URLhaus Database

You are currently viewing the URLhaus database entry for https://kitaplik.bilimvegelecek.com.tr/wp-includes/IQDSf4uv/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:769011
URL: https://kitaplik.bilimvegelecek.com.tr/wp-includes/IQDSf4uv/
URL Status:Offline
Host: kitaplik.bilimvegelecek.com.tr
Date added:2020-10-30 10:38:07 UTC
Last online:2020-11-04 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-30 10:40:03 UTC to merkez{at}aerotek[dot]com[dot]tr)
Takedown time:4 days, 13 hours, 22 minutes Bad (down since 2020-11-04 00:02:55 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-31FILE_42296134.docdoc 858159295a83a85ce85a8e18a4398873eb02dfa32012325f963ab2de57c8c0aaVirustotal results 56.25%Heodo
2020-10-31025878435425.docdoc 4ea3b44401112b07c8579bc245bb22ee9c40c153200538038bb8bc8d53f6b632n/aHeodo
2020-10-31Mes_IM2575865096BM.docdoc 369deae0aea3bfa6e8367f494d149dffe4c9a5f821bd8270c06016f0e6923227Virustotal results 52.38%Heodo
2020-10-31PII_100120_WXT_103120.docdoc c21fd3f4bfb11db1fc709bca4079eb7f97b6001e5695a430566b61e5e630053dVirustotal results 50.00%Heodo
2020-10-31Inf_PO_10312020EX.docdoc 780ffddf2dd1fac9d6fc091c707c84751ea2180a253431c3b4700989bd3fc21cVirustotal results 54.84%Heodo
2020-10-31doc_VQR_100120_WMF_103120.docdoc 0ab261e8e21a48f3423dbe6d18512f5e2afbd09fd31af5d5c45d2814c2c709afVirustotal results 53.12%Heodo
2020-10-31file_TD5234660602AF.docdoc c586bc35250934f22523a7bee6291bb320a8c31a1c2cda2689c51a9a65796524Virustotal results 52.38%Heodo
2020-10-31dat_753369332.docdoc 3f1565ba4e9c93cf71b5b5a3f3b16869e7c6a7d86a837a32db34f1f0105e3aaaVirustotal results 54.69%Heodo
2020-10-31FILE_MR0875856374YF.docdoc 12ef90a776bc1f4ae05962313e6b3711ec5211f8ba450527585d2da80c2d03b5Virustotal results 51.61%Heodo
2020-10-31mes_5520507617162224824.docdoc e054d39b0aac7c2b6c6b76bc40435c1d0ffca154764349deefbc46f9d6ba453bVirustotal results 50.00%Heodo
2020-10-31file_34999808.docdoc 60e4646ea5fbe72e1daf6f3d015b37205898569b303dcfc791e0d02a754c9bf1Virustotal results 53.97%Heodo
2020-10-31Inf_56449662.docdoc 9210f9032280641d080e5abde6a49a3032839cec91f757f2469a4eeeb4080afcVirustotal results 54.69%Heodo
2020-10-31Attachments_54882584077.docdoc 26b30e58ed2342d042367ba0487873439d5c9c28920ddd000bb94b3eac79d94dVirustotal results 54.69%Heodo
2020-10-30doc_DHX_100120_NBQ_103120.docdoc 9918cf9fc52a9d19fe483b17d847fc7fa23d4fe150c5df91abb94e61e932cf1cVirustotal results 53.12%Heodo
2020-10-30DAT_KI10S760YPOOM.docdoc 6a8e52f8792ecae215c55e1f73b2895cc0b304ee39db3908356b71ac38722b0cVirustotal results 55.56%Heodo
2020-10-30Doc_BT6465066233BW.docdoc 1ce95602afd3133a2b2f7ac1df3290e233ba27b2f2b71d6a1b407cda2cb4ca4dVirustotal results 54.69%Heodo
2020-10-30Mes_PO_10312020EX.docdoc b79376701bfc97b082e9d8d61f6886b399692a2b154c6095559ab1da86e4c518Virustotal results 53.12%Heodo
2020-10-3040732743.docdoc 5041a2eae4b04f23df9804031b3a30e815e0c2310bf42d82176cb89618617933Virustotal results 55.56%Heodo
2020-10-30LIST_26647765.docdoc e08ab7ce7103fb7f881b565ba2688430333bb18fd593efba0f991a3e6994b907Virustotal results 54.69%Heodo
2020-10-3020661472.docdoc cc0614f4e21c1d63a80e1ddecfd591353e15aa849f754be9d8b709cc6e9841c9Virustotal results 53.12%Heodo
2020-10-30Attachment_04483217059.docdoc e37545649e9e7c9250af64a93a2fa3e37fd90ab7f9c16e96b4469290f309b52bVirustotal results 23.81%Heodo
2020-10-30mes_0430867177064417372562642.docdoc 8cfdaf7b364045782c53fe4094501d577114deba01267ff8e074d14d7d27833bVirustotal results 23.44%Heodo
2020-10-30Untitled_43276575.docdoc 75ca20340c21dbd94ba3ec4c8eeb14f3a78e68a955701cbdc754c29163674a3aVirustotal results 33.87%Heodo
2020-10-30file_67771796.docdoc 1e363452c2a67d40f01390488a99f68ce6fab805b45eab93ee2db2469bf1b05fVirustotal results 42.19%Heodo
2020-10-30Mes_JH1195270451RE.docdoc 5fc665986d6e0e5763554e4d9f9db9ccc61b2c20fc408e955d286a458f622f48Virustotal results 47.62%Heodo
2020-10-30Arc_XT2397758905DR.docdoc a24c2997fb1b27e97d94e67fa2efe79081cb3329192ef55f1765271679241990Virustotal results 46.88%Heodo
2020-10-30doc_677529430988031560726.docdoc 8cc9b34e2f5d86937d174dd238bb8b4e27adb981bb7b44078e619ad9a438d218n/aHeodo
2020-10-30Untitled_HLB_100120_OOK_103020.docdoc 877bcaa3bd3bcb6081fbcc746a0bc8b28f01961c1061adaacae5ae875457fb70n/aHeodo
2020-10-30Doc_PO_10302020EX.docdoc cd7af62b6cdbf35cdd60b11e87084e9e0c08ae9a790abe502c3a9d5a62c4e8d7Virustotal results 42.19%Heodo
2020-10-30PO_10302020EX.docdoc b75935a097651bf38a480763eb4c9973e89974666e00bb021c25e21b7932c0eeVirustotal results 42.19%Heodo
2020-10-30FV_62961685.docdoc 6e473a77d345ee6f0f3c0371d26f9b187bf9e59a7d4dc18956b24db4f264fe49n/aHeodo
2020-10-30rep_5428386902919847677.docdoc 4eea09772ca2174c6dee225349ae15f55b9e8a91ac3aed6f961a4815ea86f462n/aHeodo
2020-10-30REP_88357887338866.docdoc 005b9b3299e128a79fe21a998375eccf999a16aeee899a934ee2cdf578137d13n/aHeodo
2020-10-30Mes_53174945144977941958.docdoc 2c35c7c2a35e6c0d057d6a29697d6caeab76363a0040219edbed385309cb15f6Virustotal results 42.19%Heodo
2020-10-30list_3ISB7RD1.docdoc f47484c61c7b2b0541690f5cfb219d2efe962b5204064435481f99e8ba92f95en/aHeodo
2020-10-30DB3954799576CH.docdoc d6f5c2f6c473a5df7285cae32d8806ee2c6ee513400416463c34c7f6b3dcc703Virustotal results 42.19%Heodo
2020-10-30DAT_PO_10302020EX.docdoc 0a44f2d88bdf47cd0c75648b07e6fd7ac80b20ebbe7f6509fab11f28872ae12an/aHeodo
2020-10-30U_NIICD57A.docdoc 6263b8ea9431ac48bf402098737c84a9cf49c01488319875132ef15ef7d5c6e7Virustotal results 34.38%Heodo
2020-10-30C_LM9YWTJBU.docdoc cdb79e413c85c2fa4724ac77b430ab5a6a0c770f7f6a640fec00d946a93f5e09Virustotal results 31.03%Heodo
2020-10-30List_FQ3773228681RX.docdoc 96636e8803958a85be6974b0fc6c91e24526ae529a00c31dcfdbf3ed761c5304n/aHeodo
2020-10-30Arc_NJM_100120_RIX_103020.docdoc 39991605b314bb39a573ea29a1b1cd2904615afe76292c0f3b6afac181a0d6d0Virustotal results 26.56%Heodo
2020-10-30UNTITLED_11928615.docdoc 665ca5b6b8e24008d94bd73e8fc3862a558d2074f35ab952eb016e2ecfb2c125Virustotal results 26.56%Heodo
2020-10-30OCP_NJ3JXM0675GY6XH0.docdoc 6a56325cee2a2a8f5e25ea794eac07e6822aafb9390f367bcc90bccc80090aa6n/aHeodo
2020-10-30DQ78X7RQ.docdoc e9b3a372797bd2c4b3b4a43d2d3920c52c30f35e2cee94a34ad17f16cb5c5eacn/aHeodo