URLhaus Database

You are currently viewing the URLhaus database entry for http://hassan-khalaj.ir/x4jqp8bg/I83-OGnzwyq-52/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:273640
URL: http://hassan-khalaj.ir/x4jqp8bg/I83-OGnzwyq-52/
URL Status:Offline
Host: hassan-khalaj.ir
Date added:2019-12-20 06:52:03 UTC
Last online:2019-12-27 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-12-20 06:54:02 UTC to ripe-abuse{at}0-1[dot]ir)
Takedown time:7 days, 2 hours, 22 minutes Bad (down since 2019-12-27 09:16:46 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-12-21Bonus Payment Notification 61396.docdoc c6cdc9917e62313415a14d953cac0f81cd70ca8843ca2bd16be5eebb6bc7ffd8Virustotal results 31.67% 
2019-12-20Bonus Payment Notification O38.docdoc 0a0fac8a8e06c84ab81548936455a94177f8662137904ad366497a0a1b2f8144Virustotal results 31.67% 
2019-12-20Bonus Payment Notification Uf14925.docdoc 22ffff4b7e6abf5770aef04a5f773fa0df57ff3ca55459327bd65844694b30cfVirustotal results 29.51% 
2019-12-20Bonus KCp68.docdoc 34c38d43e0762eb291cb497d18c9651c5441d1bbaab25f847c0ddc419947b3ceVirustotal results 32.79% 
2019-12-20Notify mLcn133.docdoc 4292d06695c817ec374a7742f8bf39dcb415404e00c5b814c647fb6f8f930ad3Virustotal results 30.65% Heodo
2019-12-20Bonus Payment Notification KEv725856456.docdoc 1a9a9db05064dfcb6d5f1c699a31218fc0621c148f4638fdfdae3a9a5930f0d9Virustotal results 31.15% Heodo
2019-12-20Bonus GKPb53.docdoc c5e754b236930122c0b6f1d86a993b5249e83b90ed5db2ccb5a1f68f24de7be0Virustotal results 30.00% Heodo
2019-12-20Pay D8876983.docdoc a214bd8b2b6fec4dc1c81e025d893701de68741aaaaece9bddf6456653a5d431Virustotal results 29.03% 
2019-12-20Bonus Payment 93202.docdoc 465dcf54b46b2a4db2a78128058c98e0fe5eb054e4c459f35754cba3480b4885n/a 
2019-12-20Pay XAtE913.docdoc aaee185ae36cbdca44e0ca7c058bff14083cef534afa3116704e44892db8ac08Virustotal results 22.95% Heodo
2019-12-20Bonus Payment Notification RGz11.docdoc b8aeb958388b6825a5d7fadc0052cede33574d7a2766a3ef9137a72c3d5cb03bn/a Heodo
2019-12-20Bonus Payment a31.docdoc 82ae2cfcce345cdf1604b06320131de90ff62d5956d49649e9ddf7ea0dc0d12an/a Heodo
2019-12-20Bonus Payment Notification flM237444.docdoc 7d4853fe09924695a8da553c11d9157d7921a6a664d75074a2279269fb79dc0aVirustotal results 24.19%