754.docdoc b556ecc3eb51d65551b28b2e9647f7104ca35427be65f2f2cb9b6384a1b5b3c4n/a Heodo
2020-08-07Arc_20200807_444102.docdoc 24572c0cb1a22167d4116bd6452b5130cbe3926a970ab4fa6185863253b7563fVirustotal results 44.26% Heodo
2020-08-07DAT_2020_08_07_YXS202801.docdoc 2c5b7f8488ec8abc944d1a90f84293494cb7c6dea6cd23bad40fce8429f41442Virustotal results 38.71% Heodo
2020-08-07LIST VR5534.docdoc 9fda153dee6f47ac4ab198402cc17dac3bd96bd975458ef5dc23e2345abe48bdVirustotal results 43.33% Heodo
2020-08-07Doc_Z395286.docdoc 3a8b2282cec411a00cd53407d72e77d90b0a84a0bbc9eeeb0a93183ccb7a75cdVirustotal results 39.66% Heodo
2020-08-07Inf P052.docdoc fe032b45e17799af19f0dff52340131849e761ed8072baa910c48854206f12b6Virustotal results 36.67% Heodo
2020-08-07REP 20200807 4706.docdoc 2a7f0551cd0fa000ed5992db4346987430e32084240b9eb53ad0369763734b71Virustotal results 33.87% Heodo
2020-08-07Dat_2020_08_07_BHA755801.docdoc 50142b56616f33de96a00f3619a900237753bb4552fdd62f220ae93fb25cbf3cVirustotal results 35.48% Heodo
2020-08-07list_20200807_304023.docdoc c284ffb9f5bdd60bbd1a54a92f2105228488ba50d6b767cd4a2157782284b1ecVirustotal results 33.87% Heodo
2020-08-07DAT 20200807 ZF8784.docdoc 4db4602068fdb37b51866a80dab39455e49b2c3a46b1e778f4afb54385027935Virustotal results 33.87% Heodo
2020-08-07Inf_2020_08_07.docdoc 8dee1c489137e967d7674246af7a20f33986189be2bc33d2d1c2a766391d65d1Virustotal results 32.26% Heodo
2020-08-07FILE_9147722.docdoc 017a10a1811401d7e7500e1b999024f7188b0636a16751e309fe8dc474232b95Virustotal results 30.00% Heodo
2020-08-07LIST_UT6784.docdoc 41ef14a19213118eb0e697d1b79f445cf4843cde57bd4b92ea7d33ad44d26f43Virustotal results 27.42% Heodo
2020-08-07File-TPI620.docdoc 6c822bf85153ffff4d424e12352a19e60d31782008681d7287a00bf4750feb70Virustotal results 29.03% Heodo
2020-08-07Inf 2020_08_07 041091.docdoc 5bb39eafa5028062850d6792e1c03eb121c1102ab0454e68ab2ae662305c2f3dVirustotal results 31.03% Heodo
2020-08-07LIST_CWR4309.docdoc f68b4830444215e42c2235d3a089e701433125057f88922a9e957fa59cd9fb58n/a Heodo
2020-08-07mes.docdoc cdad26800b0cbf8b3c591cc545378d50c93a28c735fada99d6bbe4228f2ed6b0Virustotal results 26.23% Heodo
2020-08-07Doc_2020_08_07_AGY046.docdoc 2a005cc6ecad083fbacad57dd64f003039138ab3058b1914a4857ea7390df298Virustotal results 29.03% Heodo
2020-08-07LIST_2020_08_07_E633.docdoc 2d9e8d19691ccc198cf997196c54e831404e2577b1bd3c17ae29b1c78b0f95a8Virustotal results 29.51% Heodo
2020-08-07ARC_2020_08_07.docdoc cb965595bedf28e722085f2c70f7ade49c8c594ecc499ce0c78bd06d6365cab8Virustotal results 26.23% Heodo
2020-08-07inf_2020_08_07_T26141.docdoc 90f8bbf6dee1ad7d38d610ea379dd8fd80444592cadac1f1497cad9b6d4e5caaVirustotal results 27.87% Heodo
2020-08-07List-0447290.docdoc 36cf71324f57ceb43b443ab2e5d0670e4adf672165537042e46c23de797186d2Virustotal results 27.87% Heodo
2020-08-06MES 928909.docdoc 3a17dd818992725fb9bf1c2e0d4d18141f5b9fe15a184e7ebac32b935fe7e60fVirustotal results 26.23% Heodo
2020-08-06Mes 20200807 793192.docdoc bc8d27d29c9725d37965eb6e09b9783525a30a9d0e5a936029edbe381df0115bVirustotal results 27.87% Heodo