URLhaus Database

You are currently viewing the URLhaus database entry for https://younesalturkey.sa/wp-includes/M9juj5M/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:759772
URL: https://younesalturkey.sa/wp-includes/M9juj5M/
URL Status:Offline
Host: younesalturkey.sa
Date added:2020-10-28 06:55:07 UTC
Last online:2020-10-30 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 06:56:06 UTC to abuse{at}a2hosting[dot]com)
Takedown time:1 day, 17 hours, 5 minutes Poor (down since 2020-10-30 00:01:18 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29inf_46LUG5AOMIRLFO.docdoc 98e256fc5cec649496c3aa8134d872579260d8a845b5394bdbe6d34aa3c413d9n/aHeodo
2020-10-29LIST_ERK_100120_SUX_102920.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29FILE_9BZJXDDMOLE3WLJB.docdoc 435bd29b63544b01f0aa17d2260f1b77f63cf256dbe4029d85ef0f8f9427348aVirustotal results 22.22%Heodo
2020-10-29APW_HLP_100120_KOD_102920.docdoc d7edab7749baa696b995be184437050a249c40992deb7cbd3472cf93fd8a154fVirustotal results 20.97%Heodo
2020-10-29LIST_97033213.docdoc 34d9cdd8a269048d1a73d296e922eef7ab126f766b8d9a8191dbaeb1345a8dd0Virustotal results 20.63%Heodo
2020-10-29doc_FGQNLVGZ3X.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119Virustotal results 20.63%Heodo
2020-10-29inf_89312425.docdoc 4b5407d72985ea26f81abd0c5e3d3d309cdaea79e724b4678d5dc0c151280da1Virustotal results 44.44%Heodo
2020-10-29rep_PY8MJ2PO.docdoc ffa31d45d93161ab298442d4f9d83cf8b0bcead9e50e92a048b6b0900415b59cVirustotal results 41.27%Heodo
2020-10-29List_PO_10292020EX.docdoc a94691d74d543c82cfb7a293d0de416bec72dbaa2a2776d2ffa9b176b28cc12an/aHeodo
2020-10-29Untitled_0201968206146237.docdoc 17d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7Virustotal results 36.51%Heodo
2020-10-28B_OKT_100120_QMJ_102820.docdoc 88ecbebf3f50eca1713851898cb315638b520a2c46f5d21f370de5ac8a4de484Virustotal results 24.59%Heodo
2020-10-28Inf_PR9WW07VS17S0.docdoc ad10b386d964b6056e529c2bdb70ccb19ba21b3b0a59ac606113fedc49626b81Virustotal results 22.58%Heodo
2020-10-28FILE_OXV_100120_HJR_102820.docdoc c3f9c25daaea07684a67a58d2ec8115321b592a8b0edc6eaafd2e8844f22c10bVirustotal results 16.39%Heodo
2020-10-28dat_2207640263.docdoc 7eeb30a34016ac7c6d48178f44b12c48df17acb131f0a96847d1cd67c464ce30Virustotal results 25.81%Heodo
2020-10-28list_PO_10282020EX.docdoc c52d8de4c0df2d3039b4e550b081b8386bf713ff22749065c331fd9c03bfa88dVirustotal results 17.46%Heodo
2020-10-28FILE_KF8514592607HR.docdoc 586ff0aded5422c4339495e0480f86f8454c8a813252983954522edc060f6e0en/aHeodo
2020-10-28MES_77711266.docdoc 6a3681628d5e90051c68dd3bf6855abcdff9d8b6e25447bad58745cc5406d4e2n/aHeodo
2020-10-28Attachment_9065333169712459462367.docdoc 0fdb302c3db79d7ed89244d7adf4c56d5cc9e4643c3e5bac39c3e82cff3834e7n/aHeodo
2020-10-28doc_PO_10282020EX.docdoc 2964b5d28a8d65a8477f44ee1cc2b6859302f4e76e07a48217e9d948772ecb36Virustotal results 28.33%Heodo
2020-10-28Arc_UGQ_100120_XMT_102820.docdoc 0e6d4b4fb5bd9daa6ac86ded3c620a00429f484e217542d2aada6c4635867df1n/a Heodo
2020-10-28MES_6UL9O4IIDVKNFH.docdoc 499af6e46284239845d6e547823d8f197a8c92a084b2aecf1123e44d44a764e6Virustotal results 33.33%Heodo
2020-10-28arc_83244956.docdoc 96c1906f7dbb6cdf1beff4a38feeede08acd1e3c95112c076c1d4c7a6cd0adaan/aHeodo