URLhaus Database

You are currently viewing the URLhaus database entry for https://akgul.av.tr/jfuyb/LLC/KJZZZDC02d999rAKol/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:538599
URL: https://akgul.av.tr/jfuyb/LLC/KJZZZDC02d999rAKol/
URL Status:Offline
Host: akgul.av.tr
Date added:2020-09-16 22:24:03 UTC
Last online:2020-09-17 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 22:26:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:5 hours, 10 minutes Good (down since 2020-09-17 03:36:36 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-175382879 329594.docdoc 1888c0e8ca2680933a24093dd103357ec73394ff7b627ef3b2c9272817a6e829Virustotal results 31.67%Heodo
2020-09-17dat-20200917-E900.docdoc d452df085e4fa1e9de2c26da033abc9944b538757f876b06980b6ec948953f08Virustotal results 33.33%Heodo
2020-09-179272HW 20200917 H389.docdoc 4a302b44df11e4712e28d8e684fd9be280473a1f16ede2d69ee10c7aa97122a8Virustotal results 31.58%Heodo
2020-09-17Attachments_20200917_5665436.docdoc 3f4bf548088814d982137a7a86ee7ef03c92225d8190047c8f06d3a98440b63dVirustotal results 30.51%Heodo
2020-09-17doc-20200917-9727.docdoc 52d1e34446e3375a5113383a78e7bc3a0a6c4a1791c2ef347e56564217852ca0Virustotal results 31.03%Heodo
2020-09-17INF-M415949.docdoc 9292f6dd43458e974f0c4a39a5574e21b543c84949612bfd88587187d0ab6a81Virustotal results 30.51%Heodo
2020-09-17Dat 2020_09_17.docdoc 0ee3ee6d46932766c0b60ab6d06d8791a97c6cc37289e03f7d74543916ca8145Virustotal results 30.51%Heodo
2020-09-17MES_2020_09_17.docdoc f8fc724bbea7e936d3992ae10d584f731a9769e20cf21f0c9b1520d4479407a8n/aHeodo
2020-09-17list A0132.docdoc e0ef54d4ccf770a88f53ddfc67ae2684ecc6a5af1261cef668c18943ebacae96Virustotal results 31.03%Heodo
2020-09-17Inf_2020_09_17_RN86973.docdoc 205acd1fb78f111640a402574b079502d97b9c3e17729869e6931d30842a8b16Virustotal results 31.03%Heodo
2020-09-16UNTITLED 2020_09_17 HZ6245.docdoc c0a665fc668d444e9238e57cc6599bd2617c430d10562c067b9dd5a609bbadeaVirustotal results 29.31%Heodo
2020-09-16GR58041_2020_09_17_YYD732832.docdoc 4be9c13137a7afe484e5ef71a404a5b9b910d2ca17ccfcb7524ead6a5e530aceVirustotal results 27.12%Heodo
2020-09-16V6250 20200917 ML650.docdoc 9517199ff23937f5824cedaa844f795b50e7ed9d127a62219051249d5da76b63Virustotal results 26.67%Heodo
2020-09-16REP 548104.docdoc 40afaa1f04f40b23a4002e09b26fbc3ca750eb0aa30a69c04b3c5cd33af2185aVirustotal results 25.42%Heodo
2020-09-169958JE-20200917-XHI623.docdoc 97214e11cc4031687da4e0f6bd8d5c8d1d671f191e3e0cd29ff774dd79df8d3cVirustotal results 27.12%Heodo
2020-09-16MES-MO11037.docdoc 4ff425a974e9720cc0bf4d6ae70d4d57ec4edba20d9949e1c2dce87d6f7b20b8Virustotal results 26.32%Heodo