URLhaus Database

You are currently viewing the URLhaus database entry for http://nicewebs.ir/wp-includes/4479qjck6-bso-9081935/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:301900
URL: http://nicewebs.ir/wp-includes/4479qjck6-bso-9081935/
URL Status:Offline
Host: nicewebs.ir
Date added:2020-01-29 22:02:13 UTC
Last online:2020-02-03 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-29 22:04:04 UTC to fateh{at}discoverwebidea[dot]com)
Takedown time:4 days, 7 hours, 40 minutes Bad (down since 2020-02-03 05:44:06 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01de6ub42l594.exeexe 0ddde52ca3e01fdf8dbaff394135e34de7f446d8d47942329f9b9832b3b2246aVirustotal results 41.67%Heodo
2020-02-014np0kcjr0.exeexe f5e4efdbd73118908464366a069b08216eb418d8d5ea1d3d928517daf07202e7Virustotal results 41.67% Heodo
2020-02-01z097143.exeexe d0addf66a34c34c418be6147664bc5cb8a4578ac1151576119440a4063f3f97aVirustotal results 40.28% Heodo
2020-02-011w65445925.exeexe 6154f691f5eb7ced0aba7895e5b9943b32959bffd674de0604bf222148d5c8b3Virustotal results 39.73% Heodo
2020-01-303av61k6.exeexe a1353d0a0d43cc7699deb9a4527b4c968a546ccb2e1e98c9061dc65256ebc179Virustotal results 8.57% 
2020-01-30p9bgr8qd11.exeexe e655fc95ec21b4804d0d11b6900162a6f4924c1652911298012648e7954acf01Virustotal results 6.85% 
2020-01-3090htsx7037334.exeexe 7efd2fefc1236433221d7ce7e3a77d07b14d31f91748be3d4c1e39319f7a0662n/a 
2020-01-308cdrgo1d19880785420.exeexe 03cf95ddbc1a43ae792b15f9c01cba8447c7702a94db53fd966f3a4f0c938133Virustotal results 8.45% 
2020-01-29pke5925.exeexe 5131aa1701aee89627d94545943f4389e08d55ebadce0eebe8da250cc31482c3Virustotal results 5.56% 
2020-01-29r667yj072.exeexe cce98bc072243b35e5a3830412b9d2bb83dba765554ca554a2f853ab4f91e840Virustotal results 12.50%