URLhaus Database

You are currently viewing the URLhaus database entry for http://armannahalpersian.ir/3H5qqUOB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2399941
URL: http://armannahalpersian.ir/3H5qqUOB/
URL Status:Offline
Host: armannahalpersian.ir
Date added:2022-11-03 21:37:11 UTC
Last online:2022-11-04 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-11-03 21:38:12 UTC to abuse{at}hetzner[dot]com)
Takedown time:19 hours, 25 minutes Good (down since 2022-11-04 17:03:28 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-11-04Mgq.dlldll 31ebb16af4e3b18ef7574872984df9ee150851e9fd54a60f060727a1ec48838dn/a Heodo
2022-11-04iCK.dlldll 98bf0b1ea18c04a189d62ae5b50f81a2926f017cea24df7ea9ae6bfdca53ce19n/a Heodo
2022-11-04Qvjr6HzhKui40xt.dlldll 6b1dca4dc2f5414bd52ce4dfd925844db8a6931de96b8ed64b905aa5d2d02189n/a Heodo
2022-11-04JD2Y66tG1fn.dlldll 9a3766a0220eeb7217754db5af88e50d86a5093355482140ea012f6793898fdbn/a Heodo
2022-11-04V8fXokXBVEbn.dlldll b842ded6dfc1ec1a3d671b67b8a65365ad42e75af05045ab327ff6815884237dn/a Heodo
2022-11-04VrHlATwwiRDi.dlldll ac968005149c896af3a8e1f7cdb1657848f4c52c20ce2d9359725039492e2554n/a Heodo
2022-11-04ZWp1sS.dlldll e103a8683988cbe4afecc8292b3219cb2ef17ef6cc3a12fd4e7955c2a85092e6n/a Heodo
2022-11-04DQdgOWPPJuw5sY.dlldll 8ab6cf5fe944604fec9c2af57ffe7c452efa79be963ab6d65ebc110dfb8fe395n/a Heodo
2022-11-04zOUjoosIhp2qcXY7PmE.dlldll 58344ce2cfa48c63873f9beb2a0a9855d072422d05b1be2cf35f82d2c05182c8n/a Heodo
2022-11-04Cj00FHBH029KpeTtj.dlldll a298d9cb8cfcb15bda5e04a1c159708a036c8b4a15ed9fc21d3ad49580a6901en/a Heodo
2022-11-04kqFP5Qrdz3AFWxNTs.dlldll 42479c94dce1584484cb02e9fe95b2518c54f3e861b04918d8a27b9f4ec53d1en/a Heodo
2022-11-04jJJYA3PFzvu8.dlldll 93d0e91118fa62567af2a72c73d995d5bc14bf0d7590b78bf1a1c268287702fcn/a Heodo
2022-11-04CqUV9JacYEU33NNY.dlldll 8601f4b87c2332a3a2edd08818b2f264b1fc8f26164559761da129dc20510a64Virustotal results 12.86% Heodo
2022-11-047xbSXddW3sKkh.dlldll 17690df0a699cd4ea4697b90e9430796e0338a4374f31b4d77735a5944a5ed66n/a Heodo
2022-11-04kb8attXqqWra9cJU.dlldll 44dc4ecdedff314aefa6e9f9ea26f03adeb016025db6563964812b23f0566d46n/a Heodo
2022-11-049NeOajHpKjG7YYpj.dlldll df36b537de96748276d150adb2f8fad3a9f4c7ffb159620fdd0d396557f61ba8n/a Heodo
2022-11-049R4SZjh7.dlldll 56cf0a404550bd79b30a6b3d66c1e7c7f1ea05605cf73e005330be9dbd1085f4n/a Heodo
2022-11-04jJd.dlldll 6b9fb12652269690e10c12d9a4651a1de422d53926cdd9f146b8f509ad872d98n/a Heodo
2022-11-03Owfz.dlldll 0a1d727b54ba49193c9198c5b58a4c5570689c88c6379ca59aa16a2c4e8628ecn/a Heodo
2022-11-03aNUSZzrBNjAxg.dlldll b4e4b92a9b0e0bc99d612664576d8817ea5b90688fb2cb7b130e1e8e149315c4Virustotal results 8.45%Heodo
2022-11-03eJO832r2PheQ6R.dlldll 0641ae2b93690b57defd1f7d6517166258569be74425d3912c841ddabf04f5b8Virustotal results 7.14% Heodo
2022-11-0341E0k1O6DL.dlldll 016e683ac505c85f267f22226b983bca49f632158e258349c30330c30412fb05n/a Heodo