URLhaus Database

You are currently viewing the URLhaus database entry for http://academykar.ir/wp-admin/GcLuP-qRirivfWcIXBExj_LvhJCiBZg-gY/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:173326
URL: http://academykar.ir/wp-admin/GcLuP-qRirivfWcIXBExj_LvhJCiBZg-gY/
URL Status:Offline
Host: academykar.ir
Date added:2019-04-08 18:05:37 UTC
Last online:2019-04-09 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-04-08 18:06:30 UTC to abuse{at}hetzner[dot]de)
Takedown time:21 hours, 0 minutes Good (down since 2019-04-09 15:06:35 UTC)
Tags:emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-04-09354533798201_Apr_09_2019.docdoc 48172e9c6e67f30e18b821c1232b558184327dd6dad274ff70357426d3e984b1Virustotal results 21.05% Heodo
2019-04-0975008007875_Apr_09_2019.docdoc 58a7c668443f637dde06c862407492a918a3c4aa019591316475233f4093c7b5Virustotal results 22.03% Heodo
2019-04-09966863768664_Apr_09_2019.docdoc 69417bd81b936a1b0840896d2c298a04603bee107b33c01403dc583f0bcbf81bVirustotal results 22.95% Heodo
2019-04-098526289008_Apr_09_2019.docdoc 1492b74a6c27a3e43a7b7d7e79b1b54236b9910818d5da58bc1597dc55c375d9Virustotal results 22.41% Heodo
2019-04-09696060945562_Apr_09_2019.docdoc 327caeebe6a915305f2ba0ab6bee456b10d2ce721e2e477dd7861a4975cbefafVirustotal results 23.33% Heodo
2019-04-0972114532877_Apr_09_2019.docdoc 56c1d6491690a1717009cea3f2821ef12fc70a28b64ad46dbdfead0edda1aa4fVirustotal results 22.03% Heodo
2019-04-090023897107_Apr_09_2019.docdoc 83ec56a0cf16cf96b524c41f2445c3e08100ead1717b20175fe5c09c0b2a05ceVirustotal results 24.14% Heodo
2019-04-09640994677538_Apr_09_2019.docdoc d564f6b53a1f701b77041ef9fdefe0ed83303b708db09473aad0a394124a20e3Virustotal results 23.33% Heodo
2019-04-09782936616347_Apr_09_2019.docdoc e433d3482cc74b781695031111d40fba1dff06c9d46ce3346e6c5dbab90da061Virustotal results 23.33% Heodo
2019-04-0988268404950_Apr_09_2019.zipzip d78ed59f0b032474d83313b8a7ecbf563a55dacd992f0357d8bb99e9bf4cd45bn/a 
2019-04-096333199646_Apr_09_2019.zipzip 775a796af5d536ff5ce4bcb9cba9bb96789f5330ad6fb8267b298b11a539cf7en/a 
2019-04-0969608746077_Apr_09_2019.zipzip ab94ecff0a47329909042ad74f35b59a625ab2d0cb84ab422e36892c2eca0cccn/a 
2019-04-09435026529203_Apr_09_2019.zipzip f2af2f8dbbabc2dea28fa16ff1e4df31e3dd3444c2c2ad4b6dedb68767c005a5n/a 
2019-04-0982897433945_Apr_09_2019.zipzip 50d035fff02af69151b3f6d23fa089f18c6a6a7b4ec6e4ba89efc0a08e510b44n/a 
2019-04-097226958270_Apr_09_2019.zipzip 5ee67a1f3949aaf63d1d3c31dfe910ce4e70abff1e4ffb0b4db43f7ab2ad9840n/a 
2019-04-09178147081167_Apr_09_2019.zipzip f2a877a3cad40e8bf99d8da3e15773c840ea8b3f3e592d1d71d8d92c31aa7dfcn/a 
2019-04-09952190391533_Apr_09_2019.zipzip c14b92e4312523106a92341bbc2a1cc4fadfe28b7dabd5823a62ba5e3cb749efn/a 
2019-04-0933352351033_Apr_09_2019.zipzip 834755dca80ca755c270aa752287e127e264b32ef03dbed96565ae629d5db612Virustotal results 19.30% 
2019-04-0980790396624_Apr_09_2019.zipzip 4c9fc7598fb7c63cc2104042c4f503a5580f5b6b15948ecf5c60bf0f66528a0bVirustotal results 20.69% 
2019-04-0993261488650_Apr_09_2019.zipzip 49dcd2d8e2cd3c8c14b6e57b7285553421185363e1c43217af6d84a28a032ec2n/a 
2019-04-099317691549_Apr_09_2019.zipzip 190064f8e33c252b82a72d2bfdb474063b9086cb4b10058a8eb7831896cbed4dn/a 
2019-04-095389121735_Apr_09_2019.zipzip 4490cc887df36dd5273e52131cd0a1faf172c14df939faf11ac083aecd97186dn/a 
2019-04-09626556162386_Apr_09_2019.zipzip 71992ba7975b62aecb0e48986dc3e6bc55d14039e9ed0dda5070292c43d358c6n/a 
2019-04-09096055836774_Apr_09_2019.zipzip c00714c6c061e4a109f1e1eb84c4bb9dba2f8e6f47cb1453a548bbb8b96c075cn/a 
2019-04-0998693739878_Apr_09_2019.zipzip 1fac0584ad3e879df87a4da550dc72e85a6d047b7b0f75ae978fa44225dcdd78n/a 
2019-04-0908307178583_Apr_09_2019.zipzip f71ccafa5fdc89e548c2aa82679616ab0356db447f21fbd3e7514e1932049dbcn/a 
2019-04-09450325371927_Apr_09_2019.zipzip 630204782bbadc6360da8f6ecaefc08aacc3dd750373821806ae62961e77a983n/a 
2019-04-0972963623774_Apr_09_2019.zipzip 2ac3f131eccc4737e500e2536c8b14010b305f5947c2dc4c2cc38663a0393cf7n/a 
2019-04-084279186283_Apr_09_2019.zipzip 755b512c8e5a6cc953b9225b789b677fdaedeb646c010113de82f2552652f06fn/a 
2019-04-088899816037_Apr_09_2019.zipzip 2581470a6f49ee15e0e71523a37934f1ae434bce4bb8b344a942fcf82d8c1399n/a 
2019-04-088441689418_Apr_09_2019.zipzip 11fc705a705fbac04bea12b47b468b2a6c764d32cc193cf6c30acfb5e849c08en/a 
2019-04-080842917589_Apr_09_2019.zipzip 3153f3d26ea67d1a39bb0157d2e5b6b253c40ffa4ce3f4a46bb2db657fde871cVirustotal results 17.54% 
2019-04-0813818659491_Apr_09_2019.zipzip 87d830e12fa5791010664bed32c5eee4a9a47b30469b00ddeb336337435451f3n/a 
2019-04-087334787431_Apr_09_2019.docdoc 8f6e3bd0ef1e970e2881184b0806c316cab3760e7886e571acdad3561cf92b3dn/a Heodo
2019-04-08505600415272_Apr_08_2019.docdoc 02fc35394a89b8a2010eac0d1e4a00fad1c3178aa10c08c86fa3068be23d244cn/a Heodo
2019-04-0851789375099_Apr_08_2019.docdoc 99c8a97069d1dbf1dc45f883707fe2c8ba1f4d9893dc2b921d9b0061e370ae55Virustotal results 31.67% Heodo
2019-04-0843684758637_Apr_08_2019.docdoc 68cc5c8e494a645b09fc0d1f9e2e9be8c2e63f982558fcde33f36231341096d9Virustotal results 31.03% Heodo
2019-04-08184890179731_Apr_08_2019.docdoc c1eac5382d05ee0b363900402bd8bc2ff0aab6192c34d029d61796e4f0bb1143Virustotal results 31.15% Heodo
2019-04-08Statement_0604199299_Apr_08_2019.docjs ffbe73591031973cb52f6950ed61b168a0f0bda69f004db08846dfc1bd1d1920Virustotal results 56.14% Heodo