URLhaus Database

You are currently viewing the URLhaus database entry for https://www.moharrampartners.com/requestion/73057-38562390/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1972206
URL: https://www.moharrampartners.com/requestion/73057-38562390/?i=1
URL Status:Offline
Host: www.moharrampartners.com
Date added:2022-01-13 00:08:04 UTC
Last online:2022-01-14 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-13 00:09:09 UTC to abuse{at}fastly[dot]com)
Takedown time:1 day, 21 hours, 33 minutes Poor (down since 2022-01-14 21:42:25 UTC)
Tags:doc emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1423466593KILNOLBSZD_0674.xlsmxlsm 212776ac19bae91f65534fa3995bc54aaea2fa402380cb3d9aefb4cfb6a1a302Virustotal results 29.51% 
2022-01-1443316298_505790.xlsmxlsm 5cff33ed1b7a4ed8ef30baa3a47546681144826e18bdc2082c9676a4f32c4bbcn/a 
2022-01-1339231474.xlsmxlsm b92219911245e208dd5089a02ad54181c2646a905a59ef38fa3919bb0cda98a6n/a 
2022-01-13nfKpX_012459.xlsmxlsm 236a6d0de83a050c7865dba3da1e5ec1e210668e47a23499a833dd10551e9087n/a Heodo
2022-01-13r_06.xlsmxlsm 523f8798637989d56a2dc113543544950f4c2a5d11b2bcb6d73e96b2c6182f86n/a Heodo
2022-01-1362871077.xlsmxlsm b935e9ee2e3088640c3924e7434607aa3af911123be613e2f1456c19afb23c9bVirustotal results 33.33% Heodo
2022-01-13vydk-55815.xlsmxlsm d652c467b10eb9cec0d36d73accbe00a2d4704678683e8ab611e8de487e34cf2n/a 
2022-01-1378226_989025.xlsmxlsm 3e8ac5b89fdb8697813438a75aec6df15ad029e5c499a023f5bc7a209ff1b13bVirustotal results 31.15%Heodo
2022-01-13015ANAV_315675533.xlsmxlsm a8b105b33e639fbfaf784868e4c8b14639d7e0dfbde96bb5071fa8d7160595fen/a Heodo
2022-01-13DHVVF_1.xlsmxlsm 26b70659f75983434e092f76f7a14aed02f68ecd203b7a90cd1ed6ca1ef8bbd4n/a Heodo
2022-01-1381723-48957386.xlsmxlsm e8f7635b18c4c4839e484cff628d95af7c590344a8639630639c5cc6e0afae6dVirustotal results 28.57% Heodo
2022-01-13dfg_4218045.xlsmxlsm 07fddbd97e1846aa7ef2fae79ea0d177a89210725b1a66a8b52bb066cc36bb1en/a Heodo
2022-01-133804233_7.xlsmxlsm ca6662f6a52a16a294b7d873a1f4b60f6ed054cb1cbaf3207081f30380c573e2Virustotal results 20.63% Heodo
2022-01-1399929999-7.xlsmxlsm 80f7072eb1b894cec06813c3267356f693ff21d0d1f116d1cf53d5b8035277deVirustotal results 16.13% Heodo
2022-01-1387506739_52136665.xlsmxlsm 8e8824a855908e301cb873fe67e37eb4af99b32f75fb1ea8997af913540ece02Virustotal results 19.35% Heodo
2022-01-135947369_476004.xlsmxlsm 18c55721fbff7b023ffab344abd151b7627bcdac0645f7074a1ad6b311828779Virustotal results 8.33%Heodo
2022-01-139864068_26600238.xlsmxlsm 1463c17a7f06236bf5e8cf4ce7964cc17b2eabaedf00822387824b45f83021b5n/aHeodo