URLhaus Database

You are currently viewing the URLhaus database entry for https://xn--borsaliman-6ub.com/wp-content/kDBeek3qoGISWUn5hh1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762047
URL: https://xn--borsaliman-6ub.com/wp-content/kDBeek3qoGISWUn5hh1/
URL Status:Offline
Host: borsalimanı.com
Date added:2020-10-28 18:44:04 UTC
Last online:2020-10-29 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 18:46:05 UTC to abuse{at}ni[dot]net[dot]tr)
Takedown time:19 hours, 8 minutes Good (down since 2020-10-29 13:54:39 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29List_PO_10292020EX.docdoc b770e53d7a44c680b7ce2fc81e13b5de570dce0b57c587442874b3c5f6f94d83n/aHeodo
2020-10-29Doc_MP1MI4RP0FSN.docdoc 1909a3514994e354da8e5abdfbb3b73173a1a6782a739ebdbfbacf098abf0fb2Virustotal results 20.97%Heodo
2020-10-29Arc_CQM_100120_KVP_102920.docdoc a536a1efba18ff7db257286623904f5d131c7e933b0af1302fec81dfca157b65Virustotal results 20.97%Heodo
2020-10-29BNGIWSC.docdoc 9dc022a6d94a428fb2f095b0ecb4572e6b60e7b59a3ba584a8c4a04cddbf3251n/aHeodo
2020-10-29Arc_FM8533785425WD.docdoc af8373a05bb4ac069cb45da6f676db803e252cb4c3e378c3fe25375323c74db8n/aHeodo
2020-10-29File_63916440.docdoc cd49f6f6b2b1cbf28331a1eff67e7179731f34a790a1bb69c89b65ffcfc38e01Virustotal results 20.31%Heodo
2020-10-29rep_FN6266842465VQ.docdoc 3a1dd7ec119b96ea68facb223082a398ff4c038e58e7d166c80d7a7d4a3758abVirustotal results 20.97%Heodo
2020-10-29list_471593744161.docdoc 6b696b987488f5f9abee78f4d38565535d928adb645de9f48e95a99914bc5dc8n/aHeodo
2020-10-29ARC_45180519.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119n/aHeodo
2020-10-29list_KKV_100120_DVF_102920.docdoc 5a00d4a9d8e50c06f30007460af1dc4f73950dff8ef4d1966ec4098c16712bf0Virustotal results 42.86%Heodo
2020-10-29DOC_47142320.docdoc b9e189f0cb3064ede89dc2167eca309a64edc4ae42aeda9b8fab875c4906b5dbn/aHeodo
2020-10-29Attachments_845301127136219257335.docdoc 332d48b31116922bc05e18e6322ac17328b888d5e0b92ad3ddd4d665111b7ce8n/aHeodo
2020-10-29Mes_ZB0776635241VX.docdoc 1187f4742f61d0c2db716f1b3322181923c861a7588497af125af7753f409b3fn/aHeodo
2020-10-29Doc_55NI8C4EISUQ.docdoc 42a5e4e595594e5e71e067312918e7858011f85588cc04720f4752f883f45b20n/aHeodo
2020-10-29list_ZP0LYJJ8.docdoc 6df480c2f89e67bd88a1ef3142106f925a45830756da26077582ef439dd4c5b8n/aHeodo
2020-10-29Inf_23055229.docdoc 7161db36ab8dfa34e4ae1aefa3d4fd7923a2a89118835e1e8bc905216bbf70e8Virustotal results 38.10%Heodo
2020-10-29LIST_935031881216.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 38.10%Heodo
2020-10-29Rep_EK0654441378XS.docdoc 4c8eeccd2a16f80874acd0057d5ec622d3701e32a3198bdb763f39e39ea28982n/aHeodo
2020-10-29Arc_88718440.docdoc 393cb1523cfa3f9dc1d2a45e467810be8447ea0f58435edf5bfd1e0938e293e0n/aHeodo
2020-10-29DOC_5MZDPB8SIJ.docdoc 384a86ce03971610e03d72c4c46dd311c1719b3264e1f8724c6314a5f724b5ccn/aHeodo
2020-10-29rep_VOC_100120_QFL_102920.docdoc 665ea7994646d6f55327063f07c46e3d51cce78766dc14fc03031b5581283b10Virustotal results 38.10%Heodo
2020-10-29arc_74516499.docdoc 16593eef39e8c04fdbb6390954522fcbb430e3d131921c0b5f4e9477ebd794f9n/aHeodo
2020-10-29Attachments_UO3147528592HY.docdoc ddff5ab1d127fa30a0f2353857d3ac72c8b28191737e15516420dc25abaa6784Virustotal results 37.70%Heodo
2020-10-28list_04306090.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28Doc_PO_10292020EX.docdoc ff451db73672e713a3b5a30084d42b5d09a39ca3651cbb1b3c15ce4b18234592n/aHeodo
2020-10-2863715281.docdoc a3fc674142c99cf43ec65daf8d31036f96aac0f9ef66988b6b3d80ac73f60bfbn/aHeodo
2020-10-28Arc_PO_10282020EX.docdoc fc6ba0089f3355775a62f986bcdebe3bf7d58d1934d524e952f9279bb82cce68n/aHeodo
2020-10-28FILE_04522543.docdoc c79ff6d2cb77b1d4e7bc6bea1ea1b05d78d536e72254e93dbaeb1122ff214d8en/aHeodo
2020-10-28DAT_CDJ_100120_YKP_102820.docdoc f25bd084ce8d81cd2533601965f19c49105798af5fa7465757626b6cd057dd61n/aHeodo
2020-10-28list_69803332407093440.docdoc c2d24878a478d12f42849ded89565fe77905f7af790b6a7272ece4fc9db45fe2Virustotal results 19.05%Heodo
2020-10-28Attachment_Y5XQ2LKZZJLBG7.docdoc aa5cac23b5ef62c9a3966c4722f8713c7a383ff5bda64d7a684c56e197bbe5dbVirustotal results 17.46%Heodo
2020-10-28LIST_WX8100548950CV.docdoc 290d99668c637b392210c43c77b9672357db0df908a2cee8c6c84399c0f3dc55Virustotal results 19.05%Heodo