URLhaus Database

You are currently viewing the URLhaus database entry for http://istanbulhaliyikamacim.com/content/I9Ogfopdi7/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:972174
URL: http://istanbulhaliyikamacim.com/content/I9Ogfopdi7/
URL Status:Offline
Host: istanbulhaliyikamacim.com
Date added:2021-01-20 10:02:03 UTC
Last online:2021-01-21 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-20 11:38:03 UTC to info{at}veridyen[dot]com)
Takedown time:12 hours, 42 minutes Good (down since 2021-01-21 00:20:51 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-20tZBPN0CZI9TgOH.dlldll 03ff40768f2c5dfb8c60c977b173ab72abc0932ccd13d139115bf7f0ddcdb323Virustotal results 31.88%Heodo
2021-01-20XvEmFEWmz.dlldll 20f71553767657a38c91efce8bdd0732805559fcbee00cc235db495a190b886dn/a Heodo
2021-01-20Yboso1xrL.dlldll c8d7d2fc6b5ca847e7dfaa0d7ffa45809a092450119577062ba8495978f1f9e8n/a Heodo
2021-01-20Mb3Py6RtGb6lhRN.dlldll 131c768763b68604e5b212da0a8fdba6e9f56941a83303747ab2203dbf120dedn/a Heodo
2021-01-202s2i.dlldll 4c3ecbbded53c93a1725ba55ed52e89e5f9d44b0d1ce2c6cc36348cdb348ae9aVirustotal results 42.03% Heodo
2021-01-20rCGcfdTsS.dlldll 94c57891f1be58df39b47efe924c5fb9cf19bc41aedd4e6b4869dfa65f5fa556n/a Heodo
2021-01-20Z.dlldll c9042ef88d5861e395b85700525c9fecc95c2b70e1604f4f386758f1225c8921Virustotal results 42.42% Heodo
2021-01-20n7sbVX8dikYHG.dlldll c689dc488d3c132dd53c577aae1bfc0eb8b5c487833e40ba2b15d23cb3336b7aVirustotal results 42.03% Heodo
2021-01-20wHOaEw.dlldll ad01cfdd80673eb96d385ee7251e06f42472e85782cf13ef0a2332157089af66n/a Heodo
2021-01-20j16pYlAYUiz8R22WimAg.dlldll 5074147a00b8045e55ba62a9b729d580bf58b7ff576f849f7e92d1e4fee63e90n/a Heodo
2021-01-20UvlQP5t7USfWBspj1oGx.dlldll 1a9ac9874c6185363ac093a8a82dec27f0516cd9d89775530bfbe4fea8910884Virustotal results 41.18% Heodo
2021-01-20CrXVo6ScKmsiqIaAm2A4.dlldll 94d36b24591c518221b4d575e5e614978d6757b9a915f8d86ae20d9da62d3a32Virustotal results 39.71% Heodo
2021-01-209OZevvW.dlldll 52470a9f927c84b09ab53d4d67207f202a9bc83207278e6e9d54ded856f7e14en/a Heodo
2021-01-20dMBzOwxpiDHHiE6k.dlldll b5c22a79f9574b36002f1259cb5ca623529f3edcefd285f5e2d3b9dacb3fe2fen/a Heodo
2021-01-20I.dlldll 62bb5f24f363af412aa659cbd4a13134f57c6e399da58bdf2adf00a6a00141f8n/a Heodo
2021-01-20mcN8aPKK.dlldll 232e77f4ab21c9846f8a338d6e08ff9213e473225135ed7eaad2a6e6d6ed0b5cVirustotal results 37.68% Heodo
2021-01-20PSr5bGG2.dlldll f81b3545827374b846451d8096d5b0c8ecdde728072edf4250b462afe3f43394n/a Heodo
2021-01-20Qw4EnJnebawPH33.dlldll abaa8ead9d435304450e0212f6fa5adf442ab52b8dd45107425c4c13b84e746cVirustotal results 36.23% Heodo
2021-01-20D56tOLBTI4iPx.dlldll 0f86f4d3b0a87b698584d54e5802c4668ad80b7c6997a129c956668d9310b223n/a Heodo
2021-01-20RjYq.dlldll cf830001502bdc2a51d1eee6a8cfd886fb6834bc6b4a0fef05bf7c92d63b9336n/a Heodo
2021-01-203Tm3SWH61e.dlldll 0d99b6550461a5d55ab5b24ef9b7b16d50f099acfba2d62aa2596201cae299fdn/a Heodo
2021-01-20lSIddugjYfCBXsSyFkg.dlldll e275f2a380b04c64ba33e2c658c77547aa82368e2d10d4fbe3682e1d72a6b1d4n/a Heodo
2021-01-20avjYxr3FGQvChvMc9OzR.dlldll a4268faa2e60e81d7d7c9c52012e858c0fdcb2951f7c6b3f9b9037c75129dc32n/a Heodo