URLhaus Database

You are currently viewing the URLhaus database entry for http://iransciencepark.ir/wp-content/upgrade/squctpl6/e-54899205-283-csyrq25vm-az7mvteo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288743
URL: http://iransciencepark.ir/wp-content/upgrade/squctpl6/e-54899205-283-csyrq25vm-az7mvteo/
URL Status:Offline
Host: iransciencepark.ir
Date added:2020-01-15 04:10:04 UTC
Last online:2020-01-23 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-15 04:12:03 UTC to abuse{at}mehrfcp[dot]ir)
Takedown time:7 days, 23 hours, 31 minutes Bad (down since 2020-01-23 03:43:58 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17G6W8QBR7W.docdoc 8e1b4940436e835735c4319af3e1725e2ff693737935968fe5e2077025f05d18Virustotal results 37.70% Heodo
2020-01-16L_22512375.docdoc ec7daa97138174c5878ea751f64fc280edd5c475f1ad353be67afe6c74b2e857Virustotal results 37.10% Heodo
2020-01-16ST_78L0XGT.docdoc 8aa03e0069da2642cdf2b5951f6fc50e9bbdacd01a38e0e6c8d636a1afd522c7Virustotal results 38.33% Heodo
2020-01-16RP_GEO_010120_FBY_011620.docdoc d13b7bb583d3175a5a66a45e56f859a8ad4f514b8461da2c589fd74c69bc4b3eVirustotal results 35.00% Heodo
2020-01-16BAL_TH2745549076HB.docdoc bf08f22796d9bd2305d29ef668a5b81ee6ef9d07b49827d05b88f97c74a4b249Virustotal results 32.26% Heodo
2020-01-16REP_41872887.docdoc 67e4ad463f707098e9dd3aa9ef44543687de41237cb6bd15500e428aa17c34c7Virustotal results 31.15% Heodo
2020-01-16CSPAEDJ7WGH18EL1.docdoc 3c99ebde95d760948c4ff5db925c0272ec89b8409d698aab26e5785a42c88243Virustotal results 26.83% 
2020-01-161162432477152.docdoc 8f7528de459c08404bb34b2b574940ad939445c0f2c6c701f5f220e4de5d7cd9Virustotal results 25.42% Heodo
2020-01-16MTA_010120_PRB_011620.docdoc 791dc93ca83900c29d93fc3641d199b853413a23d3899b119ed619f9223cb20dVirustotal results 22.95% Heodo
2020-01-15BAL_1248798149788682143601.docdoc 9709e4969e9e12fee433a941061c1c5d89761b1c2b527fe7e04499a5f1b792cfVirustotal results 37.10% Heodo
2020-01-15FU3606818018RW.docdoc 2c40438076c3f7beb36d70f56c99baf764aa9c3936060204d6fdba9f27e6c847Virustotal results 34.43% Heodo
2020-01-15DOC_5645833112876795555.docdoc 33c109c33a748ebb55fa788c5a5f0b4e575d51e007a9961f0026ea079438091eVirustotal results 31.67% Heodo
2020-01-1547277579.docdoc 93ab67a92f697263656aeaeb5f01d856f25f562772e46a1a486dfcc777667020Virustotal results 32.76% Heodo
2020-01-15PAY_WK7571971791MY.docdoc 69b8edb2ec5347c6279a2292935d5496bae2a2bdc49bc7e246d786a31f68335cVirustotal results 19.64% Heodo
2020-01-15BAL_GFO07RT7B7.docdoc b58af543a114f02eefa12324cd48a81e69239da04a6fd4bb9cec8b32fedc9cd2n/a 
2020-01-15WFB_VLJ_010120_MFV_011520.docdoc e4fa19c4736ffb554aacdb6de08c4ad081fd55105dddc85b31eac5c6082e601bVirustotal results 18.33% 
2020-01-15ST_PO_01152020EX.docdoc d3edd09e8e4e9e89dbff176e69131f189175abf1a598c18593a3bb194fc45c2eVirustotal results 37.10% Heodo
2020-01-15FILE_90431395306.docdoc a5ab4f49f85a942911907bda864337b1506a94af7fcf9b00838fca0315e0b7a6n/a Heodo
2020-01-15INV_704510761927660968.docdoc 0fbb827318ab68c5da36b9e67f14d43c2fcf291c4727299663d3cb8c5c4367a1Virustotal results 32.79% Heodo