URLhaus Database

You are currently viewing the URLhaus database entry for http://ux2.ir/wp-includes/gnbzky7r0-cjhh4sc43ip575tn-section/verified-cloud/73n-39ts7v0/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:294231
URL: http://ux2.ir/wp-includes/gnbzky7r0-cjhh4sc43ip575tn-section/verified-cloud/73n-39ts7v0/
URL Status:Offline
Host: ux2.ir
Date added:2020-01-21 23:07:13 UTC
Last online:2020-01-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-21 23:08:06 UTC to abuse{at}hetzner[dot]de)
Takedown time:5 days, 9 hours, 24 minutes Bad (down since 2020-01-27 08:32:57 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24arc 20200124 EZ5256.docunknown fc14516cd8aa73e06734233051c0abfa2a95a3a69de1bc063958cac821a69d50n/a 
2020-01-23arc 20200124 EZ5256.docdoc a6619c9b9adb0aece883a3c86c650a62cae169e0aec1b92e0055af292818d137Virustotal results 36.51% Heodo
2020-01-23LIST 20200124.docdoc 7abb3e4c83b02572677e4ec2c0fb9b815830bea5eeaa515a50fb999016abd7cbVirustotal results 38.71% 
2020-01-23inf.docdoc 8d24a8ecfc76b7d708a048bf50179beccdec4f6912c0721c177fa420edf0aaabVirustotal results 31.15% Heodo
2020-01-23Mes 20200123 DA270.docdoc 93bb9d052dae7e7965182fcd79c48c1e7e88e30f37ebf761462d4c5c5c629049Virustotal results 30.16% Heodo
2020-01-23list-DD307.docdoc f72e74ea61f7b7a18e525ffa6453d67872f898f2be8def76d3ec300684b9be38Virustotal results 33.33% Heodo
2020-01-23LIST_P838417.docdoc 544b49bce1aeac4879cdcd5526cab45257ada596d9a32b3cbd254b7cb5bab381Virustotal results 29.03% Heodo
2020-01-23Doc 2020_01_23 K5918.docdoc 70084c2ceb78bd84337fbbfdb4765d5cfcf58a003b9d39b07c4e1ca9e7e1291dVirustotal results 30.16% 
2020-01-23list-20200123-902.docdoc e64e311b594718ab849cdf6a3379d11774932a94c3498135f107d659174adb40Virustotal results 28.12% Heodo
2020-01-23REP-S8259.docdoc 935442d00e5e51d838e5a2a3651c249aa15fc5ffc106b3fa9414973e11dd8d08Virustotal results 27.42% 
2020-01-23INF-20200123-65779.docdoc afe09e292b9823a2d28f0c6b6c795b2e3f9d1758d53e30d1eaafd8dd29b2d0a4Virustotal results 26.23% Heodo
2020-01-23MES-2020_01_23-455306.docdoc 8854c592155c1bd835e9edee147c7fa3714ba319ad138943dae4aa94a01d2adfVirustotal results 27.42% Heodo
2020-01-23List 671.docdoc 7aad6646929e3d37983073134ffba0e2735588c43e8f23d1249845c4da1ad410Virustotal results 29.03% Heodo
2020-01-23Doc 2020_01_23.docdoc b63585f5efab051c9a793dac78be7af0a7bb002f803b2d67a828065ee6ce54fdVirustotal results 27.42% Heodo
2020-01-23File 20200123 867727.docdoc aaade832c86b767e64ac370ec468133b1b0f777316fc22d37a85c2254ad1d752Virustotal results 20.63% Heodo
2020-01-23file_0166548.docdoc 2ed537c3f16c932316239ece8a27394b2f340ff86131277a08b29853ddb8ea0cVirustotal results 21.88% Heodo
2020-01-23FILE 244.docdoc 476a96fc934924101f12b1f1e3548a9688c25bf0eb1c67ef835bc657244b0835Virustotal results 20.97% Heodo
2020-01-23Rep_2020_01_23_745.docdoc cb8f7b473f1c200a59f57ff19de1171c4931c3264b691ac05aa63c3d33f37fb6Virustotal results 21.88% Heodo
2020-01-23Doc-2020_01_23.docdoc dd46168d7017d454d5b01dcb489a4fefe457957a8b0ea67e4bec9678a91cff94Virustotal results 32.81% Heodo
2020-01-23Doc_D95040.docdoc 6e3ff44a15d4fef5a7596e98e7824beac05bb2734acba2eae908fc221f9561f2Virustotal results 33.33% Heodo
2020-01-23DAT_101053.docdoc a62f3f486509d0fabcf6e3df247c28df135df4464a83c3ef304e61088deac5abVirustotal results 32.81% Heodo
2020-01-23file 20200123.docdoc 35e9ccfe2fb736ab494d113297f3c7069e131c28b9996efe0623d6f6fa2e2644Virustotal results 34.38% Heodo
2020-01-23arc_20200123_VZ5352.docdoc 88ff8c8ef536a4e8b31a9600abf42ca11d5082fbbfaf8838707b37877b3c38c5Virustotal results 32.26% Heodo
2020-01-23Arc_20200123_090829.docdoc 184e990a522473877e090d94d604888ffc86d75830faaa9858c5131b8e03adaaVirustotal results 31.75% Heodo
2020-01-22INF_9538.docdoc 3f3fa3b3ffd6b91f1bf8e2b173e25767cd08c324342cd0c52a18c82d37ca3ec1Virustotal results 31.25% Heodo
2020-01-22dat 20200123.docdoc 054097464a18a552af3b8b22367aba7e730d8e4d65de944f8a3414fcef815337Virustotal results 29.69% Heodo
2020-01-22list 20200122 UK08599.docdoc 50999d99ad66e0b196084e0b6f483db32ba133c85e2a4ecb7065b5fdb4053e8an/a Heodo
2020-01-22inf-0397.docdoc 346b0ba9684b9fdc8dde08af0ab486c86cbea5347a32be77aaafb0dc9034f2e2Virustotal results 28.57% Heodo
2020-01-22Dat_2020_01_22_PS439.docdoc 09c16304c3e1aec3c34700ba9ccc3b60a96824e6f17b99ada9f1ddfc84e20d06Virustotal results 28.12% Heodo
2020-01-22Rep-2020_01_22.docdoc 6eb3a1de5779c87ba943671cbe8f29213ae390f189e8bd35f9520393e1edf6deVirustotal results 26.56% Heodo
2020-01-22st-3927.docdoc dad1b60c001deb55fd561c435e1825db93fd1dc33d40fcf6d99a469e56d0f6e0Virustotal results 27.69% Heodo
2020-01-22mes-2020_01_22-KMD494.docdoc 2ad3eac84cebb1c035141e43e0b9a5cf7ef8defb6dc62580737446cc39f9f7f7Virustotal results 30.65% Heodo
2020-01-22st.docdoc 6dab6d9bdad5fb8c6564493c3c06f10835f916e3980e4937d8c55f4c2f1f1a01Virustotal results 30.16% Heodo
2020-01-22File-2020_01_22-PAU74088.docdoc d51bc288487e5fdcfc17a5ec6e0fa384a022cb77f0474947a0d2059faa19446bn/a Heodo
2020-01-22DAT_2020_01_22_3619143.docdoc d5d9a7450867f6c951b33c65e5c363becf43297041b078e61259006714be9da2n/a Heodo
2020-01-22arc-20200122-RQO41765.docdoc 63e4f747e3e1e3b0013d5e079ba505deee4fac664d83b0e250297677230bd592n/a Heodo
2020-01-22Rep O1585.docdoc 35aa31f7e13efde73dda7cd2a817bd49c6f322ffe1f765e585c50f564ae330f0Virustotal results 25.42% Heodo
2020-01-22Rep-2020_01_22-XIS178.docdoc 27a95f049070cadbefa3c02a756a3b031f62b48a3fd6b2deadc601e88c1e2defVirustotal results 27.12% 
2020-01-22ST-2020_01_22-NVX879.docdoc 51eee3e4a7660d4f56645b90486fff90496b798f882585f6bce988615624167bVirustotal results 26.67% Heodo
2020-01-22doc 2020_01_22 1691674.docdoc f215874c38b91208764829b0950f3658cbed0e5931060ec4d658ff212f019642Virustotal results 19.67% Heodo
2020-01-22Bl 2020_01_22.docdoc f57549b2d5b329a8c83b05e2a6ea4f288e4215882c24d2650cc818e65fcd6239n/a Heodo
2020-01-22Arc_2020_01_22_04589.docdoc e32b84c7d967bd21ca4def6c66ed1441afca25b720e896b926f4c01906891918Virustotal results 19.67% Heodo
2020-01-22Doc_20200122_MHI1667.docdoc b92b6beab56264910194b45aac22370981155c53c9914cc654e211652b370c95Virustotal results 20.00% Heodo
2020-01-22Inv_2020_01_22_Y937521.docdoc 55e7c45b115a1b3f5841cff784e524e1a7db1007c8b7dab6c0ac641891d18a4bVirustotal results 20.00% Heodo
2020-01-22Pay 2020_01_22 CA2844.docdoc a6d88c45a2db468584d02f98537fa9948fb89553ecdb4a9ed46bd92cbc43d863Virustotal results 21.31% Heodo
2020-01-21MES 2020_01_22.docdoc 2119f3e51c12625d689a0d06dbbbf6d19fc6555e7f33b67a54e3df778f1a09fdVirustotal results 20.00% Heodo
2020-01-21BL_YSO935.docdoc f898be20d68c31a4789e549ee4d35ce8f19baa7c25304261e7bfc310ae8a2d31Virustotal results 21.05% Heodo