URLhaus Database

You are currently viewing the URLhaus database entry for http://sngp.ir/wp-admin/parts_service/fwjopp87287710fjozromldg5c3ijf/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415498
URL: http://sngp.ir/wp-admin/parts_service/fwjopp87287710fjozromldg5c3ijf/
URL Status:Offline
Host: sngp.ir
Date added:2020-07-20 20:03:04 UTC
Last online:2020-07-21 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 20:04:02 UTC to abuse{at}respina[dot]net)
Takedown time:17 hours, 23 minutes Good (down since 2020-07-21 13:27:12 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21REP_PO_07212020EX.docdoc 9d29290a0e2c6f3801444df8141e4099b9d87d0d3d3ba984bbc9d9684fcb5511Virustotal results 24.59% Heodo
2020-07-21M_AFH_070120_VTG_072120.docdoc b4f865e3011a63a5b8a0da14876282d97d5144e153f8316025555d276602d335n/a Heodo
2020-07-21FILE_70125852.docdoc fe7bb6362bb3a11a4579b9c0c36fb7d1df5b57d43ff14b8b4ada2254224180e2Virustotal results 25.00% 
2020-07-21FILE_369107244.docdoc 4501457e1fae31cb83a1d2818d169525f75627a017efc573932fd412e6e2c406Virustotal results 24.59% Heodo
2020-07-21T_BE01UNCJY7EE94OK.docdoc f401b333111464ea79f5ccfc7794bd0582a1bb72e06c0e9762fd8b36da24dcabVirustotal results 24.59% 
2020-07-2127436724.docdoc d40a13f38676eec40c7fc38f03d55507495374f948219045d50e6ae6af725275Virustotal results 23.64% Heodo
2020-07-21PO_07212020EX.docdoc 2cccb5979a562d00936dba58168f63f56806a4013284bab9f2a8e84be5eee72eVirustotal results 22.58% 
2020-07-21KFF_070120_VFG_072120.docdoc 8969bcaa62533ea3d1c200c02009112d2d21e5b51ec3500698935d4689d46265Virustotal results 22.58% 
2020-07-21UK_KHF37WB.docdoc 76135328ce70dd5755fa54408d962b10954d6bb5c47f883a7c2bdd1defbebb9cVirustotal results 22.95% Heodo
2020-07-21PO_07212020EX.docdoc 7205124c976d15cd097c35d5c82d63d616b710da7b82ead06faecf91fd620405n/a Heodo
2020-07-21REP_55492684752.docdoc 09828f45a3ecb9732b256236d772b4af278b4d4855c7ed217c1a7d7ea21ef296Virustotal results 23.33% 
2020-07-21XV7985867505QO.docdoc 49e7f3d18db1b3402794fa15a11d36c41d2857d4a668834b6178d0c739e2f821Virustotal results 22.58% 
2020-07-21ZDJB_6695342995267.docdoc c0a07acdba0bcb551c7783cdc1b10474c024031f6f011ee1761843ca640b1c3dn/a Heodo
2020-07-21PKE_070120_BCP_072120.docdoc 2786a95d643bf9b6c90e2940c4387436c45e5bcd4f88746449713a6abdfb5c51n/a 
2020-07-21K_19869618.docdoc 8b448dc2b315f49801c7b4d4b20a2d3163f9c9376a3c36dc4dc7a52513a101f0Virustotal results 22.95% 
2020-07-21ZTY_53462509.docdoc 660ff4d3124a99db58894556a3461eda17393ca94c27e075185e72536eb6735en/a Heodo
2020-07-21REP_FPJ_070120_VDB_072120.docdoc fc2bb7719f33ff249113e3c05c4b2b6fdbc99190e250b3073295e271c553f0d0Virustotal results 32.26%Heodo
2020-07-21DOC_F5X0ZTRJQ.docdoc d604f20c04d25e448176ddfdf3e01865091590cdf5f2cd2c42eb9af7cf41c718Virustotal results 33.90% Heodo
2020-07-21TJF_070120_MZN_072120.docdoc 53b9a409018adc25ac26a608d9fae417659211d8754dbf7f07c3e4710a026774Virustotal results 31.15% 
2020-07-21PO_07212020EX.docdoc f23c88283a5b29e45eb6658afb904be03923f73895e4f6b232f3e04e288bb715n/a 
2020-07-21BAL_PO_07212020EX.docdoc 41239e9448583b6a09ec8574d34295b254dec60348e219d0a1355467c3ab37a4n/a Heodo
2020-07-212972290794137255397.docdoc 9e8362c34f689302d747bee833e604d4d7e10c7d519b401e9c9fe257bc241197Virustotal results 32.20% Heodo
2020-07-21REP_MX2399148239XV.docdoc c9d9cfb4d6f95d66b6480f5dfb60edf7b0c4581895b68dbf25a830f9006b2d3bVirustotal results 31.67% 
2020-07-21GI_NT3229210987JM.docdoc 2c03fc75fe3490e41923ce263321de82aca6656dab7a4d95ce7334adf39a04b3n/a Heodo
2020-07-21IISA_HCC_070120_LHT_072120.docdoc d6c5ff0dea2cbabf074ec5c1f7ca759925d9f469a37d4265919edf2414c60d5bn/a 
2020-07-21BAL_3CKZKRTZHRE6T.docdoc 9953004cdba2aa71a7552b41ec9b4718f1fcf03abe1589629ce524746cece259Virustotal results 30.65% 
2020-07-21584264944.docdoc 296943dcba8c391e81d42bf4b7887bd2929bfa9cb511d3e1a9056ca64013f00fn/a 
2020-07-21FILE_SNWRMTI81Z6YR.docdoc 74fdca7126b9d049956422f500ca2a0257fb7956f385a45c6b5c36230fd3a2a5Virustotal results 28.33% 
2020-07-21DOC_2HDMFG6IPE.docdoc e341cca78e446c93ee00c387cee3517341c104ac0587512879a602ff58871c64Virustotal results 27.87% Heodo
2020-07-21REP_NL8458829345UX.docdoc a7f4f8b9dddb70414bfdbbffd5c446c88b517c104a441be19151c8a711133686Virustotal results 27.42% 
2020-07-21SEF_PO_07212020EX.docdoc 229710df49bb17b78fae2414fe4ff138609fdbbe410dc297f49d8b7bf10ad109n/a 
2020-07-21YB1015959526PD.docdoc 9f082f2eeb02660ab639991cade576f8a7f72990579ddb87315b51374e11fc18Virustotal results 27.87% Heodo
2020-07-20REP_OHB_070120_HUP_072120.docdoc 5ef34d47ef171a2b5cab01782a4a45d9a12f01d70dde381936b6975ca93dfad7n/a Heodo
2020-07-2057484218617052980.docdoc 2a7edcd4009ca88459bd2ec64af866f700abb7acb68cc5b13a40315c51976df7Virustotal results 28.33% 
2020-07-20VX5674321319JQ.docdoc d94cea8ea634ed8d8de82348acb5c417260d48a0f2b559531624b67f776c660cn/a Heodo
2020-07-20DOC_PO_07212020EX.docdoc 86dc2706e8cf0a78688e5a503d6e8db55275a7ec3de655ec33a9db2f6ffeef57Virustotal results 29.03% Heodo
2020-07-2061948400967182437232662.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-20DOC_2796622412076012543979568.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255Virustotal results 27.42% 
2020-07-20BAL_PO_07212020EX.docdoc 53dfc48b5b049b05895bc4e2e5fca037946e69d083cdac2e6c222b76c86f4763Virustotal results 29.51%Heodo
2020-07-20PO_07212020EX.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dVirustotal results 27.42% ZLoader
2020-07-20MNDK_WINY4M2UE9.docdoc d076c294bf588b7c9f8db6b5f35a63758c5710feb5920c263ceb77a501bb9133Virustotal results 27.87% Heodo
2020-07-20REP_D8SG7OYV8VML1.docdoc 24801ffebf7c96489c02613a4cc1fe277a4b1aab78bf4034145167ab19ae657fVirustotal results 27.87% 
2020-07-20FILE_MIU_070120_YUO_072120.docdoc 401dadd7c1211dae181b8767949d274790aa4fb72e78a3d57ae92ac2cf925da8Virustotal results 27.87% 
2020-07-20BAL_PO_07212020EX.docdoc 8163146178e6d55057843fa5f0da1b851d049bf802aea69b44aaec7352be33d4n/a Heodo
2020-07-20PO_07212020EX.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20E_700048817530022.docdoc 4fdba539896383e37ec2383fb569df4f17395dd40115ba8caba62127b7ebe949Virustotal results 28.33% Heodo
2020-07-2060652344.docdoc 70fd23e6a829661f7fe775e5b73c20b09a4dbeb5b97648d0851dde0591a3b304Virustotal results 27.87% Heodo
2020-07-20T_PO_07202020EX.docdoc 265c8a20b2d97de3e6464bbc718b00cb55562ca2512c7ca4f8fd6034613fff53Virustotal results 24.19% 
2020-07-20FILE_PO_07202020EX.docdoc 8811f4498f1b1d8729556a61a5683ce20c4270a64ee5ad0223185110adac5f2cn/a Heodo
2020-07-20OLZQIQ0V.docdoc f479686dfc59c7e2cf8607ef958b067288d47d2de6a92db1b0c1268b9862f42bVirustotal results 27.42% 
2020-07-20BAL_AJA_070120_EKG_072020.docdoc 8895dd40aa0da4cf1f3087db7cb003067025c7baba71478699d849d2f419d172n/a