URLhaus Database

You are currently viewing the URLhaus database entry for http://alemelektronik.com/wp-admin/Overview/lg7WXidrUjEa5vv// which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:607977
URL: http://alemelektronik.com/wp-admin/Overview/lg7WXidrUjEa5vv//
URL Status:Offline
Host: alemelektronik.com
Date added:2020-09-24 00:38:03 UTC
Last online:2023-03-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 00:40:07 UTC to abuse{at}bursabil[dot]com[dot]tr)
Takedown time:2 years, 6 months, 5 days, 9 hours, 19 minutes Bad (down since 2023-03-18 09:59:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-15file-JRN4127.docdoc f6b597f946871c368edaf6b2e00b66fa841104f305c908ac3112e2dddecbfcb1n/a 
2020-09-24file-JRN4127.docdoc f2e3feb41565cc844a3bb072dbb0d54fb53d4f1cc44860f23dc3d8c4f4c470edVirustotal results 19.67%Heodo
2020-09-24Dat WFO55800.docdoc 7ac2d92f6e512351d634ba8379ee1740add6e1ef9323c0b1f178d38d4b37a50aVirustotal results 19.35%Heodo
2020-09-24LIST 2020_09_24 0841272.docdoc 32723c361acd35dd884c3243982f32d78493255655f04ef6246b0c4fdb18f3f5n/aHeodo
2020-09-24file_20200924_2554141.docdoc 15b5594b366a3bae22e4d6bdaad907bf889b957c9e8572452d9569ed245530b9n/aHeodo
2020-09-24Rep_20200924_4608.docdoc 448c58d4e526ffd04116fb0f31bd9971ce9f51c993c4368e3ef8a54c93a2c70cVirustotal results 44.26%Heodo
2020-09-245685798 233103.docdoc 77d05388e54ffc1cf04195a80a090cb3eaa41f8820c93c4c646f4f56cb6beffdn/aHeodo
2020-09-24Dat-20200924.docdoc 4646dd3e53714af28ecc8c4bd54029a5cb00ec4ea6eead753353eeb8e574ff63Virustotal results 39.34%Heodo
2020-09-24file-20200924.docdoc 884432de11d0670a7d8007ef1fe5d877b72e7ebbe678ac2cac3bc08708a723aaVirustotal results 35.48%Heodo
2020-09-24list_20200924.docdoc a8c29fd851cb952d316acc958e0666ef6c6d2ce6e1d8404dc1aa1ab06c95b79cVirustotal results 33.87%Heodo
2020-09-24Dat 2020_09_24 ST125900.docdoc 2f8c5f8173199d582e3535ffcda34ccfa553e9b5d8ab915b54d4d0307061ed19Virustotal results 33.87%Heodo
2020-09-24GG3207 84764.docdoc 48523dc1483cef07ef0bca44fe8f6629de0a7ab7e89899640b66568d4816c54aVirustotal results 33.87%Heodo
2020-09-24inf 2020_09_24 971.docdoc cb764536b329d21fa9638d8e1609ad4382e4e4ba44756045a7196c051cd12c78Virustotal results 32.26%Heodo
2020-09-2422641253-20200924-090197.docdoc e78aaad701d002d1f339fc7ba9cc5b4638abb42e61d7e17a5ece92ecb54ca0b4Virustotal results 32.26%Heodo
2020-09-24Rep-2020_09_24-K29890.docdoc 1f5a248a7fed3080327c72e34d85898e21d55cfa67d12d4ddad538f86492573bVirustotal results 32.26%Heodo
2020-09-24MES 2020_09_24 42386.docdoc 7c7c3627f0d6de0dacbaf735a2e34a8dc5d7397c9a7fd91b3831446a55667642Virustotal results 32.26%Heodo
2020-09-24042815.docdoc 234d3ad4abc48e15ee2c813f7202154e54609b7380d8d7f803801c1759ed2042Virustotal results 27.87%Heodo
2020-09-24doc_396.docdoc 94e4fe6c73db0e80100417fe60ab8d9b1fe7fc9ece7a2923861e1e1d42717d4dVirustotal results 27.42%Heodo
2020-09-24inf-954.docdoc 84f79d722be936645f3ae527e940d6902ca8c87bdbd337e85c31a2990460dfa3Virustotal results 27.42%Heodo
2020-09-24MES-APB944.docdoc 627da70ae807d43827d68ed505588ad930a9e5c02c294477c5910f844b3a7c30Virustotal results 28.30%Heodo