URLhaus Database

You are currently viewing the URLhaus database entry for http://alemelektronik.com/wp-admin/Overview/bnzox9aq5scgy-09621/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:731243
URL: http://alemelektronik.com/wp-admin/Overview/bnzox9aq5scgy-09621/
URL Status:Offline
Host: alemelektronik.com
Date added:2020-10-21 21:42:03 UTC
Last online:2023-03-18 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 21:44:02 UTC to abuse{at}bursabil[dot]com[dot]tr)
Takedown time:2 years, 5 months, 7 days, 12 hours, 19 minutes Bad (down since 2023-03-18 10:03:03 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Invoice 824339.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22October Invoice.docdoc eedc1f3d57d4274cbfc97e09ca0975f97fff204e89fe92574f9e3964a569c9d7Virustotal results 38.71% Heodo
2020-10-22Inv. 01000584882.docdoc de172d512ec3cc9e02fe2834be3639ea0cfdc900b82d65acb581575290fc2d70Virustotal results 38.71% Heodo
2020-10-22INV #0081272 FOR PO #10704929.docdoc f95869656ea95b50cdc0dcdc93991a0bff0a1c265541f45bf204766fb5870736n/a Heodo
2020-10-22invoice.docdoc 6e126e02b7f4c06d354c623ac04174c9b81ca1ccb03c83f5de29b5722526983dVirustotal results 38.98% Heodo
2020-10-220073102.docdoc 12e6288fa176b86b7658d14a6f17935f324b38b4b454088088c6aa7548b9e905Virustotal results 37.25% Heodo
2020-10-22invoices 691 & 0236.docdoc 837053e508d4b63b491b2e13135ab62be34d6cafbc9a8cbd7d763816dc17f4afn/a Heodo
2020-10-220818465770LI.docdoc d18c0e979f37984b270f0c13f5be14520443ccf55b445d68ffaf6c48b89cf5c6Virustotal results 39.62% Heodo
2020-10-22Invoice #8948.docdoc 12a9d00947e3f08cb67e3d1a197fd116e29836a17845009e590d283eb80e960en/a Heodo
2020-10-22Inv_0012.docdoc 2de2e349e085756dd49a7af51ca902f1097273e33d63c057915e2ee159bce81eVirustotal results 36.67% Heodo
2020-10-22L7992315157YU.docdoc 2acac0803d5b5de2f17bb7d2c43af5ad438be8af04faec7bdb33b4cddda2a4d8n/a Heodo
2020-10-22Form - Oct 22, 2020.docdoc 01b228cd4f024acce23be7b762797915e8ece1d47c301e20f9596a98aed2acb5Virustotal results 49.06% Heodo
2020-10-22Electronic form.docdoc 74e16bd58ef88cfbc4267cf32b54a6444f5a01675811af2f8da025c1dd9e7272Virustotal results 50.00% Heodo
2020-10-22Form.docdoc 8849667217cbf5aaf17be7bc7eaef3b073f32d6d7d7a6f36a022c270228a0d8bVirustotal results 50.00% Heodo
2020-10-22INV_5775.docdoc 3ff0742359552875b1c51123cda087f09d97186d0f5540ada3e9611b8a94e9f9Virustotal results 48.33% Heodo
2020-10-22invoice #31554.docdoc 61c90e0b60ab1ac4a891679a1e051a65654201f44b65be90543c41691ebe8204n/a Heodo
2020-10-22Inv. 0712532.docdoc e61b38e662adb534177ec713ebff6bb70aba8c3e9ba4bd47c6f06229f803c1d2Virustotal results 44.07% Heodo
2020-10-22052412.docdoc af5bddd9f46abad7cf836d9faf757a676ba5bf9a7ee90e04c3a5cecd22c7fbd6n/a Heodo
2020-10-22PO# 10222020.docdoc 3cea95fe241c36b02ffc90f1260df43c8fc77e7acde8d5804ba4a461203332d0n/a Heodo
2020-10-22Electronic form.docdoc 2c746449ae089b436ecab1058c035e9ea8e01fd8f45508ed2ed720ff30ee2c01n/a Heodo
2020-10-22K-100120 EMBK-102220.docdoc 973f68fa660b0ff4da0047bc9d942a6f2faf63713e745fe19eaf4cf5d29828ben/a Heodo
2020-10-22form.docdoc e5ed1f6d9906107a56334a0f4903201eeeda7aa77f349ac217c53c9540b03c17Virustotal results 43.55% Heodo
2020-10-22October Invoice.docdoc 3abe5cdbb82a1a48fb89ecf043e24351ffb466cb6112ea7316f6fb518244a289Virustotal results 47.06% Heodo
2020-10-22926568.docdoc 14a0d5ba65a4585300b4daafa06c20898b303bcea1302012ef2f19559124edbaVirustotal results 41.67% Heodo
2020-10-22Inv. 0056079199.docdoc 2566d4cd03b1b31a54ee14af117d50f0d166a3500ac7b39df87cc69f567a862dVirustotal results 45.16% Heodo
2020-10-22INV_818613.docdoc 29e0f3a1a3ea0fa9c5f4f6de0c645b84d175af82725200c3d2fddfebb517c938Virustotal results 40.74% Heodo
2020-10-21Payment status.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 51.85%Heodo