URLhaus Database

You are currently viewing the URLhaus database entry for http://valery.ir/wp-admin/qqvC-kULzS253EdA-disk/test-portal/9739919332199-JZtfIjjtzfA27qdB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415460
URL: http://valery.ir/wp-admin/qqvC-kULzS253EdA-disk/test-portal/9739919332199-JZtfIjjtzfA27qdB/
URL Status:Offline
Host: valery.ir
Date added:2020-07-20 18:31:08 UTC
Last online:2020-07-21 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 18:32:03 UTC to report{at}parspack[dot]com)
Takedown time:10 hours, 1 minutes Good (down since 2020-07-21 04:33:26 UTC)
Tags:doc emotet link epoch1 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21Dat.rtfdoc 276dfa20b9cffd3ac104aeafed599b2f70a9fd0e8d4faf1d86ffd46e8354a416Virustotal results 32.79% Heodo
2020-07-21list_2020_07_21.rtfdoc cd605825d74d60677fec41c84dc39462658ebbd5edd8e29cfe9610a29291b3e9Virustotal results 32.79% Heodo
2020-07-21rep_327.docdoc 6c7da386cdaa6398c065aafedeb01b31ec959ecf615e9601a81a2c86488c4c86Virustotal results 32.26% 
2020-07-21INF-20200721-609.rtfdoc 1236dd4116a2c4ba4427175d0a3e88c848f70dc6219f6b22f1997ae3ba80ba14Virustotal results 31.67% 
2020-07-21REP_20200721.docmdoc 4e34674eaa422795c92ef9cb66994e18a57553e217b4bb4de69c1369608e36e6Virustotal results 31.67% 
2020-07-21Rep_20200721.docdoc 49b857e2068f710d1facd444264c6d8804ecc9e2ba9660953b24bbf213cc66baVirustotal results 29.03% Heodo
2020-07-21Rep_20200721.docdoc 33e64096db5340fb26c5b5d6f9b1dd89674d3a77a96a25fafcb878d9929fc9daVirustotal results 31.15% Heodo
2020-07-21file-20200721.docdoc 99c6c8f02c2fef792bc8a5a6406b0baa294156cb38b8df191f98cfb5a90547f5Virustotal results 30.51% 
2020-07-21ARC-20200721.rtfdoc cce8e5e706869261ede523822b673dd52e48d4351de8600f5ac209a7f0189629Virustotal results 29.03%Heodo
2020-07-20Dat_YDC59379.docdoc e00291bcd00edfbf9f8f55a1f34576b512404c036b744d0ce846397f8a83bb1fVirustotal results 29.03% Heodo
2020-07-20INF 2020_07_21.docmdoc 518def77204a86e55289809beda7c491b0f9ab290b10d7b4bae1c670a0f69c8dVirustotal results 29.51% Heodo
2020-07-20File 2020_07_21 66426.docmdoc f83e32a15080c0f31451809377046083d52daef3354edecea6db6ccf4158a43aVirustotal results 30.00% Heodo
2020-07-20Rep 2020_07_21 ALE2858.docdoc 107cf68ace70917126432b415c7a9b4a18e3f87c304c1ea780b1fe0950167c29Virustotal results 29.51% 
2020-07-20Inf_2020_07_21_TNX245.docmdoc 44c487bb620fcaf9ecd88961303e24f705390f3c23b0154b738fd30873832c0eVirustotal results 29.51% 
2020-07-20LIST-B07745.docdoc c0696d196c346305861f4e358f48f216dcdde4251309abed3547504007cb858cVirustotal results 27.42% 
2020-07-20FILE_A145495.docmdoc 616dde6dc6e22e28f4149e26996578dde114b40f896cee3cb36165d52ff70857Virustotal results 27.42% 
2020-07-20list 20200721 4396.docdoc 1269bdbbc40be92cc1f13918a692b34fdfeec466bd7d872863ecc405ff38f77fVirustotal results 27.42% ZLoader
2020-07-20REP_20200721_FEO302.docmdoc c6050ddd07c6d8c4aee73c52d0e50d6056ebd5f3e82550d8c771fc4353d489feVirustotal results 28.81% 
2020-07-20rep-PQF83222.rtfdoc eccf2d10cb44fb11136e2edaf7af5de351637d1479888142221354abf8986760Virustotal results 27.42% 
2020-07-20doc_2020_07_21_SWZ5315.rtfdoc ec87e9999c894cdef59c964d06c6de6c7a7134d373b4e754180d90dd5fb23f64Virustotal results 27.87% 
2020-07-20dat_9038565.docmdoc d28f9dea8c5837be7474d3735799da462ae74c0a0f3e7279a3eb8a50ba6183eeVirustotal results 27.42% 
2020-07-20Arc-2020_07_21-339.docdoc 10e15c8850925b8f03210b06fdc2e0e87bd7339bf6a185992346e2063cbe1e99n/a 
2020-07-20Rep B853735.docmdoc 3aedca3992d77371154f015834399c14aab576050a53efa01fb5714e01beb841Virustotal results 27.42% Heodo
2020-07-20inf.docdoc dc9d3da24212096b6029163166558cefcd8b37aae588dd461d9b5c02700700afVirustotal results 27.42% 
2020-07-20arc_2020_07_20_978325.docmdoc 8f282a424b1167ed2e71b2355a7c4e6797a75d031969749e3ba21050292414e6Virustotal results 27.42% Heodo
2020-07-20arc-2020_07_20.docmdoc a1064f658ecf514ba982b19196bb1ea0b7f1e85661c20777b3e93093510db141n/a ZLoader
2020-07-20LIST-20200720-7764.docdoc 6b5e8002c323071f83df953f977caf3a477d1a0c7178e0795674d263bc2dab15Virustotal results 27.87% 
2020-07-20REP_2020_07_20.docdoc 0c3330e4e8475d74677055d540545cc5474b68e106f6fe147b44c45187cb4c54Virustotal results 27.42% 
2020-07-20arc.docmdoc 3bcf67ec54f94ea28c8c35560ef2f6b2ef8090951c1ce2d0a94aebfd04a4786eVirustotal results 27.42% 
2020-07-20dat-20200720-82470.docdoc fa441d24dc18f47c3205b5c37950b44346f110e1aaf7822e5a1d7894e2eebb49Virustotal results 25.00% 
2020-07-20Rep_20200720_WC7712.rtfdoc c8b4b7e686954bc7ebd4115f98ec29527b1b0d47d1a817adebc3c6b44c26d787Virustotal results 25.81% 
2020-07-20inf_8063263.rtfdoc 0cd73a229418caf24e599b0db39e5ff3ae2903ffb83340c026c0ffa0f7e9f86bVirustotal results 25.81% Heodo
2020-07-20Dat 2020_07_20.rtfdoc c80914cd78207fba0edb12b286a7d21c3d616e6d3ff2951298af4b2ed23d9e9fn/a 
2020-07-20REP 2020_07_20 569209.rtfdoc 75eaca3fb8ce8fd803f214bd785fe9e6112990c4fd2f2c8d7148c49cd3e4c7f9n/a