URLhaus Database

You are currently viewing the URLhaus database entry for http://iransciencepark.ir/wp-content/invoice/y-53994950-9956585-onibky-l8wnrwz70gzc/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295522
URL: http://iransciencepark.ir/wp-content/invoice/y-53994950-9956585-onibky-l8wnrwz70gzc/
URL Status:Offline
Host: iransciencepark.ir
Date added:2020-01-23 06:39:06 UTC
Last online:2020-02-10 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-23 06:40:04 UTC to abuse{at}mehrfcp[dot]ir)
Takedown time:18 days, 6 hours, 47 minutes Bad (down since 2020-02-10 13:27:28 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-25INV_PO_01252020EX.docdoc c3a291dbb415f79194897903f7896dce073aa911a5b9bf49a42294cc7becbeb6Virustotal results 37.50% Heodo
2020-01-25ST_XEN_010120_VUJ_012520.docdoc 592a0ef2e88f78e312bb01885b175903af622c96256d39f2186982f551c14c7dVirustotal results 38.10% Heodo
2020-01-25I_80655263585179094969.docdoc 28a279c154fc7ab9b592169b72ad25533b8f32a666684d67970c20d33ebebef9Virustotal results 35.48% Heodo
2020-01-24BAL_EYU_010120_ZZO_012520.docdoc adf03a9cd4f48ab4855342a14c7fa34a0e2f63e88d622a4a6e6e22440247c056Virustotal results 33.87% Heodo
2020-01-24SW_1026829564902546448.docdoc cba73ededc4676a3fd5ea386a62854670752212eedaeea52fb505d3fb96068faVirustotal results 26.98% Heodo
2020-01-24SW_20552005.docdoc 17d0af0278265e68fc7bd551aea53ca47aea8455884650d045407cbddf0d0b96Virustotal results 26.98% Heodo
2020-01-24ST_CKE_010120_IGH_012420.docdoc 9bbb35982fd4300210c38da4c1a0b8b9f47953e6b01915d44f8b86272c278013Virustotal results 26.56% Heodo
2020-01-24PO_01242020EX.docdoc c193f9f1d0aa152f2ccf74df239c634be636f925007421eb3d1ba60ae1571c18Virustotal results 44.26% Heodo
2020-01-24INV_WSD_010120_IXN_012420.docdoc ddf866c230e59d9ca832eab360303767357ba3355a1cdc0509e069fa3234898aVirustotal results 41.94% Heodo
2020-01-23PAY_DVA_010120_KBF_012420.docdoc 5be57dfc1ec466f1be92f7b12e5623520bdd185a7ea6f50d60890f7df9cd67f9Virustotal results 38.10% Heodo
2020-01-23RP_PO_01232020EX.docdoc ac60a426ee85d3c809274c4b733643bcc5d5feb530d5ec2edb7b4c4a7f647256Virustotal results 30.65% Heodo
2020-01-23SW_6956872195658376750291304.docdoc ac9dd4e543ca8121fc28dcb180e615d6e19fa44715e30f4af82315d38a7bb0fdVirustotal results 30.65% Heodo
2020-01-23HN5261155403UK.docdoc 70b896a95932fba098f1e50ae4c7f8796bd1636fe7f75ebcd5b690c986ab0c00n/a Heodo
2020-01-23DOC_PO_01232020EX.docdoc c82a367077df5a08b1c5607128e658095404e2fe76bd7a0c4c17b8d74bdba0c3Virustotal results 29.03% 
2020-01-23PAY_DZ4191739732VG.docdoc e1380fa81c9ecf98aea7ac2b25a691e612910e8b07ce4adf982136d30d00907fVirustotal results 29.03% Heodo
2020-01-23REP_RJI_010120_YDK_012320.docdoc 1fd3b81ca3d30c9017a44eef7861ac902255560376ba3a1524e22f8bee5fcaa7n/a Heodo
2020-01-23R_DWL_010120_UJJ_012320.docdoc e81dc8d25679f4fea9a21338bd9612d079418003d3304029950f146696624ff7Virustotal results 28.33% Heodo
2020-01-23INV_729518631470519566711027.docdoc 6c80474d30b5602e99856fe45de6e2d0583201c2f3cc46ec895dcbaa7aeb5126Virustotal results 26.23%Heodo
2020-01-23GKD_010120_NCX_012320.docdoc 590f0a342c24b79d0de79d296f97e76a596a41763e8c24844af72b974d60a629Virustotal results 26.56% Heodo
2020-01-23IY1603412045SG.docdoc 3dddeb95fb091ba145a2b0705117b8ecefdcf833024674c193dbe2ccbc4c6bd4Virustotal results 20.63% Heodo
2020-01-23IL3991904993HB.docdoc 79950a40bf62dac08fd1adbb9c8aba2b8db0e05de9829d485ac3a51302d546a8Virustotal results 20.97% Heodo
2020-01-23INV_PO_01232020EX.docdoc 260b5a47eceb11eaeaddda02644c85294da44e3eaca951d45152e1db6b9f1c79n/a Heodo
2020-01-23SJ_YZ6577666498YT.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-23YS050A7.docdoc cd39f771dfbc5ccb77640dd555b2b1a726c32cadd61e068dff35b3e5ea74a5c0Virustotal results 31.15% Heodo