🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for http://shimdental.ir/wp-content/diusdm-3qx-3746/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:266628
URL: http://shimdental.ir/wp-content/diusdm-3qx-3746/
URL Status:Offline
Host: shimdental.ir
Date added:2019-12-11 00:59:03 UTC
Last online:2019-12-12 00:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2019-12-11 01:00:03 UTC to noc{at}gulfpal[dot]ir)
Takedown time:23 hours, 15 minutes Good (down since 2019-12-12 00:15:46 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-11Invoice-DAS774_073.docdoc cfe131f570f7e2edf117f2a1b4470c8aae81390c23327d6528bd2b6af605e932Virustotal results 38.33% 
2019-12-11INVOICE_SZ212_4560.docdoc fd39f0c4feca6bbc2bc72df5b1abf1266ea1a7bfd76caa5d1803e00096c19018n/a Heodo
2019-12-11Invoice-GDU15_08004.docdoc e1f315e16cea5360492223af2d3b47da3f3b3d250882552371d5578b0f319ba0Virustotal results 29.03% Heodo
2019-12-11INVOICE-REX068_5281.docdoc 228881e86fd02f1df936abd4e534d0fe625f5f923bf39fa8625846e8ac6b9172Virustotal results 28.33% 
2019-12-11invoice_JRK77_0816.docdoc bc3d5a793002c6d23c5e6166c7b8d8084f9f335793a4230c0ab459808f276ed0Virustotal results 28.33% 
2019-12-11INVOICE C70_0152.docdoc 7acb9dfcbeee0357d301da9535e185ed81352ca4f2c11a57d9797a13fbae0ccdn/a Heodo
2019-12-11Invoice-QOV760_7238.docdoc 4ee0bf78e3b0a06c35fed0f912db6fabbb5fae13f838cd4132634359ad0d24daVirustotal results 39.34% 
2019-12-11invoice GV197_96.docdoc 598ca34558e9464124f85cef62e3ee262da4544695fb430fbf3989b5f23a62e7n/a 
2019-12-11INVOICE-G149_3415.docdoc a60c7102286fc773ec8ada02318ac04bc6b9e5c4d835d4465fee783df6afe81bn/a Heodo
2019-12-11invoice-WOR10_888.docdoc 01a07d51f32634df14db55221faf44cb5b064fbb737a0e140fb44e674f0dcf01n/a Heodo