URLhaus Database

You are currently viewing the URLhaus database entry for http://yatkiralama.online/wp-content/Document/nk7jo2731146115yjxp2gce00hh8k4w/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435187
URL: http://yatkiralama.online/wp-content/Document/nk7jo2731146115yjxp2gce00hh8k4w/
URL Status:Offline
Host: yatkiralama.online
Date added:2020-08-17 21:27:04 UTC
Last online:2020-10-09 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-17 21:28:04 UTC to merkez{at}aerotek[dot]com[dot]tr)
Takedown time:1 month, 22 days, 17 hours, 29 minutes Bad (down since 2020-10-09 14:57:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-23N_BWZ_080120_KZD_081920.docdoc 8b7e4be9c5b4142aa0687a1e9eeb2d8cbcb5f6002bec7665fbc98124102b5172Virustotal results 66.67%Heodo
2020-08-17MW2230577812AZ.docdoc d4917c2e36254107abd6f1f06201f1cedf4bc6fdf73e569b6ae7827bdf677925Virustotal results 42.37% Heodo
2020-08-17REP_MTJ_080120_BLV_081820.docdoc b9b63541ecaaa34dcbec65dc87f19610faa26ac3f9b45a749f686bededa3b54eVirustotal results 40.00%Heodo
2020-08-17I_15282157.docdoc 18b1585abb668182213b56998ae5ed30758e1649c11469b52af43723c5b0704eVirustotal results 40.00% Heodo
2020-08-17FILE_KQ4601483975NY.docdoc 6eb52f464c8845b595169880341a670e6dfc2fb1c5ba4e59f01122d6e15c9536n/aHeodo
2020-08-17RSUAJ9JJLK2VTF0C.docdoc 14b04f2ebe4013ef67c7eb3690723c89f1d6fa7eb0994579e271fac13feacef1n/aHeodo