URLhaus Database

You are currently viewing the URLhaus database entry for http://www.demirtozboya.com/FILE/594891564002766/18u55zv-213798/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:445501
URL: http://www.demirtozboya.com/FILE/594891564002766/18u55zv-213798/
URL Status:Offline
Host: www.demirtozboya.com
Date added:2020-08-27 21:32:35 UTC
Last online:2020-09-01 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-27 21:34:03 UTC to abuse{at}adeox[dot]com)
Takedown time:4 days, 12 hours, 14 minutes Bad (down since 2020-09-01 09:48:57 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-29Payment.docdoc 5df4f10d255d1733e9450ecf67d166c73f6f29bb36efe88d6093a31d31ce0ad4n/aHeodo
2020-08-29Payment.docdoc 4cc3b0434341ecff74a4c62206f91d15c075496a48829df0ab0f51b530dc9ed5n/aHeodo
2020-08-29Form - Aug 29, 2020.docdoc 3b5c4fffd6b0548d5d66842086b1b3762032be24a72ceb3154d72cc55cbb8d83Virustotal results 44.07%Heodo
2020-08-29INV #04773298 FOR PO #0000457781402.docdoc 3a8a42c319462b67597a9fefae7c60c0a3917018eef2b0bba8bb02980e6ffe02Virustotal results 44.83%Heodo
2020-08-29Form.docdoc 139e6af741bc7d94ee44f8a69dbc8e694a72bb780b0b984a2c57cc99966d3e5dVirustotal results 44.07%Heodo
2020-08-29PO# 08292020.docdoc 63b6721473e50f9b390f116cda2dc97aff00e66766293eae82b907ae7ce0c375n/aHeodo
2020-08-29818401.docdoc 3b05f64f06873b3ad6438916c81c4f4139191b2d5a8324a632b2ef7fe4a82803Virustotal results 44.07%Heodo
2020-08-29Payment.docdoc 20d5c90c46b7747659e92efa4aa78da9e7404b82187e9e8605337918faad432fn/aHeodo
2020-08-29Invoice #92893038.docdoc b7a2a470b35a3cbf4a6501f45709fa7cc29d2a33c5cac4f00ac64b426b90929en/aHeodo
2020-08-29PO# 08292020.docdoc b8029c0d90d1b4ff550cf1f13603ccb9b462e64c8b81afc2ac33252b86839931Virustotal results 35.59%Heodo
2020-08-29INV #0616380 FOR PO #003651375370.docdoc c98ebc2ba9a8e8f27e921e635f8742cdbb64688b48b57e7300575ccee61930a5Virustotal results 35.59%Heodo
2020-08-29invoices 608 & 3281.docdoc d8c49275c5f1f5f0737181da7071f1755efac730269b0741539b1430a34096ebn/aHeodo
2020-08-29Inv_85318.docdoc 0c962f3623896801e405c611fdc2b6cbbff5a1757ab32e43feaaa32ac76fd56an/aHeodo
2020-08-29Invoice 02134661.docdoc 8024aa6cee62d71b90733458c64c779647087eb613aba76cd872a01b46cfdea6n/aHeodo
2020-08-29invoices 91115 & 6803.docdoc a936fa77ef0be55ddc1bba6a24c65da623b7207d45356219d55b2475a4234b9cn/aHeodo
2020-08-29Inv. 067959960.docdoc 7a2ea6bf67afad967a724ca65954848493d2b3d60c68a583219c0d8acff06db4Virustotal results 32.76%Heodo
2020-08-29Inv. 061879.docdoc 84f65defa9ad80289cef180755c5be526232c499254749b3a11020a776c34ba5n/aHeodo
2020-08-28invoices 08820 & 8742.docdoc 5db10c40e7788456c57bf2481d95f86b762e85ec74c1ba5a232014afc0b7071en/a Heodo
2020-08-28INV_662908.docdoc 418cd12b251bce9b75ac793c3d626440b35e8e6ef2002751114a27eb3a627d26Virustotal results 29.31%Heodo
2020-08-28MG-080120 WYDG-082920.docdoc a457afd23063f580f5431f2118cc0936362067a7440f76d90eeb270da41508ecVirustotal results 28.81%Heodo
2020-08-28INV #09269154 FOR PO #0023616274450.docdoc af205422f14b639b4df94286a2e75e65fd7522ea8c0ec60d23af74f197e9a02dVirustotal results 30.00%Heodo
2020-08-28August Invoice.docdoc 1af25f1feab8bab24a7f9f4531268d94b21a132eb001a1474213e7f92378cef5n/aHeodo
2020-08-28F9848904125GH.docdoc 83a4d7860de46ad541e0399824ba56d53f755c233914096fa08cdf1d966960b0n/aHeodo
2020-08-28Payment status.docdoc b89e478d217b03e8c0042bab248bd9431243f6fbe54c13d26d77b63b93c0c99cVirustotal results 28.81%Heodo
2020-08-2800917768.docdoc c7042f61131d4a483d3b7433af94d39743944f2fd4e00abf795450a603c883fcVirustotal results 28.07%Heodo
2020-08-28Inv_6224.docdoc 96955576446f803417498ea62363fb51274e644a275afcd1086cfa9a60df1d92n/aHeodo
2020-08-28August invoice.docdoc 81cadd314f1bf342797da22c3d89200bc29b25a928bd3a8241d2864d3a6d4771Virustotal results 27.59%Heodo
2020-08-28Z0528 invoicing.docdoc efddb6ce3f85a172356a95dfe3e262efff6d615be2339031c4ac5a68d7d2b2dfn/aHeodo
2020-08-28Copy invoice #4322.docdoc 427fa32e1296a2edfcab458af02c46f7ef53c82d98e29ab7161e5d8f8443b932n/aHeodo
2020-08-28Invoice.docdoc 8e0a43dba192a9953d51771fbb1935e32f67fe8ec37566325e406fecd46c36a6n/aHeodo
2020-08-28JM6646596241KH.docdoc 17040e536cb711011ddfe95c5302469d68db8f57e368902fa164633d4104c7e3Virustotal results 43.10%Heodo
2020-08-28Form.docdoc 819b13194a2265d7d36170eea82b3d549e982afd2dc4dd0a18f3dfc0978ea61fVirustotal results 35.59%Heodo
2020-08-28Form.docdoc 47d6846e884d98db8852029fc3165f685f5dd03ab66b75531c54ba037275345cVirustotal results 36.84%Heodo
2020-08-28INV #16072 FOR PO #00046471474321.docdoc ec40ed720288cc6f6709a37c239c8847a075b83924b6234f129f28d4bf5b229bn/aHeodo
2020-08-28Invoice #1621418.docdoc 04db0fe3d77ca5cbbff1f31bd8c3a447d0064d2a0154116bbb03556dc330bb21Virustotal results 36.84%Heodo
2020-08-28Invoice #5944886.docdoc 5a4cf0221fb9ee6669bf548222ff11e164ce4d437225148a391f7121e6401a7bn/aHeodo
2020-08-28008800745.docdoc f5eb0742ddd76b3e12d9f836701dd83a4bc0acd63810d1cddcbf7306caeb48fcVirustotal results 35.09%Heodo
2020-08-28INV #0506 FOR PO #0070376934994.docdoc eb2643323c03b0e4f951c27f3d3003dece58d31ade3490d2d2dba0c480c21695Virustotal results 35.59%Heodo
2020-08-28Invoice #039876832.docdoc fe67dad19921f5aa8094f795c7d533572b3d6d386e1d3b9d1490738b2150e066Virustotal results 37.29%Heodo
2020-08-28INV_864391.docdoc 56385c138dcd6e1f59be2fadd0cb3e78305d5a8b74de904c00ca85d68aa84809Virustotal results 31.03%Heodo
2020-08-28August invoice.docdoc f518586d760ddbf3ef58ae4e7f8bc570d1154c9756e793135770a886901385cdVirustotal results 30.51%Heodo
2020-08-28NJ6180164321YH.docdoc 80efca7075384c9e74efa75e5b474a4e4e89ed61e019e3c493133a31f97b1ba8Virustotal results 31.03%Heodo
2020-08-28NJ6180164321YH.docdoc 7f55c07ecb2fd95e4a4c2d8f11f4fba46a013d487e3aa270e1a2d91686b01578n/a 
2020-08-280995779843.docdoc 8a2ccbf2fd45902471ea5dcc116d258ca0ff53b4e7499fe76f00349f029d0570Virustotal results 31.03%Heodo
2020-08-28H6230157911GR.docdoc 717e95cf51d45cf596aabdf52e31383a32dea1d2e41d90601b9d8176d44f588cn/aHeodo
2020-08-28Payment.docdoc a4e35918b2db5a325a398c79bb0cd310e6d1c70f405953dd8f0335f3c9cc8f2cVirustotal results 31.67%Heodo
2020-08-28ZK0 invoicing.docdoc 1d2b270375ae00907412647180a7dffae422dac066c42966c9cca4bd1dd8dfe2n/aHeodo
2020-08-28August invoice.docdoc 7e0d6fc8bc7a69d5e27e2130c83b434512af52a5337145098c2426f62abf97eeVirustotal results 33.33%Heodo
2020-08-27Form.docdoc 358ed107c0ee5415d97b9bd9445a363ce135bbab29a12ae7daa028dd9e5514fen/aHeodo
2020-08-27Payment.docdoc 474fe5a4009da897047f91b9d9b8f40aaa5d674955f0815934507029c7038976Virustotal results 33.90%Heodo
2020-08-27Form.docdoc 907ddcc7b2dd5151f379c7897b9de25bfcf3e3f5a8a58043b3339a540ee5ab76Virustotal results 32.20%Heodo
2020-08-27August invoice.docdoc 6404e3e703da64c594a45e59e02f1ebd13380fdfb4462b7f6086317f46432f3dn/aHeodo
2020-08-27PO# 08282020.docdoc 5eb93964840290b1a5e35577b2e7ed1c0f212ef275113d5ecdb4a85c127ae57an/aHeodo
2020-08-27Copy invoice #5250.docdoc 7b20c42eabfcb75c62ba2730d3e92e4fb4b6b8b025039d6a80f23462aa755027n/aHeodo