URLhaus Database

You are currently viewing the URLhaus database entry for https://mahdehadis.ir/cgi-bin/FlzwlBjn/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:252562
URL: https://mahdehadis.ir/cgi-bin/FlzwlBjn/
URL Status:Offline
Host: mahdehadis.ir
Date added:2019-11-08 06:25:11 UTC
Last online:2019-11-09 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-08 06:26:05 UTC to abuse{at}faraso[dot]org)
Takedown time:1 day, 5 hours, 34 minutes Poor (down since 2019-11-09 12:00:18 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-09opjCSFiU8pHzMbQb.exeexe 7c4253b33a37e66a80a613da787b30c62173944f0ecdad098465bcc87808020eVirustotal results 26.39% Heodo
2019-11-0921e9.exeexe e6663411d5475c42a41c3f63844870fe20b066625800ac9159757990d900b4ean/a Heodo
2019-11-09vrLpfygkIHGTzIWhx.exeexe 7779594bad1be8defb03fdf44b16312360357dda19dbbc01ec73f0783b5c729aVirustotal results 19.44% Heodo
2019-11-09TOn3.exeexe f4ff1ab52c05cd2efc971a9809ae28a4a556683e1b166e46bdc45bd1a2ac7e18n/a Heodo
2019-11-09ZgJW41S09h3.exeexe 931e9b9185c104c6ac52abd7a08a24f2dabf23a28ad0e9d11e325b1fd405048cn/a Heodo
2019-11-09Bo01zpd737F108jC.exeexe c2f094c4b9d45c2a98eddc58fa652d1571c78321c62178e621feb7416c258bf9n/a Heodo
2019-11-09sUSz.exeexe dac50045ec2aef8cb8a0cf80f7da2d7d0f58116dce960002a6cc1282584652c7n/a Heodo
2019-11-08qx9jFjKkpw3p.exeexe 946bcab362b71e8b30b445464b7a47fcf032be69d72829148f5d9aa9c7c7895dn/a Heodo
2019-11-08PQl9G.exeexe 3227c09b7b029a3e1361f13371182a3688933a93cae1a37df9062ca846b138d3n/a Heodo
2019-11-08FNQ5Q1QfJJqOYOAvNrZ.exeexe 4aef64241b1f6af9383090d3afc1cce2f6a1a3c49fde9b8db8c0b22c83c5c648n/a Heodo
2019-11-084m.exeexe 17ae657db99ca059fcaea05ad3ff4d45b88b7b9b33da3926f7a2a703d492795bVirustotal results 12.68% Heodo
2019-11-08ITtvr5lXboJIJvF.exeexe 5bc6a0995a7e42724cdd1e8b95b1ce575cad30c6b0d5df6e6d89e62f02ba24den/a Heodo
2019-11-086HtCgsMFS5UR.exeexe cb0a625cf7ad5c3c63620e302ad45b0d4f06b8f2e52ebcc855d7d25dfbb2cf8eVirustotal results 9.72% Heodo
2019-11-08C8dM8nrgtlf2pXO.exeexe c64ca381d3329fbaea7e63fa5dd2a07c60ca3e267c882121e34837074fd81ac9n/aEmotet
2019-11-08SPhhhYVbE5jT.exeexe 84d4f539b32903bb1126b6bc32c9d4e90665d9137baac54172fadb7e770bae91n/a Heodo
2019-11-08PmDDcr7nv7DopNmXI.exeexe c245ebf895eaaf4db04ab0d4439efd3655f906132125c002658fec3768419b54n/a Heodo
2019-11-0844QwjAEc3x6i.exeexe 9451735c12cba9d2dcf274eb7a72fbebe98b2d4a29120820b88d13d14dbee379n/a Heodo
2019-11-08MwVbahUtqQsxBJkK.exeexe 53ff0c47776b3b6d7867458f0d9ebe85dd776a8d08b702404adfcbb4fa919ecdn/a Heodo
2019-11-08FzH.exeexe 09f4a501fd5f2b035eaa44e2c57711df8a14a0cbee6a3643121c293948d519fcn/a Heodo
2019-11-08f9COVzqK9DTALW.exeexe 6e5b9bfb75c5d630bfa00b7ce633e1a216dc281089025577109dbdcb9f269dben/a Heodo
2019-11-08PcdXXXTTap.exeexe 1eb95e1f291f5742bebad2bd942dace5e6082ce67eb7e93e38d9edad646bd713Virustotal results 22.54% Heodo
2019-11-08dKDxAAVVBFzn5w3mgXh.exeexe 58dfe02b8dfef28ab4af1e4c45c4f692b33f49d52dbc96019291c1de75d3df00Virustotal results 21.13% Heodo
2019-11-08n.exeexe 0843b98ccb13829966027dae4812de095318400a45b91b566dea35ad8b829395n/a Heodo
2019-11-082r0ofDL1ig.exeexe d508eb302f5d49ce06e1503bcb983d05b78eb6e98cff89dca4cacf96dbfc3e87n/a Heodo
2019-11-08a5mF3Bxx2FG7WGu.exeexe 07edbabe79f98cec3fcc07710a1203f6dbddc7bfe3abd2b66e0a297a8e483810n/a