URLhaus Database

You are currently viewing the URLhaus database entry for http://hassan-khalaj.ir/x4jqp8bg/common-ruf-6xx8irjoptxkht78/test-jteboh7-h6jsi8kfcpdb39/g3mrw9daesjy5-yz480xtwz98/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:271180
URL: http://hassan-khalaj.ir/x4jqp8bg/common-ruf-6xx8irjoptxkht78/test-jteboh7-h6jsi8kfcpdb39/g3mrw9daesjy5-yz480xtwz98/
URL Status:Offline
Host: hassan-khalaj.ir
Date added:2019-12-18 01:22:03 UTC
Last online:2019-12-27 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-18 01:24:02 UTC to ripe-abuse{at}0-1[dot]ir)
Takedown time:9 days, 7 hours, 53 minutes Bad (down since 2019-12-27 09:17:04 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-20adjusted-OOZ4292688.docdoc d3454c787ca79995baa875d8ea8d39587dedffbff8b33f7b71a3d3488fe77605Virustotal results 32.79% 
2019-12-20rep-2O88544 798837454.docdoc 437a0a34b41ccd256aa33586c85f5b788a93fd62946f11d19b23ac06403db402Virustotal results 34.43% Heodo
2019-12-19approved-reference_12_20_2019 0182454016654.docdoc ef2f6014b9f926466073f7e036544e5188ac00b96f5f321e12c8daece16e3b94Virustotal results 32.79% Heodo
2019-12-19greeting_card.docdoc 8a2265802819dd5ca4f6613abde71b3c378f0ed75aafd74217c7c67dc6d9aae3Virustotal results 32.79% Heodo
2019-12-19GreetingCardChristmas.docdoc d394ed6a30ff8bd2c2812675561d9662c72ea9d8c987dd329046f0ecfdeb9177Virustotal results 32.76% Heodo
2019-12-19Christmas-wishes.docdoc 38228d35350b8cc46377671e6c82da104d71567808173fd99063d63b506488eaVirustotal results 30.51% Heodo
2019-12-19GreetingCard.docdoc 1e1aca50c65bc43be764fd92ca9b520348c710fbf834ff62ab8d6d1198d3a1faVirustotal results 24.19% Heodo
2019-12-19Christmas_wishes.docdoc d4601ec37ca5d892f5eb1b542c99ed3754aedff52fdc011f13eac364de842c4eVirustotal results 22.95% Heodo
2019-12-19COPY_12_19_2019-FG60339497460.docdoc 27820b2e783ff5a9817650a7f8a04b23a41db0d06c86748ef6a1c4a1fdf9f43eVirustotal results 22.95% Heodo
2019-12-19info_I1806.docdoc e75e3aebe863fbe42808fecadb2cefe8ef18d23891d13b6b970f21ef8489a238Virustotal results 19.67% Heodo
2019-12-19rep-8375.docdoc 61fe55be0a1c2a52426f90abfa9778eef565c849a24ae59e31c6c8ba403462e8Virustotal results 21.67% Heodo
2019-12-19info-7U00180776.docdoc f6757602163018e20a342c32add664ce6af3c4bb4a72b9568be734dd2809a38bVirustotal results 20.97% Heodo
2019-12-19T1784118806.docdoc aaef0320ecd50b713b2c75b51d342616767426863d2a0c48a5dcf3be3eef288bVirustotal results 25.00% Heodo
2019-12-19REP-12_19_2019_3031812.docdoc fd9d4c5f8fc3b3a7508a54917340e9b732a4008c88bc03ed50ad76188e79b06eVirustotal results 22.95% Heodo
2019-12-19UNTITLED rmrop3tvm9p0o.docdoc 329e19d1556d04d8b0127c2a303bfe3df8aca28c95c3ac40ce8c8be9087f350dVirustotal results 22.95% Heodo
2019-12-1912_19_2019_F3F628858475.docdoc c2a870be9ac4430222a860da9ef1b34fae2a78a8d16cd1d1bc28e0f3ba78366fVirustotal results 31.15% Heodo
2019-12-19VER_4871841689 04558453.docdoc efa5656199e7633e1cf7656adb85cad8e309a8c45bf8f8f1e01f4759224c798fVirustotal results 30.65% Heodo
2019-12-19scan-12_19_2019-390878564.docdoc 13adf04d2b552069ad8870dd21dc5fc100bda4a2657644deba9ac368a022754fVirustotal results 31.15% Heodo
2019-12-19DOC-ZL062376.docdoc 0c45e14f368d59e03d4881e280642933dd8287a088108931f5c4f1425c442300Virustotal results 24.59% Heodo
2019-12-195460.docdoc 7d99d26d814089465a149220bc4e600d0bf87dea0383b6b071b605b7fadcbaeeVirustotal results 24.59% Heodo
2019-12-18COPY 33t7wo2r.docdoc 97f9065802854390f753dd2b54dfbb13ef92fbc2387216f2a09014a4ab9a64ddVirustotal results 24.19% Heodo
2019-12-18VER-12_18_2019-AD491132.docdoc a5c388ebbee623f26938d67427170bb063976b1dd0524f6ea18b402809afed4cVirustotal results 21.67% Heodo
2019-12-18NP369986448 28144.docdoc a5e5e4716eda5cccc9d9b8a61517b4fe21e4fbfcc4ecabbd3d08fc89b0f33f29Virustotal results 20.34% Heodo
2019-12-1812182019.docdoc a9b41646ad51dd5bc762a07a0efce3c6f5d6f372281699b1ba4747ad29e74c9fn/a Heodo
2019-12-18copy 12_18_2019 D7F7397.docdoc 561126bfb39ff16fe82c097bf9150a1e4b4f4e5674359c8c07bd900befb3378cVirustotal results 45.16% 
2019-12-186s1837lon6m0.docdoc 96eeaeda0e8075bdc21431cfa17b07d5ebdedcd515b5073c4074b64202419735n/a Heodo
2019-12-18REP_r68579srwmn6wo.docdoc 992d05921516c9f141fca70dfe31a45a23b8eb4a1ed260bac73a3b5aa4c78638Virustotal results 41.38% Heodo