URLhaus Database

You are currently viewing the URLhaus database entry for http://cepc.ir/wp-content/6iyxdyg-e40fhnai8q5ecii2-94076-vse41r/close-forum/6LSsrNzJ3-dboMK9mvH2huG/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:306703
URL: http://cepc.ir/wp-content/6iyxdyg-e40fhnai8q5ecii2-94076-vse41r/close-forum/6LSsrNzJ3-dboMK9mvH2huG/
URL Status:Offline
Host: cepc.ir
Date added:2020-02-03 11:56:34 UTC
Last online:2020-02-25 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-02-03 11:58:02 UTC to ripe-abuse{at}hamipars[dot]com)
Takedown time:21 days, 20 hours, 15 minutes Bad (down since 2020-02-25 08:13:34 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-05OFRT_02_05_2020 5G5165538794.rtfdoc dfc7f1cc0e079c7469c7e3a0536510d5f3b5556a4655f95e98496e2c11cf1874Virustotal results 23.33% Heodo
2020-02-05CONTRATO-02_05_2020 G91746164642.rtfdoc ef74202276aee43dca3327e29e3f7444583c342da59aa5f7ef01e6be1dccfeb6Virustotal results 25.00% Heodo
2020-02-05Contrato_172785.docmdoc 46529e473f1dc76c028e9d23e9b51ab7dca3b2f86cab1cf88db1fc504aca4705Virustotal results 25.86% Heodo
2020-02-05FACT 22880914117.rtfdoc 2680ccc11a0001f2af126f851b3389dd62ebf81afd0e72ce2dde130c37a48578Virustotal results 25.00% Heodo
2020-02-05Factura-23796729329.rtfdoc a9d9d090c46571aac592ac8ab969a6c1f70c729927d1c863b3ed327c286b3b5dVirustotal results 23.33% Heodo
2020-02-05FCT-549558520.docmdocx 3c0292963e5af1dfc8aa14b1b0408c3d3e0873fde4dd75962bd380b5aa67eb36Virustotal results 34.92% 
2020-02-05fct 06492655.rtfdocx 50c91ab41f34779b30eb26c662f4e368fd4a736ac1fc4f0190b4b9457a4f5378Virustotal results 36.07% 
2020-02-05Factura_02052020.docdoc ace19c1fb2c225a5cf426c9f169fa5f0eda40f1ca92af9e19f352f59847bf8f3Virustotal results 31.75% Heodo
2020-02-05FACTURA-E424407643044_787307072530.rtfdocx bb7f9a8328d27dd65771ead824ae5f5026f9776a02bb59015053dd5d7c220f37Virustotal results 30.65% Heodo
2020-02-05facturacion_02052020.rtfdocx c88c5193f9ffea07709eeb7dbe053ec079f2a2d4f142fd26ca76ed7f55c6e6abVirustotal results 30.16% Heodo
2020-02-04fct_02052020.docdoc f2d5330b5aa423a1c21c6f960154447080fb0b6a7747307519ce8d57a310d1a0Virustotal results 29.69% Heodo
2020-02-04factura-02_05_2020 H03620236150.docdoc 775897886b7d18c9ad1d538d845dcc9b8e85df821bfa94904985368de0e8f100Virustotal results 30.65% 
2020-02-04factura 316416958558.docdoc 3e807f7cb48c71df4ce8ba0a0024238ec14712f1e68e7d0c959ab376f2fbd524Virustotal results 32.76% Heodo
2020-02-04fct_943m8o688p566o6.docdoc b9d42e016bb94271c9d10c7c68d438ead1f0078d3b0fe039da3166ed9f29432eVirustotal results 33.33% Heodo
2020-02-04FACT 65O60726195628_93639.docdoc 6773f2d12cac7fc60b6b05a0ad90ea189f3479d0c7e8eb0ed642722077ca9bd5Virustotal results 35.48% Heodo
2020-02-04Factura NXP519477331919 2961.rtfdocx b652230d0ab5eba2fd05573b7ef10013f6563c1bb9f64d5f5106b15cc8a5ade7Virustotal results 31.75% Heodo
2020-02-04factura 246558.rtfdocx 265e4a2697fbfecc43edb76419d9e4a8928492d01b548cd7d6804226d6b2a593Virustotal results 37.10% 
2020-02-04facturacion-MNI7430664853.rtfdocx 786563efb876e891aa804967d96e0a176417ad2c731e93a1fd788cc7d15d57a7Virustotal results 37.70% 
2020-02-04FACT 258012184-161320702.docmdocx a22639097a957b8debdfb4ff182eb2b6a288368b09b8427853ed91346b687737Virustotal results 35.48% 
2020-02-04Factura-6R8527370125 93895068.rtfdocx 05f89d1b6bf1a0443a52a1f52c120eda46fb60b922beab020051781d3a405981Virustotal results 37.10% Heodo
2020-02-04FACTURA-02_04_2020 3489657509.docdoc 4797cddac2f4b88206c147e98842f78fb081f26db474df81a02a7a05c59865beVirustotal results 35.48% 
2020-02-04factura-02042020.rtfdocx ab0837ea73974131b3f5b997122999652e55984c19cd55a48ab812c4500480f6Virustotal results 35.48% Heodo
2020-02-04Factura 02042020.rtfdocx cf2fa78d90fcfab9100f273c1e9ffe890840d22f6a0dad51aafde1684d179222Virustotal results 34.92% 
2020-02-04Factura SE96208477-97643809715.rtfdocx 14caedac45df173fa759640f3d19efcd330e4ba5c3a8f2d6751dab8556b6fa77Virustotal results 34.92% Heodo
2020-02-04fct-5895721.docmdocx c896b275330256006e4bd20c9f1acb9b11b059ff0673988e853bf709b6fbf67eVirustotal results 35.00% 
2020-02-04factura-6qmp82n97qq.docmdocx 002d694ef8bf683023d2285a4a16c1673c4ac35874c13d7cfd9c9dc9cee5854cVirustotal results 33.87% 
2020-02-04FCT no0068np7n.docdoc 4c49178c3c577635eff4ba3da2f2e2df98a5226e07b1472d2df347adbf2f36ddVirustotal results 38.71% Heodo
2020-02-04fct_02042020.docdoc 8143fbcde0aa33fda4259a4da03b0f205f9577ebc92d9dc186cb20a1219de133Virustotal results 38.10% Heodo
2020-02-04FCT_02042020.docdoc 821d5e01c6a22bf01f87a2cc063615e17a74dd2599e21bb6ec2de779f77c8d08n/a 
2020-02-04Factura 2W2239245.docdoc 3331178cb99b81f405f5cd9f9856d581a217dd6b65ebf3746cb823d38d2df988Virustotal results 35.94% Heodo
2020-02-04Factura 02_04_2020-660771.docdoc 576eab9fa078004f23ef56aced50697f3ecc180240ac97ad357fda437b98fbd7Virustotal results 35.48% Heodo
2020-02-04FCT_0917047.docdoc 1a843423e43f96d0064931578ff25eabdd863b7b8cda34d117d5d6ca7b7777abVirustotal results 37.10% Heodo
2020-02-04FACTURA-02042020.docdoc 3cdc07371e6b5c24c97d84f28fe8234b260a08267d8f57d1f4a45237097844faVirustotal results 35.48% Heodo
2020-02-03FACTURA_S360214110479.docdoc f1ca3ac8b29ff318670eb9fec48430c20bfd5c159a0e78ea322110f711f0b3caVirustotal results 32.26% Heodo
2020-02-03FACTURA_59211416496.docdoc d48d382a360c44f8990a525f7ee79c00056b9091d438e3d641396d8353374bben/a Heodo
2020-02-03FCT_02042020.docdoc 638b50da8c574f4785910dca412d1afe1520c754d676c4f8838455d0de5d637cVirustotal results 32.26% 
2020-02-03FCT E3939402 8551.docdoc a76a7c2029ae2435701beb379d26d8d9d8d033af5dc49715a117b071173d4da0Virustotal results 32.26% 
2020-02-03factura SNZ7248.docdoc 07203376cb50ab736270e81db3c3c4503371a701b5015e88407c407326388750Virustotal results 31.75% Heodo
2020-02-03FACT 448419.docdoc 5f570674404dafed0028b479c8a05c8d21186b07e803f2837cc21ed2e4708139Virustotal results 31.75% Heodo
2020-02-03FACT 02032020.docdoc 9681ccc3cf58b12d30d0c4be40f0de86eaa804c3f72922a4e654956134e1b831Virustotal results 31.75% Heodo
2020-02-03Factura_1RP38561244.docdoc 892fd68b4a8f46c4a39dbc623d9d742a089bfffed2bb63deaa3fdec71fd7cc04Virustotal results 32.26% 
2020-02-03FACT_02032020.docdoc 4f42296ac4fca625ee4ac4df92bd4fb7bbdd444c465ca3911dbb1c5ffb411e9bVirustotal results 30.16% Heodo
2020-02-03Factura-02032020.docdoc b63a7c322815d02e5de2b325723064a71aced4f95f46db1743d25b8084940f8bVirustotal results 29.03% Heodo
2020-02-03fct-02_03_2020-0184937379.docdoc 5896448511544efd3cef9039dc85e3caf21c87fab2f845ed4a1b9ffa1fbaab45Virustotal results 30.16% Heodo
2020-02-03Factura_GP2041869.docdoc 613c07add2e36525d212575f590b50a52b69cb862794bea5ca43df22454e6f09Virustotal results 28.57% Heodo