URLhaus Database

You are currently viewing the URLhaus database entry for http://dibaanzh.ir/wp-content/secure.myacc.resourses.net/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:167781
URL: http://dibaanzh.ir/wp-content/secure.myacc.resourses.net/
URL Status:Offline
Host: dibaanzh.ir
Date added:2019-03-28 15:20:06 UTC
Last online:2019-03-28 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-03-28 15:22:02 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 hours, 20 minutes Good (down since 2019-03-28 22:42:17 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-03-28eINVOICE_FILE03_2019_I8_0-39_74528.docdoc ab16d26f1b07001aa8da1ef5952f44b869e6a6a5b45bb7c6b558340616642ea8Virustotal results 20.69% Heodo
2019-03-28INVOICE_DOC_E3_75-78_B611.docdoc 85ce0b6f11357619590d599a56063126e9610c6b3b19d2b6ca37cf9cd8a532bdVirustotal results 20.34% Heodo
2019-03-28eINVOICE_FILED6_2-11_V882.docdoc 30104a704f45e7021ba42f9e461fd8b4e6fb7b0497bea2ee412257d6713fbdb4n/a Heodo
2019-03-28UNTITLED_FILE_W1_2-92_Y375.docdoc 7cad22cb843c2fcfd4470d5d9acec7a6ac9d6226b210fbecc6fea1ce718800c7n/a Heodo
2019-03-28eINVOICE_FILE032019_S1_68-19_L5668.docdoc 17ffb9c6d2c9155fd3f429c00dab716e0500191cbf9786b46073703468fa0a4bn/a Heodo
2019-03-28UNTITLED_FILE_O6_3-69_D7208.docdoc 18b357e0fabf12c46dfb3407731f052b440d02695454fa68a86a3df374c54742n/a Heodo
2019-03-28invoice_number-201903_Y9_92-07_J128.docdoc 58c481a9fba100943b37f867b2eacad9269d46b7ad93dd4eb68c86c8ac885616n/a Heodo
2019-03-28OPEN_INVOICE_M8_9-79_K5202.docdoc 95486e2d7bdf753ab5dd9caeb51cbb91a06f11521db0fea52573e902a03da112Virustotal results 20.34% Heodo
2019-03-28eINVOICE_FILE032019_L1_28-80_38360.docdoc 7699b547d21e5fff5a674fa0334b2b3c99df4028409b34d4c34400e21cb38ddbVirustotal results 19.67% Heodo
2019-03-28invoice_number-201903_J1_87-96_U9708.docdoc a30a91cb7e147735f4ea59d4755368febe6fe0e2819c8a00378c66a124b2f97aVirustotal results 19.30% Heodo
2019-03-28NEWFILE_N1_3-54_A5332.docdoc ffbf6b1562b8ff882933b9ce4dc9234fd6fbdf6e5be7e645bc6e2461159929bfn/a Heodo
2019-03-28M5_6-74_T980.docdoc 3005821f84ddac51706f1b6fb7b12cb6a20d300c118944476eac31974020bcaan/a Heodo
2019-03-28INVOICE_DOC_Q0_1-27_E278.docdoc aa0ef3951a39c86c0395dde80d57272def9b8756952204304bf9ed79d85cc221n/a Heodo
2019-03-28P3_14-53_H9398.docdoc cf5666bf169d06e74114fab1a59b26f962e97fb046d101fd3ee60e745b22a2f7n/a Heodo
2019-03-28invoice_number-032019_Y7_34-63_8184.docdoc beae56ddab7d410ceada376488b8752736acc8d25989c56aa9fbfb3b6f304a05n/a Heodo