URLhaus Database

You are currently viewing the URLhaus database entry for http://hassan-khalaj.ir/x4jqp8bg/kp022z-hi-48082/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290073
URL: http://hassan-khalaj.ir/x4jqp8bg/kp022z-hi-48082/
URL Status:Offline
Host: hassan-khalaj.ir
Date added:2020-01-16 14:44:04 UTC
Last online:2020-01-27 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-16 14:46:04 UTC to ripe-abuse{at}0-1[dot]ir)
Takedown time:10 days, 16 hours, 15 minutes Bad (down since 2020-01-27 07:01:30 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18INVOICE-IB2_4735584.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18INVOICE_D09_2573052.docdoc 83f1652682079f39835315667ec159797f69ba97e5032d110999fc7f0b6a3b43Virustotal results 22.95% Heodo
2020-01-18Invoice-92_83161136.docdoc 315f3d156f10ed289ffac2ac3873448cb7c7dab3d36fc8039414f1b9e1dcc8ccVirustotal results 21.67% 
2020-01-17Inv_D006_7397289.docdoc 5587771cb559a03d5f4f78ea8b0c7981efb107d23f15f6de057ef6bad84c7b1dVirustotal results 22.95% Heodo
2020-01-17INVOICE-ES199_444307.docdoc b09c1b973c6ca799fe7817c241a0a1c56f907feffe6ecd63daa615be18c7b077Virustotal results 20.00% Heodo
2020-01-17Inv-ZBEG5906_416040.docdoc 8a37c88dad693d0f6589c7563648abbd0b7c254d683ef495f6a47c5b5d117c2bVirustotal results 18.64% Heodo
2020-01-17INVOICE-UXB26_7805576.docdoc 7d11b7bc87f942cd91eba2a37875c91da96cbe743fa581ec9a59617be7d8496cVirustotal results 19.67% 
2020-01-17Inv QBTK0822_80373066.docdoc d147493c7524068cc73eb5a2bbefdf9d2b39d888629d7fa5eb5c9691feea8cfeVirustotal results 25.42% Heodo
2020-01-17invoice UU190_961098.docdoc 56efd76637885b1d5cf7e97f165f971b813918fc404774d8b2f9b84af94eac87Virustotal results 20.34% Heodo
2020-01-17INVOICE-W32_053570875.docdoc ce80467db173a085999c0c2e59269426ca25b247416d264657ea646a9f2be7a9Virustotal results 24.59% Heodo
2020-01-17INVOICE_UJA2126_9789325.docdoc b4b6809e8ad49a3c2b726e5ba3c33fbf94b11f51beea1f5208ce000ac005cf58Virustotal results 21.67% Heodo
2020-01-17INVOICE_OLKI22_94992091.docdoc dd16805945f08b66a472325c92bdb3d2a2568f1741453e6d5249a2532c721232Virustotal results 18.03% Heodo
2020-01-17Invoice_5_787417110.docdoc c3caee2567d4552915d80cea79db008ddc0f2c27bad8c286934a364e3f9cbaf1Virustotal results 19.67% Heodo
2020-01-17invoice-40_0748408.docdoc f56384dea4f59a337a231e2a4b8034e0a35ad0b48b887af33845729aedf263b1Virustotal results 19.35% Heodo
2020-01-17Inv_GZBP7868_571679.docdoc bd10ca954e76a2aa5ac190da4c96e306d3fb02e8a5124dd5b4b29e46f004b86eVirustotal results 19.67% Heodo
2020-01-17INVOICE_MEF5829_2250492.docdoc 72e668b37382f89e2ca769002432f8795a29663a6d98d1e2ad158c6cc13f3794Virustotal results 19.35% Heodo
2020-01-17Invoice ZTG6_351036164.docdoc dac2c347a8f0b296dd79ecc4bf418ee7984f79508352ac9dada729255708a4c0Virustotal results 19.35% 
2020-01-17invoice CL48_167298.docdoc e78005dc26efdbfec6cf9d593f1128a45f3ddef5d7e95dd4de8ec35216b5b1f4Virustotal results 21.31% Heodo
2020-01-17INVOICE-ORX6_68577925.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo
2020-01-16invoice_PJ90_809952321.docdoc d78eb413ddaedd38b4af3913ad17ea3205500520abd9fcb1e0be467f52cb8d49Virustotal results 35.48% 
2020-01-16INVOICE VZJG4027_3415604.docdoc 6938ee25f059732dca5502edbaea8994dd3f9bfe8f6bb4cc60e51f1d4e5c54daVirustotal results 35.48% Heodo
2020-01-16Inv-HC9513_932794.docdoc 1e53826fa6cb51f3dc880dcf24fe8eaa926f6c7b3db06e4bc13e57881df4b8eeVirustotal results 31.67% Heodo
2020-01-16INVOICE-579_3708555.docdoc 9ba8614234637feb1a441b0175ff20df2a242d795079586ec71aa807cc3485d4Virustotal results 31.91% Heodo
2020-01-16INVOICE-BQNI6_6957956.docdoc a716c0312fb85a58bdab838df8a6fec98b7f8c0e14c27caec4221ae4f76403aaVirustotal results 29.03% Heodo
2020-01-16invoice-LKK97_04119083.docdoc 091bb505b62d1bffdd4c7376163c8276d2de635a46ba479d5b0fe52bf8272d4eVirustotal results 29.03% Heodo
2020-01-16invoice-JAX1_727378027.docdoc fca5ef8ddc03838bfcbfaf96d1a0ac1655e6a0aa57d3621cc6aec27e5e327026Virustotal results 26.23% Heodo