URLhaus Database

You are currently viewing the URLhaus database entry for http://swarm.ir/bi/xUeFCCUfopNehO/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:205303
URL: http://swarm.ir/bi/xUeFCCUfopNehO/
URL Status:Offline
Host: swarm.ir
Date added:2019-06-01 00:57:04 UTC
Last online:2019-06-01 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-06-01 00:58:03 UTC to abuse{at}faraso[dot]org)
Takedown time:6 hours, 37 minutes Good (down since 2019-06-01 07:35:14 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-06-01FILE_6830601971US_Jun_01_2019.docdoc ef62880b29c9e9403633bfe2c0572d75e5d9ee3fa4fb698697dceb9efc99ec3dVirustotal results 49.18%Heodo
2019-06-01Document_930102412657US_Jun_01_2019.docdoc 570a32b3a97f12b17246e9940817c9c72ee63ac383f6983e342e09f79debb17eVirustotal results 49.18% Heodo
2019-06-01DOC_234374891031US_Jun_01_2019.docdoc 7c4cc9d295547a0cef91a556f42d21a5e87964fb2272c8a33fca00016e71ec4cn/a Heodo
2019-06-01INC_288551140957US_Jun_01_2019.docdoc be08e4e434bf6ffb686cc050d2d014fbc47fdfa0ba3abbd8f33b0aa11ab2d23dVirustotal results 44.44% Heodo
2019-06-01Document_39128184758US_Jun_01_2019.docdoc f5f4295f963a3f3ac6e0dc5f1b965821609ca045e1ee63c8687225310155887bVirustotal results 45.45% Heodo
2019-06-01FILE_58818808122US_Jun_01_2019.docdoc e5cd9fb3599e112d7f690ec64cc87eaca100d75fc46123812fb4a690ad71be55Virustotal results 48.39% 
2019-06-01Document_6139156473US_Jun_01_2019.docdoc 015d2e25bab599d1a78b8d7f021f29d07fd98d092a4d8558171c21b2ff2d5cf1Virustotal results 49.15% Heodo
2019-06-01SCAN_2747079447US_Jun_01_2019.docdoc 1c2f25113cf027732770e9f16c727da8ed92c9503034e0c7642bf26d939a8c84Virustotal results 47.37%