URLhaus Database

You are currently viewing the URLhaus database entry for http://cepc.ir/wp-content/closed-ouj6Tj-vxoCnsP/verifiable-forum/Qc8n4XVH8p1q-eogvlvei05Kpz3/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273623
URL: http://cepc.ir/wp-content/closed-ouj6Tj-vxoCnsP/verifiable-forum/Qc8n4XVH8p1q-eogvlvei05Kpz3/
URL Status:Offline
Host: cepc.ir
Date added:2019-12-20 05:52:10 UTC
Last online:2019-12-23 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-20 05:54:05 UTC to ripe-abuse{at}hamipars[dot]com)
Takedown time:3 days, 12 hours, 3 minutes Bad (down since 2019-12-23 17:57:40 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21fragment_391930.docdoc 1aadecae9e168d092eb93dbad3f0473f5c2c11233263ed2ace1269ae81743868Virustotal results 41.94% 
2019-12-21approved original-12_21_2019_G92438860.docdoc 5856d01e49924a0e1b270f2113a1bbdecec91b51ff0ac817a82099b71f685092Virustotal results 38.33% 
2019-12-20approved-instance 12_21_2019-2F221076033.docdoc ad97d47e1677a88bae94cca01a1937e50fe6c2f7b3bf01a367d49ce3437a4573Virustotal results 32.26% Heodo
2019-12-20approved info_290015524745.docdoc 7c1b37c35f2850b2e46138366121618fbb23d5222b11acd5d08b1e374e107192Virustotal results 27.42% 
2019-12-20new_notice-12_20_2019_58G34185.docdoc 0e2f92e673a24cd047d183ebcc0fdaca842dbd2d0f32b7ddf18eab3ce91a571aVirustotal results 27.42% Heodo
2019-12-20notice-7353368.docdoc 109da0381499feaa9d9bfa202a146781bc1777476841f0c5847015f7a6fa92c5Virustotal results 32.79% Heodo
2019-12-20final-scan_6599512.docdoc 115088a6fc23e09b797f8256fd67ee60eae48df940103b7607f7d171523dd47eVirustotal results 29.51% Heodo
2019-12-20version RYJ9959460239.docdoc 6054209ef8d53dafabfb03023d236d7cdb010a33e35f45f11280ef331d7315edVirustotal results 27.42% Heodo
2019-12-20fragment 3R39251219517 61725343.docdoc 33fd0465cb66a32f30e88e45cad70257f866ed7cff9763293a5894da2b32af7dVirustotal results 25.81% Heodo
2019-12-20Christmaswishes.docdoc e2793baa07cbda28507c9b8e423e2506a34527d3af97f22589a23b3b7a7d7cbaVirustotal results 26.67% Heodo
2019-12-20adjusted-statement-1198388.docdoc dc98644b4039cf69b3aeca3e755ea9380f66cc906fe23126044154fd4655be53n/a Heodo
2019-12-20adjusted-receipt-G6326722251.docdoc 5ff89563f185b55eb05da2f55cf8749cc90c65780af138ab2f4e317a40b8b138Virustotal results 22.92% Heodo
2019-12-20part 12202019.docdoc 0c61d6d3fdbcff7d1576737fa4f10668e5443f5bff6746028266d2b8da55df89n/a Heodo
2019-12-20adjustment-B1100105.docdoc db1b7614f7990cf6a79141f12cb65d47eae15099ee14be39f8cfee9872b1bd02Virustotal results 22.58% Heodo
2019-12-20correct-48641665-336922415811.docdoc e7f3d38e909a25fe37d40452a07b925e8777c017e1a9cfb65b8a637c14f37bdeVirustotal results 38.33% 
2019-12-20file 112414518.docdoc 75b3e8ecff0075dbf1714a95d4316d9a56ada3547050ffc8a9035ca531ff6460Virustotal results 37.70% Heodo