URLhaus Database

You are currently viewing the URLhaus database entry for http://gundemhaber.org/EN_US/Details/112018 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:80029
URL: http://gundemhaber.org/EN_US/Details/112018
URL Status:Offline
Host: gundemhaber.org
Date added:2018-11-14 15:58:25 UTC
Last online:2018-11-26 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-11-14 16:00:06 UTC to info{at}fiberserver[dot]net[dot]tr)
Takedown time:11 days, 18 hours, 3 minutes Bad (down since 2018-11-26 10:03:42 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-11-23eFILE-2715613263.docdoc 6195196c46c199f782c906cf8bbfd89e24ee3c77dcd4648675cf0dc30bacedefVirustotal results 55.17% 
2018-11-16file-596864861381.docdoc cf53fd4d67bef004c93368ab5b0a206187c3e46607a103e2fe17107da84b3f6an/a Heodo
2018-11-16DOC-9666470926943846.docdoc 8e57c4cc83559c365ee46a558904127bd85f6d392ea649b580f4077150bb7253Virustotal results 25.86% Heodo
2018-11-16eFILE-49121682305826.docdoc f26e16e76f58ac05c4b6c80efd54a0da2de37bd3e2a3740e8b35f46d29b4bc0an/a 
2018-11-16Untitled-97780274444661.docdoc 65172c366059deb25a4ea09c26cf37d4a870bdad43f56d5592ab92a8418857dcn/a 
2018-11-15doc-5512696135420.docdoc fd83a337f59204f26517ca8e46cffdb57bb1743da265f5e7459c2687678c35cdn/a Heodo
2018-11-15FILE-26692507654.docdoc 36e4e66491a3a766c20092065b29b120760c13558f0ccf039068215e938a0eb3Virustotal results 22.03% Heodo
2018-11-15DOC-32222428802440.docdoc 1d6fa30e6c19936ebc423db16a98eb9c4361d59bee48347ce655d3f3240cce44Virustotal results 22.03% 
2018-11-15file-3751693227317422.docdoc ebd855763c68aaaab46f85996f5923d70ddecec3b72bd4ba40024f18fb430397Virustotal results 30.51% 
2018-11-15eFILE-43392473596.docdoc 8046bbabbec42f28bf3fef090cc026e847683f36f340d71732009edfc6ebbb76Virustotal results 25.42% Heodo
2018-11-15file-12735502541374.docdoc 72b6a198cdc160c0fded64b3999d10670f88d2c72951ddba4cac13f1cca963d1Virustotal results 22.03% Heodo
2018-11-15FORM-249006791943.docdoc 83987b42872150d5ab352c35fab36f29561642f3383d8501cbd430f3809b6f60Virustotal results 22.03% Heodo
2018-11-15file-0961504458.docdoc 4bacae6838115916aafe7077a78e68a4f0804f4ba7a98731069cab75c3b0d1d3Virustotal results 22.03% 
2018-11-15doc-57927383583961.docdoc fa9c688eca6d6bce62daa188325f51aede4f4342c23b9dfdb4c5592ee6b14f9aVirustotal results 19.30% Heodo
2018-11-15DOC-84382340219.docdoc 576e0a6ed02651d2e06a7face89a78f9f5b5ec24c7dc2c2fecc0bb676747888eVirustotal results 15.52% Heodo
2018-11-15DOC-0191086221.docdoc 4d12b8d73d68c14c5c765906aaa07aea20839a74c9cd0f00f926d7c5bfda9edfn/a Heodo
2018-11-14doc-73729357659714.docdoc e68125b87c26994e9356cc2bc7e31ae6e3a16a8ec86975307efb481e1e927391Virustotal results 23.73% Heodo
2018-11-14Untitled-32457059826.docdoc a62bad38fee41715cddcba7bc9828dd86de629762b21cdc86eba7ab86e39ae34Virustotal results 17.24% Heodo
2018-11-14FILE-808989196226476.docdoc 43099c7f72b6aff08e3ddb1566e32735c66b1751500fff124af6e1a761c1ccbcVirustotal results 16.95% Heodo