URLhaus Database

You are currently viewing the URLhaus database entry for http://vizbiz.ir/wp-includes/attachments/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415546
URL: http://vizbiz.ir/wp-includes/attachments/
URL Status:Offline
Host: vizbiz.ir
Date added:2020-07-20 21:06:05 UTC
Last online:2020-07-21 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 21:08:03 UTC to abuse{at}respina[dot]net)
Takedown time:16 hours, 19 minutes Good (down since 2020-07-21 13:27:12 UTC)
Tags:doc emotet link epoch2 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21FILE_2324837558836087563.docdoc 974a9bde6fa374685e63b50d21dd8254256dd8f6418d9d65e208a465a0141f73Virustotal results 24.59% 
2020-07-21FILE_PO_07212020EX.docdoc ab0c125341cfc43f2b78b409b59b4defac478f57c6989d3197f29790d5cba907Virustotal results 25.42% Heodo
2020-07-21BAL_86743605.docdoc fe7bb6362bb3a11a4579b9c0c36fb7d1df5b57d43ff14b8b4ada2254224180e2Virustotal results 25.00% 
2020-07-21DOC_OPZ93PSSHEM1HD.docdoc a77f0d09a07d8f85b737d25216501b343e22c4e04a6f88b16dc1ab9ea1b2a222Virustotal results 25.00% 
2020-07-21FILE_PO_07212020EX.docdoc f401b333111464ea79f5ccfc7794bd0582a1bb72e06c0e9762fd8b36da24dcabVirustotal results 24.59% 
2020-07-21FILE_40262800.docdoc d40a13f38676eec40c7fc38f03d55507495374f948219045d50e6ae6af725275Virustotal results 23.64% Heodo
2020-07-21INV_92681904.docdoc 2cccb5979a562d00936dba58168f63f56806a4013284bab9f2a8e84be5eee72eVirustotal results 24.56% 
2020-07-21W_JJD_070120_WGD_072120.docdoc 003110462b096556a9d96dca0472feaa2dee2edaf6d8d0e179dc08a8a8f2b775Virustotal results 23.73% Heodo
2020-07-21INV_YRKX9MD.docdoc 76135328ce70dd5755fa54408d962b10954d6bb5c47f883a7c2bdd1defbebb9cVirustotal results 22.95% Heodo
2020-07-21PO_07212020EX.docdoc 9560e6e3b0d652ebeb93460213b2441adeda06783b641d59101d2cfe2c227307Virustotal results 22.95% Heodo
2020-07-21REP_PO_07212020EX.docdoc f2e0593ca696ec36f6b813e857b8fe6741252d7b65df42e5e16bb3c80bc7a90dn/a Heodo
2020-07-21BAL_10680001692276197.docdoc 49e7f3d18db1b3402794fa15a11d36c41d2857d4a668834b6178d0c739e2f821Virustotal results 22.58% 
2020-07-2198903091.docdoc c0a07acdba0bcb551c7783cdc1b10474c024031f6f011ee1761843ca640b1c3dn/a Heodo
2020-07-2114809173.docdoc 2786a95d643bf9b6c90e2940c4387436c45e5bcd4f88746449713a6abdfb5c51n/a 
2020-07-21DOC_40823696.docdoc 8b448dc2b315f49801c7b4d4b20a2d3163f9c9376a3c36dc4dc7a52513a101f0Virustotal results 22.95% 
2020-07-21INV_76579378.docdoc 660ff4d3124a99db58894556a3461eda17393ca94c27e075185e72536eb6735en/a Heodo
2020-07-21RMUC_7428760056.docdoc fc2bb7719f33ff249113e3c05c4b2b6fdbc99190e250b3073295e271c553f0d0Virustotal results 32.26%Heodo
2020-07-21REP_QJP74VRXX58.docdoc c5862b85395572c8c73f166d1a10c2c92a01f07540ac888627c50ebc89097e02n/a 
2020-07-21INV_585788883268318.docdoc 53b9a409018adc25ac26a608d9fae417659211d8754dbf7f07c3e4710a026774Virustotal results 32.79% 
2020-07-21JGB_070120_QNS_072120.docdoc f23c88283a5b29e45eb6658afb904be03923f73895e4f6b232f3e04e288bb715n/a 
2020-07-21BAL_UYK_070120_EVB_072120.docdoc 9312e2d0d00f48b53f5ce88ad3c874968ebb3c219e93cf1c5848021de545956aVirustotal results 31.67% 
2020-07-2124064604.docdoc 9e8362c34f689302d747bee833e604d4d7e10c7d519b401e9c9fe257bc241197n/a Heodo
2020-07-2196783528.docdoc c9d9cfb4d6f95d66b6480f5dfb60edf7b0c4581895b68dbf25a830f9006b2d3bVirustotal results 31.67% 
2020-07-21BAL_PO_07212020EX.docdoc 2c03fc75fe3490e41923ce263321de82aca6656dab7a4d95ce7334adf39a04b3n/a Heodo
2020-07-21BAL_PO_07212020EX.docdoc d6c5ff0dea2cbabf074ec5c1f7ca759925d9f469a37d4265919edf2414c60d5bn/a 
2020-07-21INV_ZLB_070120_UBW_072120.docdoc 4730939d31f08ebfd93ea7fc4230820f63862d8b509b000d67f995f57f9ec305Virustotal results 31.15% Heodo
2020-07-21INV_13347914.docdoc 296943dcba8c391e81d42bf4b7887bd2929bfa9cb511d3e1a9056ca64013f00fn/a 
2020-07-21REP_4DVAKB0L65C6W.docdoc 6d41d1aae6fa70ae47a5f974e21ff291dd1cdcc4b921dc0d1393c73384169674n/a Heodo
2020-07-21VUMESYZFISQ.docdoc e341cca78e446c93ee00c387cee3517341c104ac0587512879a602ff58871c64Virustotal results 27.87% Heodo
2020-07-21LTN_070120_LIX_072120.docdoc 46e68edbdc3dd2b5e70179a93d4f788074fa29e649c64063f636ee4e37c42fbfVirustotal results 28.33% 
2020-07-21FILE_81001700.docdoc 4b2d95bf5b48a826bdf6468d206dea367ada7fdee2c90c62dce50a599ddfef9dn/a Heodo
2020-07-21Y_CIIUQAFUAS8J6.docdoc cff09d732ea9fe1f128dc29bff9f5d5d8ff78ea22eadb52fa4b5b8d7c056928bVirustotal results 27.42% 
2020-07-20INV_7KIDP6D.docdoc 1d9333d44f7442890d84cbc3972b9d00c93bf1556042f7b58c1386365eae3c76n/a 
2020-07-20PO_07212020EX.docdoc f532fcd4387475d48960a5f0863e003f7eba0281354728bf832162a0ca5673fbn/a Heodo
2020-07-20Z_JW5155847691IX.docdoc 49f90436f418a86b0f4e55e14bcf74793954cc90596ad08dfb6355a1e50a8f27n/a Heodo
2020-07-20REP_UF3WQBL0L6T.docdoc d94cea8ea634ed8d8de82348acb5c417260d48a0f2b559531624b67f776c660cn/a Heodo
2020-07-20FILE_2ADW704LLH.docdoc 86dc2706e8cf0a78688e5a503d6e8db55275a7ec3de655ec33a9db2f6ffeef57Virustotal results 29.51% Heodo
2020-07-2084742084.docdoc f073a991092d0dc2ca2d7308e64b58992ce0cb00fe5da928b65b58530c10e7a9n/a Heodo
2020-07-20FILE_UW01LN536WHQAWTE.docdoc 4ec7f2a0359b740dbbc849705f2856818bccc8fafa5a2237fd79640e61423255Virustotal results 29.03% 
2020-07-20IDH_VWR_070120_GQY_072120.docdoc a6ce3b9c522d36ac4e91cf8e2cf1581bc9d7e6548f1e66ff998e11662f6894cbn/aHeodo
2020-07-2059083MY2RUH.docdoc 148aa06dceabdc99c7588bd48277867f3d0528fcf04463562707fd66f953045dVirustotal results 27.42% ZLoader
2020-07-20DOC_PO_07212020EX.docdoc 3886724a53ad93931a6339f285e19c703a1bb1dadd7e348ca8dfca75ad42aef3n/a Heodo
2020-07-20DOC_PO_07212020EX.docdoc cfb6588d9181a97aa1f93b2b9f8af82134836e916938a80a217cd03fe4294811n/a Heodo
2020-07-20BAL_8768600194.docdoc eb0f6632e1ec41f11634db7c691a38cdae71cd06268568eebbd34ad96fd37618n/a 
2020-07-2016819675.docdoc 8163146178e6d55057843fa5f0da1b851d049bf802aea69b44aaec7352be33d4n/a Heodo
2020-07-20PO_07212020EX.docdoc 33c897cc3c1d11687231644af13032e24358c594f4b484a7040a3eeecfae7145Virustotal results 27.87% 
2020-07-20PO_07212020EX.docdoc a935d27654c333b2c9a027bca4372aee2db007a8fd90fb365bdceab1f2a7b0c0n/a