URLhaus Database

You are currently viewing the URLhaus database entry for http://ssc-uk.ir/cgi-bin/closed_zone/306168_2EaMnPlBA_area/2hlbys_2yw9ww/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:302169
URL: http://ssc-uk.ir/cgi-bin/closed_zone/306168_2EaMnPlBA_area/2hlbys_2yw9ww/
URL Status:Offline
Host: ssc-uk.ir
Date added:2020-01-30 05:45:05 UTC
Last online:2020-03-24 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 05:46:02 UTC to abuse{at}ovh[dot]net)
Takedown time:1 month, 24 days, 5 hours, 28 minutes Bad (down since 2020-03-24 11:14:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-02rep 2020_02_01 6547136.docdoc eaa0cc45cf6f7d6420ce4e051d0ec99e229788a20402347d6d4c180f129cccb8Virustotal results 38.10% 
2020-02-01rep 20200201.docdoc 111bbe3116737d3299bb49d3fe0feadda406d9c061e02171c4bb61d30b3eaef6Virustotal results 32.26% Heodo
2020-01-31Doc_20200131_FBM9054.docdoc 7d51e85c069b10d26420af90603009f9ab8496020c918378c0d1de743ebaa277Virustotal results 20.31% Heodo
2020-01-31Mes-20200131-9418553.docdoc 2c1c2bc7043d0a9e19f8082f74edb7fe6701df464a66a408969bd9825c11d16aVirustotal results 21.31% 
2020-01-31FILE 2020_01_31.docdoc 2bce224fbb796e89f3cb3cabf9a2fc0fde11da346cbbf8bec73c159ecce0e445Virustotal results 33.33% Heodo
2020-01-30DAT 20200131 213.docdoc 38ed0185799cc1cb1e2fcfea1f554229ad2ddee7695a8eee704426cf83a6b7e6Virustotal results 33.33% Heodo
2020-01-30mes_XC39180.docdoc 710bca7eb8f1b38ff3ff591ffce42780c42d513d5db8e8edbed62b2a30a41145Virustotal results 33.87% 
2020-01-30list-20200131.docdoc 3094a8cc9745d2d8c20e81837a459f5d1b7509d411d7954dc4f3309fbad50d3cVirustotal results 34.92% Heodo
2020-01-30Rep-2020_01_30-4020.docdoc 72b6ec3c1e924a2f6b1bbf4f5359a7dff2c8d0cd96062fa882119a929ff9b6faVirustotal results 33.33% Heodo
2020-01-30MES.docdoc 88d2169711b161c4ef3ad2a293d5d31f96681e8341468acf5a7d8f77296a0649Virustotal results 39.68% 
2020-01-30mes 20200130 E247.docdoc 754cbbb7ddc67e1475afc52e76a09e3c2f2caf788795fec9c7859e82dc81d9e6Virustotal results 38.71% Heodo
2020-01-30ARC 20200130 6187.docdoc 8f4a6501b7d0a50fd6e8efa50f1eb0cf68d343cd44f5e4b28c47fd843d56fe6fVirustotal results 37.10% Heodo
2020-01-30list 2020_01_30 831.docdoc 11078ef33eb1bccdd13fee326af0b5a51e5d9bfb1335c25004cf281c01ccfdc3Virustotal results 37.93% Heodo
2020-01-30mes_20200130_IH7275.docdoc 33bff75b0b0477fe5ebb1baa53a6e72f2c569227d8ab61eddac59592d02d28faVirustotal results 32.26% Heodo
2020-01-30List_2020_01_30.docdoc cd3214c911c1d942daf6c996111cd99097c00e5fc450d39c2abfdb45c27658c8Virustotal results 31.75% Heodo
2020-01-30list-20200130.docdoc 8fccb53dc5d9058d11d344f7fbd34609642b1b1d2a9e4699134d165ce6ab21a0Virustotal results 25.40% 
2020-01-30INF_20200130_6289.docdoc 7099bcda5f0b4caadc077f6bc794a4dc8933e66863535f49c23c8b19ec793b7fVirustotal results 28.57% Heodo
2020-01-30file-PLC873.docdoc 6686a87ce4ec03815de4f384705a2a876aee4195ecaabf95d727a6d63030d4e8Virustotal results 29.03% 
2020-01-30MES-027920.docdoc 1db0c100dfea192f88767bedda9beef583fcfb5c7797f32d7f93dcf045d3239cVirustotal results 25.40% Heodo
2020-01-30mes_2020_01_30.docdoc 7813953b519fd2415485a5fa77ff22d67371ce55ed3b466d024d0bb9f3bdbaacVirustotal results 24.19% Heodo
2020-01-30DAT_20200130_2606185.docdoc 0c899fbd963450fdf0d3d487fd91c0ef00e8c4191115d99d58a6b75476b06254Virustotal results 28.12%Heodo