URLhaus Database

You are currently viewing the URLhaus database entry for https://okankoleji.com/wp-content/uploads/2020/6yjxunji5eqi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:734386
URL: https://okankoleji.com/wp-content/uploads/2020/6yjxunji5eqi/
URL Status:Offline
Host: okankoleji.com
Date added:2020-10-22 11:53:04 UTC
Last online:2020-12-26 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 11:54:40 UTC to abuse{at}ttnet[dot]com[dot]tr)
Takedown time:2 months, 5 days, 10 hours, 39 minutes Bad (down since 2020-12-26 22:34:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22PO_10232020EX.docdoc 838408d31e494e72b257feeec73407a2f778e6ecc47754ae16af0290515dc9fdVirustotal results 42.00%Heodo
2020-10-22INV_35332253.docdoc 03d580e7110bd85d7a360ceb31538a967f59877402892ca04ae4859e4ea20e00Virustotal results 42.31%Heodo
2020-10-22PO_10222020EX.docdoc d6703263ade837f40041f706035c4607c319cd75efa19a8c68a7ab46fc43c1a5Virustotal results 42.62%Heodo
2020-10-22FILE_PHZ_100120_PLN_102220.docdoc 1fe29e28174521c55bb6e73db876f3e783ba9eb0905a51be0d2ee6254bb903e4n/a Heodo
2020-10-22INV_89480985.docdoc b1dd253ade315392024f0586eb829a5317cbaff4c8428276b58a1566ed9db173Virustotal results 40.74%Heodo
2020-10-22PO_10222020EX.docdoc 001639b7cc59c0a2584aa6a318a5f5b65adab079e516f81c1053efbd1feac7ccn/aHeodo
2020-10-22NV8631272314GA.docdoc 160feb6c0a83cf0dab3174f74683de6aa53315477d6679712d47415a2364dc2dVirustotal results 39.22%Heodo
2020-10-22DOC_8664184161641359981261557.docdoc 28061fbdc60d3031a20e1c8f75d20d703307a03ba696fc87e507c3a356e0ae68Virustotal results 37.74%Heodo
2020-10-22AZP_C5E5OV7QNCCY93.docdoc 9dfb5e6e2134b14b82e9f8ec6fa56919f65c57d95c28d9c2bba1fece5a4e0082n/aHeodo
2020-10-22RPVZEQM.docdoc 44be59f199c5d2d4d0dcfef847d9e611abcaab3d8223b63fcbfe9a5d3c6745d5Virustotal results 40.74%Heodo
2020-10-2289678926.docdoc fa80d9c5ac5a3d08f91d1d1a13ca9e8dc5bd6e9dc289fa203b6822c74a1dbab9Virustotal results 38.33%Heodo
2020-10-2255020156.docdoc 7a2e6cd2e23620e7dd3ac4811e5b79b7532fb6d910e96109e46bd47b0b4b5c2bVirustotal results 37.74%Heodo
2020-10-22RN9840837110RH.docdoc f96bf3a1c2f289447b8d80a94b458e8987c92d191d6fe9880b1f21be1ab78abdn/aHeodo
2020-10-22KA_AMY_100120_XFH_102220.docdoc 6f64e8f7b58ef57d185a9150be2954a871855e0c33586a9309652e7b16a333b5Virustotal results 56.60%Heodo
2020-10-22F2X2U0X9IJ0BJ.docdoc 41a63682988f94b9df71c291da74ad8723e2663b7d17e36d8169a3922e5ce580Virustotal results 50.00%Heodo
2020-10-22INV_74916142.docdoc f84f03da92518ba991641be1e7096fef4fa7914d858e207b1a645fbe7c2291eeVirustotal results 43.33%Heodo
2020-10-227247229112321232670.docdoc 7672ae3ab7ee30ee3ef086ec0b9ced8c85e56d045f12305531d826ba491237b2Virustotal results 48.39%Heodo
2020-10-22DOC_HG6469112424OY.docdoc 9bb4de39d9e3b645efd9378896791c1cdee73c0c1501b95fde6b2adb1334c0e6Virustotal results 49.09%Heodo
2020-10-22FILE_PO_10222020EX.docdoc 9c0cb6e2390b59f199cd4dfbca2d6eb2106969b29ec8df33e4987474b80344eaVirustotal results 45.76%Heodo
2020-10-22PO_10222020EX.docdoc c41bcade49f3e2413b5d95ce09c2ecf30c21b43ab6b306206b9b737f1cd10450Virustotal results 42.62%Heodo
2020-10-22BAL_IZ5989013461PE.docdoc 6916f815ae3094ba0e9c9f0464bbd05f8619ce4da774387e7b7df3e1d82330c5Virustotal results 43.33%Heodo