URLhaus Database

You are currently viewing the URLhaus database entry for http://www.tekfark.com/UJkgvUOSitYiaZ/SEPA/PrivateBanking/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:48317
URL: http://www.tekfark.com/UJkgvUOSitYiaZ/SEPA/PrivateBanking/
URL Status:Offline
Host: www.tekfark.com
Date added:2018-08-28 04:13:59 UTC
Last online:2018-10-09 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-09-07 11:49:49 UTC to abuse{at}cizgi[dot]net[dot]tr)
Takedown time:1 month, 2 days, 1 hours, 12 minutes Bad (down since 2018-10-09 13:02:14 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-292018_08Details_bzgl_Transaktion.docdoc e7435a841ee7686dec1e9d6f2b9d6cfe5f6f037e6697489f7093ae6f8d9b3037Virustotal results 35.00% Heodo
2018-08-292018_08Informationen_betreffend_Transaktion.docdoc abe0ef45a56289299c007087029bf03c76e3ba13c144fe1d5eb4936d80a36f82Virustotal results 30.51% Heodo
2018-08-292018_08Details_betreffend_Transaktion.docdoc 283f4abf0240e746d9f8287d1a70d83ab085b91198b08b8a06453ceeb8c66408Virustotal results 23.73% Heodo
2018-08-282018_08Details_zur_Transaktion.docdoc 066fcdaac9c4245c517d63b0374bbf7aa8819699c0f94fe81a7c9619be462a34Virustotal results 30.00% Heodo
2018-08-282018_08Details_betreffend_Transaktion.docdoc e95a1730be5d655d7186684f7600f282c968de8ddb8c980c7c26317229e37ef1Virustotal results 30.00% Heodo
2018-08-282018_08Details_zur_Transaktion.docdoc 0c97ed85f2b9812c168c180b2c52fe12d397d8f738384e7d8bae6b73295ab04eVirustotal results 30.00% Heodo
2018-08-282018_08Informationen_betreffend_Transaktion.docdoc 985d90e1cbaf14278409cf16a82e26ceb88e1891a380b6dbed14a26a231fceb9Virustotal results 31.03% Heodo
2018-08-282018_08Informationen_bzgl_Transaktion.docdoc f865da7599c9c62aa4dcde350239ccd436e0aace9d0479d119b9df095f40abeaVirustotal results 26.67% Heodo
2018-08-282018_08Details_zur_Transaktion.docdoc 03a294a89508bace34e961e8a525539bcdf8542da4d36dd22a436677570a2c82Virustotal results 40.00% Heodo
2018-08-282018_08Informationen_bzgl_Transaktion.docdoc f423b8bebb1e71d7d8dae1ad6afdc93242c88b1a9d5f86f98fc4ff3d31cb53daVirustotal results 43.10% Heodo
2018-08-282018_08Details_betreffend_Transaktion.docdoc a30c1b751af3c2ed476c35905599c91eea76b5ac786b37158d5703d5f21afc9eVirustotal results 31.67% Heodo
2018-08-282018_08Details_betreffend_Transaktion.docdoc 64cbb6d77af4e715dc4d61023b26fc463e99f1fa0e176de484d71730eeac36d5Virustotal results 31.67% Heodo
2018-08-282018_08Informationen_bzgl_Transaktion.docdoc 29390b9ee891dbeac9519a65a1eaf199a398a502076599e5ced5c7856f1574a7n/a Heodo