URLhaus Database

You are currently viewing the URLhaus database entry for http://eyupoglumedya.com/blog/parts_service/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432247
URL: http://eyupoglumedya.com/blog/parts_service/
URL Status:Offline
Host: eyupoglumedya.com
Date added:2020-08-13 18:11:49 UTC
Last online:2020-08-27 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 18:12:02 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:13 days, 17 hours, 21 minutes Bad (down since 2020-08-27 11:33:04 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14BAL_PO_08142020EX.docdoc 2958931d81ad10eb95bb3fca9457a800e9b4a9459d2727f30cb5d49d7bed0527Virustotal results 24.59%Heodo
2020-08-14REP_FCEFIBI9TSPP2W.docdoc 38c8a47d1d9798b4da56d1a354bb62681c1e7e32c0e8665ef84cf88e8b4eae21Virustotal results 23.33%Heodo
2020-08-14REP_PO_08142020EX.docdoc 73cad6ba26fb0aa184d10e24cfdbed4498c47ef40ef010ed07ae719fc7b6b2d4Virustotal results 23.73%Heodo
2020-08-1416546333.docdoc 79cd7f136cc0a61a98a896ade45d1aa6746869461a7524b0abcdb743ff8a454eVirustotal results 23.33%Heodo
2020-08-14J_XYI_080120_RYB_081420.docdoc 3949030f76ff6b3522aa805a451313ab179bd113f785e3a2ec1fc1d474619708Virustotal results 24.59%Heodo
2020-08-14PO_08142020EX.docdoc ef7ca96ffe6ec90acb92e8c9643a98c30154a996cbaf90a2d7f3a4a2dd6e1108Virustotal results 23.33%Heodo
2020-08-14FILE_198881399738780418099.docdoc 2ba31bcf0605c3fb50f7855062c192023371778e906ddbc8f2f9c8812d07a2a0Virustotal results 23.33%Heodo
2020-08-1468088777.docdoc faa4c872e4e08e1146cc849b5a9f4302d22a6a7b88f28c20d267b44d7d6b0c5cVirustotal results 23.33%Heodo
2020-08-14DOC_86736513.docdoc 52dfa2ae84a796728c42db4f98cf77d399ec18ebd3e7a3876add7ca5443107b0Virustotal results 23.33%Heodo
2020-08-14BAL_PO_08142020EX.docdoc 1b566e47879307c36ab6864f6877fbdf8128ab937cd837fe3050b24c7958c673Virustotal results 22.95%Heodo
2020-08-146542490124035238430288822.docdoc ce9ff1845b08d7610cd9a181ced3676fc04452e4d019ef14a48d59634b45cff1Virustotal results 23.73%Heodo
2020-08-14REP_ZK6980934876WT.docdoc 43c592e78307702281f1105969aad4a99aed3a1cd8b87965c1724b3e0e2f08den/aHeodo
2020-08-14Z_PS4KZ8EFRC0DPV.docdoc c6b7c7bfc887108475b13843c34397ce838e4338a8ced72d8b58d478631d3ff3n/aHeodo
2020-08-14BAL_PO_08142020EX.docdoc 4c07030c48ddd9cdd9c6d7e1de08af7b2498d2ca7e8edc75ea8ca09b53238cd0Virustotal results 23.33%Heodo
2020-08-14I_ZSC_080120_GLD_081420.docdoc 184f481ac2e0638a5f29787df5ef317f15c5b1509de96eaef3f949c86c2f8b78Virustotal results 23.73%Heodo
2020-08-14DOC_NMM_080120_TLF_081420.docdoc 1cb2882cd1b3a5d7abcbe3d76caae33bb609753651c611bb27d19f740f26fc8bVirustotal results 36.67%Heodo
2020-08-1448769967.docdoc 0f80316b76262700a25c47fc972ed9f77b1d2f997f7d8f4f2dc7c00a2c59eca5Virustotal results 37.29%Heodo
2020-08-14UXOC_37591299293.docdoc 8217ef5454225881de094f60ccb5714c9d729406c576bcf59c4e61904022b289Virustotal results 35.00%Heodo
2020-08-14J_9I2G4BR3CLMSC7F1.docdoc fa4a4908d530908c1e687ff784931d3e57af14fe24494b625e45f1f0387a8528Virustotal results 35.59%Heodo
2020-08-14REP_95200868.docdoc 8c1068585407f5f88829c4f57a246305ddd51450ef74893d81cc738604e9cb3eVirustotal results 36.07%Heodo
2020-08-14KR5691300677VC.docdoc fb7a412b04631d97dd0997790d131551a8a9538f20413aa9d4d76664ad2d4d15Virustotal results 37.70%Heodo
2020-08-14FILE_63351543.docdoc ac72c66d611118545906b5f23ba3aa32a7dcf91eb2f2f41c1476afea66ad21faVirustotal results 36.84%Heodo
2020-08-14FILE_D8CTE9MW81ZZFQ9.docdoc 5b9c77e173da67ad419ce7c2c1264bd51647f242339265f6ea7a2af57ddd8f5aVirustotal results 36.67%Heodo
2020-08-14INV_50071016.docdoc 13425d91c0471208df6a06b23e5f176fea8637422e82c95f1ecd534aadda855bVirustotal results 36.07%Heodo
2020-08-14REP_PO_08142020EX.docdoc 28bc4f423b833b0fadccb2de2327be63041318014cf1ae1e1dc1941010322f53Virustotal results 35.59%Heodo
2020-08-14BAL_GPW7BBDY6IXYMU6.docdoc d4fade764b1ae03f546843ff7b67176a1d7fca0c1cad66455d0770c364b5746eVirustotal results 35.00%Heodo
2020-08-13S7B9TH2.docdoc ae007fe87d30f9b482a9a7525e1ccd6b8a482bd23635156170ae371339d27341Virustotal results 36.07%Heodo
2020-08-13DOC_PO_08142020EX.docdoc 668487ec145e75676c1a4fd6e0828331c412f7fe35709a3deb6d182debad6422Virustotal results 37.70%Heodo
2020-08-13473664681086445812563.docdoc 0ed266508f694702f6337f375bc70e94eb3c5397bbf5e4fddf1d319a751544dbVirustotal results 38.33%Heodo
2020-08-13REP_9Q4285SP2P.docdoc 04df573ac90a418093676f7b715b938c6ed9367b845d3ef5e4e1ae4f51ced816Virustotal results 36.67%Heodo
2020-08-13PG_YE6771936494XK.docdoc f0e83e09fe7f05e06f70b1e8e13f26adda64a1872f9104b340bfe870d9e27011Virustotal results 38.33%Heodo
2020-08-13LR_WP3991673124QB.docdoc 40fa25d14444c5f0471cb5e33a8397ec008ad42615aefa558366173602afc62bVirustotal results 38.33%Heodo
2020-08-13C_FNTL0MN8PA.docdoc 9b6d833972d18927b686656be4ce748c8824166731d940152534142ce2647cafVirustotal results 36.67%Heodo
2020-08-13FILE_TPN_080120_WXQ_081320.docdoc 9be561c7cf40dc53dbba36e51b0787a5dfb2c43000b0c5915df93ec5ef170687n/aHeodo
2020-08-1300JM1GH7CN7O.docdoc b4a759ab982ab288dd6ab871610df205148b10cf4305cd15be190ceb1370e330Virustotal results 38.33%Heodo
2020-08-13REP_DU2RBH90SK27ZM2.docdoc f153d1cd2401db480ab764a78b8a1928c558755e34f37ecc8ece84b1f14e6964Virustotal results 36.67%Heodo
2020-08-13FILE_30636290.docdoc bbbfae57148d4ae3803142303babc3d2fcb182194f9112aaa34b6f4978e8e0een/aHeodo
2020-08-13BAL_49892016.docdoc 3f54dbc7d7efc9342ac4ae143a7e38bb8d4138d9106817ab2f5ae7ac6b95f277Virustotal results 36.07%Heodo