URLhaus Database

You are currently viewing the URLhaus database entry for http://isri.ac.ir/cgi-bin/Tf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295129
URL: http://isri.ac.ir/cgi-bin/Tf/
URL Status:Offline
Host: isri.ac.ir
Date added:2020-01-22 19:33:07 UTC
Last online:2020-01-27 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-22 19:34:02 UTC to abuse{at}fanava[dot]net)
Takedown time:4 days, 14 hours, 29 minutes Bad (down since 2020-01-27 10:03:56 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24invoice-EA29_584908.docdoc 0e3afb24573ffda5934d8ee2b9e9062e8e06f2fead17019fdc6a4c38223c19d6Virustotal results 30.65% 
2020-01-24INVOICE_FSA9_419170.docdoc 3d77b72651e464a5eacd9ec09426f2ed186472e8cd379d628629a6b29be9bd05Virustotal results 29.03% Heodo
2020-01-24INVOICE_D9887_83736029.docdoc abbfd0b5d7417b224f96c7ed693c2f4cf8549db85c79eeb4fd9f03994ff3eae7Virustotal results 28.33% Heodo
2020-01-24Inv-01_5336503.docdoc 58f4a9350c2c4d061072015bf56382f773719d9d78ad3bba260cece6dce54e54Virustotal results 26.56% Heodo
2020-01-24Inv_G6_70596312.docdoc 7dd53825b5d2ade36c33feb1492c3e52cd0a331948cbdb102e2098dbe2811560Virustotal results 25.81% Heodo
2020-01-24Inv V9612_286435.docdoc 14fe7337dd8013e7452ceda396a48bc31e996af513bf55583c72a07ba610556aVirustotal results 26.98% Heodo
2020-01-24invoice-DZB299_635505366.docdoc afe0a560ee672620ff68bfc61134f7caefb311f68e127fbc6f9676ce3f509250Virustotal results 26.98% Heodo
2020-01-24INVOICE-BK50_5242705.docdoc 8b2e4b7244319f99c6c6813e954f42c6f9580320d266b016e4752e25c56f812fVirustotal results 27.42% Heodo
2020-01-24Inv-PRM09_00085377.docdoc 21ed646e9c73d65b5355a50adb7b3a7b2f6d76b45d4248e2ad2480fd784ee8b5Virustotal results 25.40% Heodo
2020-01-24Inv_86_397988586.docdoc 22fc147219da662eef1c5d64f772b9b2883c3832c951cdc76148b5fd46bcc13cVirustotal results 25.40% Heodo
2020-01-24Invoice-RO242_50176812.docdoc 829533600afafde7716701f0ea4bc0cb998fbd85124cda950547315d1c512adeVirustotal results 25.40% Heodo
2020-01-24INVOICE 5_757254683.docdoc 7c181b5800d9b531de9f431cbd6947e93f55ac0e5f6fcad200acf2466f411a8cVirustotal results 49.18% Heodo
2020-01-24invoice ZHI822_860693177.docdoc 4be1884210b27c4d55b524c41d8c65ccbbf4c086d2915007150cb0a4c8795386Virustotal results 48.39% Heodo
2020-01-24Inv-OK82_096311.docdoc 8e96c8617604fd15ab39a4e48e257ad769bfc12440f857da0cb0b21ddcaa86ddVirustotal results 47.46% Heodo
2020-01-24Inv 62_761088.docdoc c393c68c511fa27255a6d8dffe5f67053035c168b4a2c0f049bd297cb4cc5b37Virustotal results 45.16% Heodo
2020-01-23Inv-XOVT527_8685548.docdoc 893a038578e5f21affe22f84929bfe83d54f52703b0e206956e26d9441e1c67eVirustotal results 32.26% Heodo
2020-01-23Invoice DR9294_147575.docdoc 4cb4d8d3fe9f861f5ab75bb11d23fedf98a1561b3aac9173f5dc211b8bb8bd5cVirustotal results 40.62% Heodo
2020-01-23Inv REQ70_350109989.docdoc 69896fb1907aeb3711bc79924a6aa0f9d636605647439f36e14ad1e7c1afa917Virustotal results 31.75% Heodo
2020-01-23Inv-UGQC50_561636.docdoc 15b199f8ba35174c6082d599128c694edaf953347bc41c55212437e09f16f741Virustotal results 32.26% Heodo
2020-01-23Invoice WZWX01_40979575.docdoc f1d7ec05895eaeda241064ec4901d67a5372659817cab6154477a414177feca1n/a 
2020-01-23Inv ZVAQ0918_2553568.docdoc 4bbfaa0bfc167dc0c1be1a0f65032d2c7214c7134bdc4d158bf3abe40a2ae93eVirustotal results 30.65% Heodo
2020-01-23invoice_SADV7_4056284.docdoc 343354c5822df99e96d6b88dc7da718785a030ba68942f8cb71584e3ddeb78e5Virustotal results 26.98% Heodo
2020-01-23invoice-YB5270_0574872.docdoc f8a99bfbf6c324f6f76f07ae81630edabaf926a75bc2bc290abeb01d910b9a67Virustotal results 27.42% Heodo
2020-01-23Invoice 05_195687824.docdoc 4b1fc8d62a7e490364bf85388322e779c0ff8a7adb39bfff5b386d7ba08eda1dn/a Heodo
2020-01-23INVOICE-UA6_474976.docdoc 248089756bc9657dbfe332ec94f5d2a71815ea2f66e3c12de45075ffdcafd1e4n/a Heodo
2020-01-23Inv F6972_46586391.docdoc b012b6c6233e2ac25206db6929c3a8c479710c21a520c0667eeb726556c9b671Virustotal results 27.42% 
2020-01-23invoice T10_134459.docdoc ef477d74f507594ec53f04f6c9cb1c1824df07044c0197d32197ff0f5c706d21Virustotal results 20.63% Heodo
2020-01-23Invoice MJNX6_893316.docdoc 023430cd6c69dc69f461d433915b89ed4b22fab2cbcc9882319f266d3e20f6d4Virustotal results 22.58% Heodo
2020-01-23invoice-PG6_77689042.docdoc f28efd022a443c710b7a21451f86673fc1f60b1d4c7a49de6f52297edb24cb26n/a Heodo
2020-01-23invoice DT4819_596613249.docdoc 54269042654b69699ba49ebeed232b03a543d8736b38d7b6797a98e3b8d9e541Virustotal results 20.31% Heodo
2020-01-23INVOICE OCYX3_9993315.docdoc b880f03f8d1480e05b41dd7f4f69cf55c05166f273b59619d8af1386d2c92316Virustotal results 33.87% 
2020-01-22Inv-25_065391.docdoc a419daa5498124a0d7b59767846c8c3c8348a5e2dc20b0d1d9f469f1d4797042Virustotal results 28.57% Heodo
2020-01-22INVOICE-C6_014803365.docdoc 3c1cc64c9babf45acdb186c3dc9689517fefa31918bdd47faf8e17878f2e43e4Virustotal results 28.57% Heodo
2020-01-22Invoice S6_889957.docdoc f62230c89fbf246ff1994db79c23eda7dc640e36bc6c63c2653f6fb490b72dbfVirustotal results 34.43% Heodo