URLhaus Database

You are currently viewing the URLhaus database entry for http://younesalturkey.sa/wp-includes/M9juj5M/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:761020
URL: http://younesalturkey.sa/wp-includes/M9juj5M/
URL Status:Offline
Host: younesalturkey.sa
Date added:2020-10-28 13:34:03 UTC
Last online:2020-10-30 01:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 13:36:53 UTC to abuse{at}a2hosting[dot]com)
Takedown time:1 day, 11 hours, 54 minutes Poor (down since 2020-10-30 01:31:21 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29inf_46LUG5AOMIRLFO.docdoc 98e256fc5cec649496c3aa8134d872579260d8a845b5394bdbe6d34aa3c413d9n/aHeodo
2020-10-29LIST_ERK_100120_SUX_102920.docdoc 75df04fe2bbfe95af6c2ff3ad6beb372645597b0350f6cc16f995a09e27da829Virustotal results 26.98%Heodo
2020-10-29FILE_9BZJXDDMOLE3WLJB.docdoc 435bd29b63544b01f0aa17d2260f1b77f63cf256dbe4029d85ef0f8f9427348aVirustotal results 22.22%Heodo
2020-10-29APW_HLP_100120_KOD_102920.docdoc d7edab7749baa696b995be184437050a249c40992deb7cbd3472cf93fd8a154fVirustotal results 20.97%Heodo
2020-10-29LIST_97033213.docdoc 34d9cdd8a269048d1a73d296e922eef7ab126f766b8d9a8191dbaeb1345a8dd0Virustotal results 20.63%Heodo
2020-10-29Inf_96018961.docdoc 0eabb37538a78fb8b43917d7263b14ceeb7cd09922f2d1c397b8db18cab99e2bVirustotal results 20.63%Heodo
2020-10-29inf_89312425.docdoc 4b5407d72985ea26f81abd0c5e3d3d309cdaea79e724b4678d5dc0c151280da1Virustotal results 44.44%Heodo
2020-10-29UNTITLED_47662112.docdoc 38df7a8d7d8ddeec4905b01777148222f208d5030b7a44665b5fdafb5bd9ff19Virustotal results 40.32%Heodo
2020-10-29Attachments_74824046.docdoc a94691d74d543c82cfb7a293d0de416bec72dbaa2a2776d2ffa9b176b28cc12aVirustotal results 42.62%Heodo
2020-10-29Untitled_0201968206146237.docdoc 17d6d17702d158eda616b2096600e47fe0808914ae353ec5009763a5de5fffe7Virustotal results 36.51%Heodo
2020-10-29dat_9VF4D3T.docdoc ab7a59b346e75d68ff9a689f85a0d2a96833a3048478fab68af1e8f1bd4d5905Virustotal results 36.51%Heodo
2020-10-28B_OKT_100120_QMJ_102820.docdoc 88ecbebf3f50eca1713851898cb315638b520a2c46f5d21f370de5ac8a4de484Virustotal results 24.59%Heodo
2020-10-28FILE_OXV_100120_HJR_102820.docdoc c3f9c25daaea07684a67a58d2ec8115321b592a8b0edc6eaafd2e8844f22c10bVirustotal results 16.39%Heodo
2020-10-28dat_2207640263.docdoc 7eeb30a34016ac7c6d48178f44b12c48df17acb131f0a96847d1cd67c464ce30Virustotal results 25.81%Heodo
2020-10-28list_PO_10282020EX.docdoc c52d8de4c0df2d3039b4e550b081b8386bf713ff22749065c331fd9c03bfa88dVirustotal results 17.46%Heodo