URLhaus Database

You are currently viewing the URLhaus database entry for http://avayesanat.ir/wp-admin/WgHVyW/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1993641
URL: http://avayesanat.ir/wp-admin/WgHVyW/?i=1
URL Status:Offline
Host: avayesanat.ir
Date added:2022-01-20 19:50:05 UTC
Last online:2022-01-24 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-20 19:51:19 UTC to report{at}parspack[dot]com)
Takedown time:3 days, 13 hours, 37 minutes Bad (down since 2022-01-24 09:28:56 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-21532258240569.xlsxls 6407591df6ce61f946e24715faa6fba1b1f3221e2baf22f6c4f5a64f1ea98eb5Virustotal results 36.67%Heodo
2022-01-2186304012156427874683.xlsxls 3ca3bcd5771a06938cc8e8c44cd2c85b794376401b469fad7e5d4b513449fa27n/a Heodo
2022-01-214014903627581.xlsxls aba8e5024172cc0cd240eda2c379e91825cb922f0c5d56d82a560dcb15eef097n/a Heodo
2022-01-21106762415854.xlsxls 5a6ae409ad46c453172d047a1b1d7685cbdcc317653d90c6a968509d1c2229b6n/a Heodo
2022-01-2112373748977196.xlsxls f35abc3dbc3faa333da128234f2b7778969e1ea5f8ef088498cc8ecf325f8a9cVirustotal results 40.00% SilentBuilder
2022-01-2121556462481.xlsxls 7efacaa6dacfe6bf20d27faaf86184458461e64165c615cede70b42cf913f8aen/aSilentBuilder
2022-01-2192813480465940.xlsxls 29111d8e5e8306e76660db292e7232ab39e901955014eede21e912c931a09b5fn/aHeodo
2022-01-212618228880722618194.xlsxls 2c9af469fcb89bb2e93d1ac70ce0bec912b78d5c3cbadccc3040c18dd03f5e41n/a Heodo
2022-01-21891480230002.xlsxls a3d7cb606d8f77987119021ad7d89fac7d02668d86ff90db65c87e54a15e73fbn/a Heodo
2022-01-21769569161338320.xlsxls e06d794800a6c8e29eaee2ec0e2ccd9f60b00c7d6c9b4a80ce605a4c156f9982n/aHeodo
2022-01-21774781084932764.xlsxls 6232ba47b182fc60d16bf5b9d41f5dc614f2f348e83414c533df7ccbfb940885n/a Heodo
2022-01-21370478682800.xlsxls fe0ea8701f0d1d1b08de951b55324c38441ca10539fdac0274a95e293448f8f3n/a Heodo
2022-01-21855032552294.xlsxls 8b24ef9d0556c1351a46d2e0eb996b21b65638c41dc79cd5b676a79bf0d18a17n/a Heodo
2022-01-2162106503139.xlsxls 9ad38c251b929edaf974d16b81d02e8b87ca16da14c4aa4eea44df09aa210c69Virustotal results 32.20%Heodo
2022-01-2105281194761698.xlsxls 3b8dc8f1f75a66d545d45ee9f4160ea99cff4e8cc3f5b265ea27736a3eabf381n/a Heodo
2022-01-214724370885.xlsxls 2847438e4b48ee5f630b8d0a3d5361bf4071aa308d8999a69cba995fa548add5n/aSilentBuilder
2022-01-212089394147.xlsxls 9eb1535c5aaefb0a3a2b583a4aad8ef65f55b805294dca339ab2f8e632ebffedn/a Heodo
2022-01-21924966830977926782.xlsxls baa950d432aeb1593d886ae1afff9dbc40b6be9828af26c7d3c72431f4fdafffn/aSilentBuilder
2022-01-21828830226853405.xlsxls 2cb043937c5838c3f91d3955127cc444ff420b74448d38395ab177b8369753d0Virustotal results 25.00% Heodo
2022-01-213509732735144.xlsxls 278e2b44764f4223799867c585d886b7fe57313055f5f82d983f7e13e1a49aedn/a Heodo
2022-01-219145999940421330.xlsxls 132c3baa8263b51b4a2847b2cd87c504be97ca43a01155b688d12d538c8ba7ccn/a Heodo
2022-01-21894382299378.xlsxls 1b6134b3db142025a7ebff094a48928647019264965031e089063502561e7ca5Virustotal results 22.03% Heodo
2022-01-214211883733.xlsxls e57baf9289180802e131633ce599fd55a0a67db3423c45d62f4a88fbf94a0874n/a Heodo
2022-01-21997127775953052657.xlsxls 46e07bbc26b054bd482b53d0528f74edc997f805951abdafb92a26dc38b7bf64n/a Heodo
2022-01-2106234994303425.xlsxls 9296f02a362c27b1e3a3b4119ede64ea52b6c0430fc70517e5146730c23c987dVirustotal results 22.41%Heodo
2022-01-214211449199.xlsxls 561f1541d1ce60dd8a10c61c54f99d83e67ed86b0f645a6e564a99baa08f56b3n/a Heodo
2022-01-2074560903136647628.xlsxls 88c13197081731462e05ef64b1c9abbdc1b85e0e573437506270137fb7b735d8n/aHeodo
2022-01-20527234994156008.xlsxls 2181997083632b17484474d7152e18c8a65175b823c871b164d15d2e20a8ae16Virustotal results 18.52%SilentBuilder
2022-01-209441280226.xlsxls c3782f393e6dca8cbded5a7bbb73789792cd1bf807f4f71cd863b12992beda95Virustotal results 22.41%Heodo
2022-01-2061387668457217.xlsxls 1aa1e797bd106f28bc73e4a09bd4d3eb7a13943ef42f06bda76c41fbca54d0ben/aHeodo
2022-01-207131815634449.xlsxls a72795a18fa2b90928f307e227b1f1a57590672870b3acc9e8cb0eb4d38bdbffn/a Heodo
2022-01-203589715559.xlsxls c48cd0ed918dfb1a8db5e5b91d904d99fea25b476cf4d9e004668e7ac5f91f1an/a Heodo
2022-01-200902515898067675068.xlsxls c670de986eae7da2182e35158c11f0354bb595a2cc5330ecf91bf8dcff6f32edVirustotal results 22.03% Heodo
2022-01-2044627262947620857155.xlsxls be65f36f82f02acc98c4863c49f827b9f166231307edd501a34202d58d78648bn/a Heodo
2022-01-20835922036109.xlsxls 94ef78ad1bae59d96e38f0f9e0b1cdfa1533ea531ee1522be6adcb6dcf389548n/a Heodo
2022-01-2037372667532.xlsxls 0450c09d5fe3db81273bb016f057664f805ea0dde2c1c53ad512324c191ac2a5n/a Heodo
2022-01-200296614983967.xlsxls 51dc452edd7c975ac8f632ad888d6cada4233c19aa061416076abbdb2ac596b4Virustotal results 22.41%Heodo
2022-01-2078474614127034232.xlsxls ab4456f73cd0d49bd6c2dc5553a33ff128bc765cb07cd47f8e0619d01735f966n/aHeodo
2022-01-200413633855768940034.xlsxls 5d372591b1e8b3107e0e57ec3a38f1d2bfd43afef5f04bee85334f46f57d71bdVirustotal results 44.83%Heodo
2022-01-20817383194892746.xlsxls b1ee7aa00b7884ed02a3f5ddc07419b6e8dd6e7382269d8cc5511f06431d5eafVirustotal results 28.81%Heodo
2022-01-2054077535000221975.xlsxls 4102ee23d580a34ad9a1790ea81e7d9739cae27b843165e0daa30b9450585db4Virustotal results 23.73% Heodo
2022-01-20464256635754155.xlsxls 3ce617ed4d5a78ba123d6463b4c0c6b8e7ea29f0800761e9559c8bf182f21afeVirustotal results 30.51%Heodo