🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://roshanakshop.ir/css/closed-6623313966195-ylZWNCaa/verifiable-FdXBo-bfefjBWi0mfKu/XscTmX-uslNd21y/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:264455
URL: http://roshanakshop.ir/css/closed-6623313966195-ylZWNCaa/verifiable-FdXBo-bfefjBWi0mfKu/XscTmX-uslNd21y/
URL Status:Offline
Host: roshanakshop.ir
Date added:2019-12-06 20:21:04 UTC
Last online:2019-12-12 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-06 20:22:05 UTC to no-email{at}apnic[dot]net)
Takedown time:6 days, 1 hours, 59 minutes Bad (down since 2019-12-12 22:21:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-07duplicate n4o976qn.docdoc 282ddf44fbb13c3ea82c1fb85e62a1db366cc254fafb1d073079b97f928d34cdVirustotal results 31.67% Heodo
2019-12-07last part_12_07_2019_1774892242.docdoc e81489265fcc1373094988fad0380074b214b53ac431845f9571c575ee4913daVirustotal results 27.42% Heodo
2019-12-07statement 12_07_2019-A1245928482.docdoc 730a1aebc8f744305118e59701835dd83766927cfea0ef68093b1022574d4f80Virustotal results 27.87% 
2019-12-06X5403937127.docdoc b2f75c5dad0c1ad7359c333d1fad6831bb336e160bfb316ed4125d7acf856e7dVirustotal results 25.81% Heodo
2019-12-06material_12_07_2019_0D146738291068.docdoc 59d9c1eeaecdc097c238150f825e753fb91267547fdf0cf9bb3dd8d58c0e8fb1Virustotal results 26.23% Heodo
2019-12-06last_instance FC0099436.docdoc 15f11d73345dd103e14951ea516cb7499f89ae9da16e1f7c226511d3811247d4n/a Heodo
2019-12-06release 12062019.docdoc 602ff0e89e13e68cc86d1a62f9a099d339583b74987f6279b9c7ec40a0108333Virustotal results 26.23% Heodo