URLhaus Database

You are currently viewing the URLhaus database entry for http://cepc.ir/wp-content/221y9-mhoptrlii-ujk3f-q1ipoc2dhrbd58m/close-space/xi1l5jj-4tz90u12y81u3t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:268237
URL: http://cepc.ir/wp-content/221y9-mhoptrlii-ujk3f-q1ipoc2dhrbd58m/close-space/xi1l5jj-4tz90u12y81u3t/
URL Status:Offline
Host: cepc.ir
Date added:2019-12-13 11:36:08 UTC
Last online:2019-12-20 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-13 11:36:12 UTC to ripe-abuse{at}hamipars[dot]com)
Takedown time:6 days, 20 hours, 32 minutes Bad (down since 2019-12-20 08:08:47 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-14rep-12_14_2019 238541.docdoc 531031a6d72b7ab28246ff2aeab60f503ef06067fee2181cd190d7f8d468c3a8Virustotal results 31.15% Heodo
2019-12-1412142019.docdoc f100539cddd42cc563d50fcce58d301e3916d3fda2f52726f02fb3a4c3521525Virustotal results 31.15% Heodo
2019-12-13copy-12_14_2019 B79613493221174.docdoc b368258dd57fc6dec297f7b65389115de4dac0d0fe457ef0e4c27a3b8beeee4cVirustotal results 27.87% Heodo
2019-12-13COPY 12142019.docdoc d9485494a28a2ee71478dc933a07c3a49643fd433529e4e1c9a4063d6fe86b77Virustotal results 30.00% Heodo
2019-12-13Untitled or4o8upmp.docdoc 16a5d98f19f39df5b036d3e83759fb410f3165a30be7c0b1caafb87e8778cfc3Virustotal results 28.33% Heodo
2019-12-13file 557913123245.docdoc 5d67e538118057fcae60a19080ff829ff0cfe7dcc156caf8b608aeca4bb77ab0n/a Heodo
2019-12-13INFO N638952310-77308.docdoc 51ba33b37f81240a99c9eb2adb0ff2fee9d1908067fbc14e521e0726af10d1c9n/a Heodo
2019-12-13STAT K6003942259.docdoc 92a969bcc7ba9627195a89643a76d8f1881972de749c1e785ed240ec4a63b5f8Virustotal results 34.43% Heodo
2019-12-13REP_12132019.docdoc b5eaf74564a9a1331c799ef707050c435a309db7d857f606bc04737557680649Virustotal results 30.00% Heodo
2019-12-13v3tw20r.docdoc 99a1da4384732ca09cf689e2b540670bb9357876e7ea8de2fb4a528dd2eb51e1Virustotal results 29.51% Heodo
2019-12-1312132019.docdoc b5785ba7893084c6a4f7142aecf37eb4be6fd71bafc67153092e20d39a844bdaVirustotal results 27.87% Heodo