URLhaus Database

You are currently viewing the URLhaus database entry for http://www.dolunaymetal.com.tr/Amazon/En_us/Clients_Messages/2018-12/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:98324
URL: http://www.dolunaymetal.com.tr/Amazon/En_us/Clients_Messages/2018-12/
URL Status:Offline
Host: www.dolunaymetal.com.tr
Date added:2018-12-20 15:45:09 UTC
Last online:2018-12-20 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2018-12-20 15:46:04 UTC to lir{at}gridtelekom[dot]com)
Takedown time:3 hours, 29 minutes Good (down since 2018-12-20 19:15:38 UTC)
Tags:emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-12-20this-site-is-virus.docdoc c2e393ff568f4a87ce48011f10664138e569710f56ddc0462aa7f36bdad5ecadVirustotal results 1.69%
2018-12-20ORDER_DETAILS.docdoc e0a32c200e279334cd4303c0ba0a793c949228c9f8258743b552cbbc5d3952ffn/a Heodo
2018-12-20ORDER_DETAILS_FILE.docdoc ca92ab5f27c770cb030a1a9cfbd192b62abdcb6b0bed4c1a3e4c937162979732Virustotal results 28.33% Heodo
2018-12-20eForm_Order_Details.docdoc 1a866243f492e5bf2d88ccf1056345222d296c404d46a4583ed836794e26b6acVirustotal results 28.33% Heodo
2018-12-20eFILE_Order_Details.docdoc 2dda9bc53538f361948d64aab5fba43b6446b8f8e1d6b21530bc5ad037dea410Virustotal results 28.33% Heodo
2018-12-20order_details_file.docdoc b76e20536a3e5990bb0712a4ad0f113b7443d8025f53f6ad7c4eef42210562feVirustotal results 29.31% Heodo