URLhaus Database

You are currently viewing the URLhaus database entry for https://tekkys.repair/wp-content/1Z1qlkBSPpk8vQujwhOLyVitVQU01sdD6n65oFH3EHZiQVaocypP9O4LwDTTUzZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:763722
URL: https://tekkys.repair/wp-content/1Z1qlkBSPpk8vQujwhOLyVitVQU01sdD6n65oFH3EHZiQVaocypP9O4LwDTTUzZ/
URL Status:Offline
Host: tekkys.repair
Date added:2020-10-29 05:32:06 UTC
Last online:2020-12-25 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 05:34:04 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 month, 26 days, 19 hours, 3 minutes Bad (down since 2020-12-25 00:37:16 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-06n/aunknown b82b9b8e2bc397156d4009040f62b005887a288cbfa563d512e1f0a33b2d2042n/a 
2020-10-29FILE_YDX_100120_TTP_102920.docdoc 4fdf2563b45602028009105b6b5f30ab0dbd3ceb11857e9861b91afff59f247bn/aHeodo
2020-10-29Attachments_QG7DBFG9DPP3.docdoc c77bdf30a9a94eafd3718a954bd79a8e9ad3b32761d6c45ae1b79245df7599bfn/aHeodo
2020-10-29Untitled_0IK1FFO4.docdoc 78234ae12ae1b1b5068a17fe32b5a2656a7f999789fa9df9eddb8445e6fd41d6Virustotal results 20.31%Heodo
2020-10-29FVE_100120_VBK_102920.docdoc c56962ccf0f482b04c168639afb894430e7cb71c873faac02d8f3a34107f33a8n/aHeodo
2020-10-29LIST_PLY_100120_SZY_102920.docdoc ae454b06f63308de7e1a613281feea2eef089041c67af45e72ceec804482b526Virustotal results 20.31%Heodo
2020-10-29mes_VM1231287009RZ.docdoc 3a1dd7ec119b96ea68facb223082a398ff4c038e58e7d166c80d7a7d4a3758abn/aHeodo
2020-10-2993737320.docdoc 6b696b987488f5f9abee78f4d38565535d928adb645de9f48e95a99914bc5dc8Virustotal results 20.31%Heodo
2020-10-29RE0986973721XQ.docdoc 4105e48c905f55328aa0a89a608c302216a2d4b119573ef85d1e9902d0531119Virustotal results 20.63%Heodo
2020-10-29DOC_DXC_100120_IJI_102920.docdoc 5caf4fac63b4007116c090e6db0db81ad250d822e1fc251885c10d80d24b861eVirustotal results 21.31%Heodo
2020-10-29Untitled_IEMB56BPTZPZE.docdoc 38df7a8d7d8ddeec4905b01777148222f208d5030b7a44665b5fdafb5bd9ff19Virustotal results 40.32%Heodo
2020-10-29Dat_XOC_100120_MWJ_102920.docdoc 6cff316da0b26621e5b1fc3d5a85c6931a68a90fde20acf702195a175fb4ce44n/aHeodo
2020-10-29file_86399017.docdoc 4d660fe18f8a7a46884d491d3bc3632eb0d0de321fe085339324e55175c33ff9Virustotal results 41.94%Heodo
2020-10-29mes_4977432061839275221.docdoc 63df7914667bd2adc0b6e4b2db5b67f07a6154956568765321641b6dc1469cf5n/aHeodo
2020-10-29Rep_PO_10292020EX.docdoc 6da55a5f2284d9e01f507160640b2505607f31d11754ba830811661016ff1e20Virustotal results 39.68%Heodo
2020-10-29Rep_87099461.docdoc bb6a910117fc42075d0f29a1d7f63f94814e7f787223e3af617ca5018180a77eVirustotal results 38.10%Heodo
2020-10-29DOC_PO_10292020EX.docdoc 6a727c9f4dd9cbd0b46dfbe10424610f304eed108280c8e6bed80618b45fa65eVirustotal results 38.10%Heodo
2020-10-29MES_OE4248221385JN.docdoc 67bf175be626fe3ee59387c2c162c6fe009315964e0d4de581dc1a94daab51c5Virustotal results 37.10%Heodo
2020-10-29doc_W1UQH82TTRS1.docdoc 393cb1523cfa3f9dc1d2a45e467810be8447ea0f58435edf5bfd1e0938e293e0Virustotal results 38.10%Heodo
2020-10-29DOC_2377458825.docdoc b89f3ae4badac97fc44a153bfb215de77641bff4cbcbe7ddc321af38e097f2beVirustotal results 37.10%Heodo
2020-10-29file_74526306.docdoc 2ddd69d637bb813f74ae33be71c1cf20fd61be5a25f0bd5e69c296136a8d1813Virustotal results 39.34%Heodo