URLhaus Database

You are currently viewing the URLhaus database entry for http://uzkon.com.tr/wp-admin/zzBi71rW0idiacKnh4UL059Zb8KTeRjhvFIlc1eCVN8/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974485
URL: http://uzkon.com.tr/wp-admin/zzBi71rW0idiacKnh4UL059Zb8KTeRjhvFIlc1eCVN8/
URL Status:Offline
Host: uzkon.com.tr
Date added:2021-01-22 21:02:35 UTC
Last online:2021-01-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-22 21:22:02 UTC to abuse{at}moondc[dot]com)
Takedown time:16 hours, 10 minutes Good (down since 2021-01-23 13:32:12 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23JTBDBR1IC03BUQ.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-23TGXNG71.docdoc 263536b327e24415fad4bafe8e171b5e86f52b4b71e983e5efda8739a2381919Virustotal results 51.61%Heodo
2021-01-23Q8GTQCRT54ZAHR.docdoc 3f67cebcc062ff44206ad6b1c356021133426bcb3a4070824b03036e36ba17can/aHeodo
2021-01-23EL22T4DY67OO.docdoc e84a53c9c72675201ca77b855375618ecae8bf0f4ce43acb1ba16b53f5a67eb3Virustotal results 53.97%Heodo
2021-01-23X1FRQL.docdoc 156db699149efcab714cb9f97ccef3b2179e9a3c53d20e6e0ad7e318e17ac1bcn/aHeodo
2021-01-23J8TG9MWBB4SRJ7KK.docdoc f967919221798935016821892199d1eaf45960045a79bf0ecb89297edf4d4cfcVirustotal results 53.97%Heodo
2021-01-23B209WOQAQ.docdoc 10dc55d6131467b2ef53cc13475499dd9f34965a9c847672f707617fc6e2e6cdn/aHeodo
2021-01-23WVXTX0KG.docdoc dcfb145c4f46a072e988cdeafc065f8116dc3b27d6bed447024677f3ea2f252aVirustotal results 53.23%Heodo
2021-01-230S0W0BD6D9YE32U.docdoc 25f478a34fccb4ec1f646b9200c1e2a858b23019bcc5b7b82a9378297f13f73eVirustotal results 53.23%Heodo
2021-01-23ILHMZEMB0D6.docdoc 02e4aa3af6d4d0a6c3f5965922f7ec76cc4302e17b7ca1c2f28601ab53f76be9Virustotal results 53.23% Heodo
2021-01-23STE8U0VZ8HL3S8.docdoc 1d131a111ffcfdeda18316ead79206237e3684246c4cb6ddc191994737f0294cVirustotal results 52.38%Heodo
2021-01-234795UWYS9.docdoc 3e2601aa7c53742f621bec3989a72e0c2db710586817cfc0067b9557e7346935Virustotal results 31.75%Heodo
2021-01-23SKCXJV35FH20JPH5.docdoc e7f279ef5b22466bf897b28fa9657446c3b897058314548a19376e0ac3a115efVirustotal results 53.23%Heodo
2021-01-23SJJ8AK.docdoc 422c84eb3c0a25bf5ea4c23eb23b048c1ff8f1dda0510c84362dc30ab3fab6d7Virustotal results 52.38%Heodo
2021-01-234PRJK6V4I.docdoc a2d525c9bd8128160c64990fa84afc4da2bea8a72cfb4ca42f14cddac1343df2n/aHeodo
2021-01-236XBD7EZZRO.docdoc dc1657890758c8563c82d9c1bdb8aa05bc4c965868247d1ac28334925e1fe12cVirustotal results 52.38%Heodo
2021-01-235GA2U5GEUUJAG.docdoc 70243026bc064de134f68a08e53d203939580d1dfbe011360f72a5df0132fdf1Virustotal results 49.21%Heodo
2021-01-23GYYLOZSXFH.docdoc b5503af31ba54c8572f00098487768ecb885e8b321974aca44c71333d9db1a6bVirustotal results 44.44%Heodo
2021-01-233JTEVQ6PD0N83ET.docdoc ac612e34cb415fcaf5c0ae462ed0e4efee5897879ee434b80354b39fe34e9317Virustotal results 50.00%Heodo
2021-01-23N9ISARZ4P.docdoc 2d59eaae9ddffa3a3624c8393e75869cab0180039bb06927734515e3c0611d9dVirustotal results 49.18%Heodo
2021-01-233H6I34M.docdoc 962dce7cc5ed4f64919264917c5f74afd1f8a3710f08274d1b6edd3653e93e2fVirustotal results 31.75%Heodo
2021-01-23H2XSZ71RIU.docdoc 56e78f5aeb76d3b2002f79b51c0344a1bc95e0c171a56f5e7bae43028543e1cfVirustotal results 48.39%Heodo
2021-01-23X7QZJQ7J5ML9RS.docdoc af3194c0b659d352c4c034514492465d714d13af99d02334148600618bfa61dfn/aHeodo
2021-01-23T3UN9OFHZ.docdoc 65d65b1d65fcab110eca51cb529feca603cc4c5bb9102dd756faa35f157744ccVirustotal results 31.75%Heodo
2021-01-23UKEI9Z269D.docdoc f241cc6276c27e057b1caf39073c1aaf230cd54bf6ecfbd7e08ec9bc0ff9a83bVirustotal results 31.75%Heodo
2021-01-23DVSKXF16BB.docdoc f34429ad75df699dbcc635b6afcd91b52756fa1d34dce852fead86e0c7eea37fVirustotal results 46.03%Heodo
2021-01-23MM73ZCQM.docdoc 04d66ed2d7e82444ce4d2b8227f03b6612a55e843e3ef434c01c93b65f10ff04Virustotal results 44.44%Heodo
2021-01-23YUAH1O4WFQMT0.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8en/aHeodo
2021-01-23ZC2ODACYIYMJ21S.docdoc fa5a2480a61176d9ef8d383ec2a77a0902bd417188b64418d1920e74505ffc1bVirustotal results 44.44%Heodo
2021-01-22T63UAG.docdoc 25eae8684f15cff80197f955eff7899e81081b1d9dd37eb92f62d7bb8bd796adVirustotal results 47.54%Heodo
2021-01-22RV38VI5TQ8BXVP.docdoc 4a53e1dd32dd8820593de18379151f5fd51cc261df4c37218b3a209525a3f427Virustotal results 43.33%Heodo
2021-01-22M3LRTSMQJWPMNBKL.docdoc 32e2565a19640e807ad76200f596703df5b37e10700339c32dd915fcb495bf9aVirustotal results 44.44%Heodo
2021-01-22OARNBUZCURBHOAB.docdoc 6776f53efed3f91af5955bfaf11f47dbf6fcf5b5a419e1bcc5a29fb89a61ea49Virustotal results 40.98%Heodo
2021-01-2227V7EWNJJAOF4R.docdoc 42152c466701b05f7fdbc32e290f3cd236d53f2a4a6e212bc675183e4a2eafd3Virustotal results 45.16%Heodo
2021-01-22IK6CEFW6XAUHG7NN.docdoc df60461aab62bf09077b67a5fd122fa46ed22f8a8d184035786a7ee3be961927Virustotal results 45.16%Heodo
2021-01-220Y1A43NE5U.docdoc 5baed32dcd265a53a8f5f4182bfa79336ffa1acc17f1ab71e8387529a82b10cdVirustotal results 37.70%Heodo
2021-01-2234N5NU.docdoc 8af280e70fb92f35455e9f18296c0fbaae42288517c6925a9db673a9368e9bf3n/aHeodo
2021-01-22HWRU0QNBNCC5.docdoc ab6d3be4c24da3e9c1df9e970119843a19dd372e08d3be797ce636117a71cb15Virustotal results 36.51%Heodo