URLhaus Database

You are currently viewing the URLhaus database entry for http://rezaazizi.ir/wp-admin/FILE/vukq7bazoxr/awtvnl-724750-765-1rt6wn120i-qcbz4h2df/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:293436
URL: http://rezaazizi.ir/wp-admin/FILE/vukq7bazoxr/awtvnl-724750-765-1rt6wn120i-qcbz4h2df/
URL Status:Offline
Host: rezaazizi.ir
Date added:2020-01-21 09:20:04 UTC
Last online:2020-01-27 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-21 09:22:04 UTC to ebtekar{at}sodahost[dot]net)
Takedown time:5 days, 21 hours, 39 minutes Bad (down since 2020-01-27 07:01:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-23FILE_NR3413239402FX.docdoc ba4362c4c23ffddd3857cfe6e6640b4c1a22588f36f14cb654f3768d5a22f8a3Virustotal results 21.88% Heodo
2020-01-23INV_T6JG9S82M.docdoc 260b5a47eceb11eaeaddda02644c85294da44e3eaca951d45152e1db6b9f1c79n/a Heodo
2020-01-23WTK_010120_IUI_012320.docdoc 627970068806ee557b861c46c5f66f04f0985ad9caddd21dc3c8e4682108042dVirustotal results 22.22% Heodo
2020-01-23SW_PO_01232020EX.docdoc bf51d8ace058a2c9c8baa6741e53cec3d5d6a07b7e05eec9ed76c69cf20f37d7Virustotal results 22.58% Heodo
2020-01-23U_PO_01232020EX.docdoc 9e417d5c58ae969ec35f92ad1143eb6c4aaf1928b9e9b86fa5e893fe6c007f62Virustotal results 31.15% Heodo
2020-01-23DOC_ZN8530095797QH.docdoc cf72901c6f393919be6a0bed5ca2671fca36d5705fd639d1722cdfeb3ff93c24Virustotal results 31.67% Heodo
2020-01-239565798612265844519223.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-2305325757817826074952.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22BAL_CUWUAVXYI77OLJ3.docdoc 72bd6822c6587d7476c2bce9cbb767b7f392c8c960c6a5f08b75f5ef154f6a2aVirustotal results 27.42% Heodo
2020-01-22ST_AEX_010120_TYG_012220.docdoc c551f97351c13e0f158f87d3c11bbdb5b9f2b2b10576509755d225e3f3bf46c7n/a Heodo
2020-01-22SW_QAE_010120_BDY_012220.docdoc 97ebcfa4df6f809a741a2027ed56f4ca2f814097ecbb08eb5c4e6788a3a1305aVirustotal results 26.98% Heodo
2020-01-22FILE_PO_01222020EX.docdoc 760da2cf865d8c30de733432733cd907c4d3473c8c956b337785f76899801383n/a 
2020-01-22SW_KII_010120_YJW_012220.docdoc 1acea02225c6650692c85051717ea09e03791a57fe39ab10730263373f7fbde5Virustotal results 28.57% Heodo
2020-01-22ST_KL0095888132FO.docdoc 478f1dc50e192ecb20ebcdb9a37e7c312e9a8cc20766a5f86f95b3d9c09cc0b3n/a Heodo
2020-01-22FILE_71156422.docdoc 4c80edcbb0062e3b1f50fd07de05afa15805203131f6a34ae1dd4f4591dfcf20Virustotal results 30.65% 
2020-01-22DOC_PO_01222020EX.docdoc a8e86ce1edef7bad9f725d8f9b127d50d0a80a4e3477a2294f61bd2be001bfc7Virustotal results 31.75% Heodo
2020-01-22BAL_71064186.docdoc 2e5f9f296d5addeabf6f8caa5e1e989363265c1ca3cba2201a933e734bcf8635n/a Heodo
2020-01-22FILE_ZNS_010120_PRG_012220.docdoc c4b215a59659e1c91fffadf971f2d9f6a0865a757e23c4ded707e894927c7837n/a Heodo
2020-01-22RP_15261912.docdoc ae732e2481c442c721b9c70bbbafde35384fc2d9c8e8426e67eabd9863b3e009Virustotal results 26.23% 
2020-01-22Q_PO_01222020EX.docdoc 336ab3a461e1a9206d529c38bf94f01e340884585fe63edd765c3fd0821f68e6n/a Heodo
2020-01-22IZN_010120_PVG_012220.docdoc a85351653bf9a0c8c76db9f4c1076418ba4fface5c3a7f373d29186bf46732e0Virustotal results 25.42% Heodo
2020-01-22N_91477965.docdoc 6386c6fdd8a1eb4f6fc7bf14c51236c53a6d7dc8419ff7add51d3a75c46d3610n/a Heodo
2020-01-221GGGZ39P9.docdoc a0855eab3940a455dc8d9abb41fe9a44d09eb1153e79da6e813565d5dac82f24Virustotal results 19.67% Heodo
2020-01-22PAY_FL2276052722MI.docdoc f1c1ff6da408d3db36973e88b9e655de09333c432f5360ddf9ba275f6b330d46n/a 
2020-01-21SW_903807208.docdoc afc71ff2f950fe201610ccb3658ecabd28277de445f299d235048e06bb3c02ben/a Heodo
2020-01-21INV_87552374.docdoc 2b0dc7a3f1517e44bdc07ad1f4e244e973879e977697384256d409300c3d8396Virustotal results 19.35% 
2020-01-21FILE_80875834.docdoc b27efe734620499ff72dafb2bd9cf0650ea42d6b08f670e80149d1a7087d4f51Virustotal results 19.67% Heodo
2020-01-21PO_01212020EX.docdoc 0ba2bc2d8ddd7c95e3a17870d34c390e31968ea645b5ca3c5978da28719eeb99Virustotal results 19.35% Heodo
2020-01-21FILE_WE6831570970BX.docdoc 0ac7a98f0bbf451a51cb75aa5b065d00e46c0860c7cd1c90a194e8a40a56aa93Virustotal results 19.67% Heodo
2020-01-21042739704789670.docdoc ce7997a982cda9e7c2591ab8566bbdc583595e079b68bb121820bd81bc0f5c7cVirustotal results 20.97% Heodo
2020-01-21PO_01212020EX.docdoc 61507dd50818260d95aaadcd23ed886f445d5c1afe613e53e1633c08ee5bdab8n/a Heodo
2020-01-21FILE_CR6PV7XLRRT0.docdoc dfe2815ab27e806aa38d3a86f0c43e7aa9fca4b580604411f1d339c734d038e3Virustotal results 24.59% Heodo
2020-01-21ST_MRL_010120_ZMV_012120.docdoc e4932995a94e0c841f96d023503d1a1bb8e8278fe5478a736b9a4cbc83283ab7Virustotal results 25.00% Heodo
2020-01-21REP_PO_01212020EX.docdoc b4357b15ba2d5ddf69c371351fa7e9e3028caef09f64d5f0056d1e39bc8bdd47Virustotal results 22.58% Heodo
2020-01-21SW_55663998984760347.docdoc 60ff2a45a1c1ae55972711d0e80904cc93e7018a9f16ca4c99c9e90f7403c036Virustotal results 22.95% Heodo