URLhaus Database

You are currently viewing the URLhaus database entry for http://www.behnasan.com/wp-content/VR7NLT9EVPE/1n0169378753r01n1p9u1djp2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420207
URL: http://www.behnasan.com/wp-content/VR7NLT9EVPE/1n0169378753r01n1p9u1djp2/
URL Status:Offline
Host: www.behnasan.com
Date added:2020-07-27 21:42:04 UTC
Last online:2020-07-31 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-27 21:44:02 UTC to abuse{at}greenweb[dot]ir)
Takedown time:4 days, 0 hours, 51 minutes Bad (down since 2020-07-31 22:35:53 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29PO_07302020EX.docdoc b245805e1a553f1a05d0134840470a89f548db0174672b5e39661a47d913c6c0n/aHeodo
2020-07-29FILE_FXN_070120_SJC_072920.docdoc 85586aed0ec99352b1a7641827523f66047222df673d56eaef2318e8cfe5d325Virustotal results 36.07%Heodo
2020-07-29BAL_46410535.docdoc a1337b78d948a4c579b396e2c35ae69111e6af596065944b6730552491a80d21Virustotal results 35.48% Heodo
2020-07-29FILE_3211415490431686744933681.docdoc 16f48852b646cab90797038aae4ecb796a246b881639100a6535548ab71c5923n/a Heodo
2020-07-29REP_63622241.docdoc 509e5ceff7eb6060dcdfecb46ff0cc25302b21a0086e73f472d6a87e5a30b26dVirustotal results 34.43%Heodo
2020-07-29A_70868504.docdoc 05612fc5c4f0acd9a581eca6977bc24478a500aa78b12f94579a7d056a9282abVirustotal results 36.67% Heodo
2020-07-29FILE_73257908.docdoc 39f28c14674ed1898fe5df53a01fab71443be457d07275b06f69f33adb6ea07eVirustotal results 36.07% Heodo
2020-07-29PO_07292020EX.docdoc 61be402d01ef60907ecb10271e98676d6e061ed6ddc0e7d6909589ffd22eef0fVirustotal results 35.00% Heodo
2020-07-29INV_PO_07292020EX.docdoc f1175d64cfa9bd48060ca1c9a55ffbc0ea4e9c9f11f776735540a5df0cbf998eVirustotal results 35.48% Heodo
2020-07-29W_PO_07292020EX.docdoc 7cc0e0d42675739a03ee7a45f6f70ba77f5586f1757dca8f793b25daf607f7e5Virustotal results 36.07% Heodo
2020-07-29G_PO_07292020EX.docdoc 9ca463088f63078936689452eb9fbbf48f0c4e7efaa553174c1990d90f5e8530n/a Heodo
2020-07-29DDH_070120_VGI_072920.docdoc eab8382b9becd262d347b0fac413cb0096a14d277206285af5e5ddfb459cec40n/a Heodo
2020-07-29W_AQV_070120_IYY_072920.docdoc 00c59b668bfe3ab47965ee4f4be120376e079ad753b9a6cbdcae4282afbf7badVirustotal results 33.87% Heodo
2020-07-2913868812.docdoc 727f2b57969b68dc6e79c694c096bf3420cc788db33ec0f47193d70ce11fb20fVirustotal results 34.43% Heodo
2020-07-29INV_71136973.docdoc 79ba06b6a2ed7e51bc791c84bd9a3fc467aac335a7e0ab848243f463a440f0b3Virustotal results 35.00% Heodo
2020-07-29D_68947293.docdoc 3d0f47c47fbc6cfee2fb276f433b21cca723df51f5c2a24b876cef35c936e81eVirustotal results 34.43% Heodo
2020-07-29J_RDS_070120_GYR_072920.docdoc 09b48077de19d52dfbc9b6d2c88ca02edd8faef66106d41aa7e6ce017667ae50n/aHeodo
2020-07-290Y8VSVIL7E7KY.docdoc 2b446f962d60ae78cb353c325d1371e6526cb8315092524b2709b9c2eeae6753n/a Heodo
2020-07-29INV_ZGQ_070120_ZXM_072920.docdoc 4a406747cc4af71f72229df7ddbd5c6858984101d67e93ab864273cdff151823n/a Heodo
2020-07-29INV_XM5386165967CR.docdoc 2795b0334a75bb6cd8f1de4fb4b536c930717e85db6b6c69abf38130fd9d0220n/a Heodo
2020-07-29ILEN696A8YTCG33U.docdoc 0cbadb841dc2c7d6152c653d711cd5ac8ca759142231e728789ff256b2d9a7e4n/aHeodo
2020-07-2934755163218.docdoc 9c24d6fd85470958aea67d26f6293c5d8cb091ccac7299fcc6c243ff90382cben/a Heodo
2020-07-29G_PO_07292020EX.docdoc 4046d4baed8c5cbed9936f09919edd39c697922a01e56617feeba4e5957164d9n/a Heodo
2020-07-29GVR_18991808.docdoc 4947e47ca102585589473567e7e3f0e8b9051aea7f9d08ee1409ddb7ad6bd2e9Virustotal results 28.33%Heodo
2020-07-29DOC_PPA_070120_LQY_072920.docdoc ea0c4bf37a77d48ec55e6fd331d26c6efd0c643194ff2c6919b8f975f0562e7dn/a Heodo
2020-07-2942634869.docdoc e5f86234f39d86f44946089d600b3d4244a9e7f9700d6d0e167c8b8821b22e05n/a Heodo
2020-07-29DOC_KQ9117934748ZR.docdoc 5a959afcb67ab697d8f53e2e91f7424fb274bee1600360681f6b61c26e377fd7Virustotal results 28.33% Heodo
2020-07-29BAL_PO_07292020EX.docdoc 255028b13e1798a9210c65582ec63fe7da4f42e7a9cb9f68ebd049b60ebc6219n/a Heodo
2020-07-29PPI_02827683.docdoc f2079fe72b86eddb5c15d9b80c2cc59076a08c0fbbacc4663d5573f5fe40e88dVirustotal results 28.81% Heodo
2020-07-29DOC_44315121.docdoc 5aa3782f329a744d9e986c602f77efc5a7103e056f7eb43db157d466d7268ab6Virustotal results 27.87% Heodo
2020-07-29S_64840287.docdoc 93d8b1a56a79f7cd3f62c1545594be31cc4ad4e5684e690d64b607c6d0fe0e42Virustotal results 27.59% Heodo
2020-07-29YJQM_TPV_070120_GFC_072920.docdoc dbd8762c7d8b9348a509e890f68a6c74aa1f60d81f6acad63ad3b56dd3337e8aVirustotal results 27.87% Heodo
2020-07-29FILE_PO_07292020EX.docdoc 74135d57c55d6142f0678a1f28259364b24907bd824f953dc77b3ba7f10648e4Virustotal results 28.33% Heodo
2020-07-29INV_55084288.docdoc 075c7bee49676a5bfce88288211ed92365f0a09e0d5c16e01ecb04398e9ba991Virustotal results 27.87%Heodo
2020-07-29BAL_SGX_070120_HYC_072920.docdoc 708c713500d5f5ea3886be172718668ca7014a38b8d3d1bd37ab37b9499690b2n/a Heodo
2020-07-29XBAH0YZ5A.docdoc 10bff4abcb10a44b3d14435988ead41d1468bf4dc8fa4fc184e0babdac5ae73dVirustotal results 26.23% Heodo
2020-07-29FILE_PO_07292020EX.docdoc 9ee009dea50f0125325d62473cfe14613ca3098555ff14345600be9cb1add50bVirustotal results 27.87% Heodo
2020-07-29FILE_KT6499261282IW.docdoc fccf70d8d89e60e1121cdc6b1ea78acec628a2f192e60810ec0948a20808fcafn/a Heodo
2020-07-29X_57547359.docdoc a1774a6485655119ea70b0979992d361b648420fb0b003439e52adff57c241baVirustotal results 47.54% Heodo
2020-07-29REP_PO_07292020EX.docdoc baa488f3a77d501d8ec7735d3df63912a500ac36a4daeff60abd475795b9343aVirustotal results 46.67%Heodo
2020-07-29PO_07292020EX.docdoc 9e3690a0a71dc239833dddc5b2aa94983eec61d88a636aa96f12bcfac9898592Virustotal results 41.94% Heodo
2020-07-29ZE_42540065.docdoc b3ffca228d4d444172e54cbafb591ce0d37193492c7775c7dbf7e8c8e6bc00dcVirustotal results 42.62% Heodo
2020-07-29EJEB_32878924.docdoc f01b3323117582e282add297541e14c3b0d359ab03af884367f2d4c562750425n/a Heodo
2020-07-2902157750.docdoc 3de845b9dc4ad5aa22fd3587bf71351eda91ae61c1003f4df40c75bf422f548cn/a Heodo
2020-07-29BKW_070120_QNQ_072920.docdoc 2e0013ae11fd80f2fcbd8488a53d6931d5cda77bb542e026cdca5c602ae4c3e1Virustotal results 42.62% Heodo
2020-07-29UHE_TAATS09D8S2P.docdoc 6370801cfa9c5207d9891ac6bce41478e5f4d52c83922ec87b94af39195aaf65n/a Heodo
2020-07-29K_06J6APB4.docdoc 1f19f1cc91f28959e4f1a099b4f6d11a2dfd3b5d5ecf73f596b764dfdc356b57Virustotal results 42.37% Heodo
2020-07-28INV_10158166.docdoc 7b0638d749631d97044b3b3d44388979a43abd48143abf524df03335eeb290cfVirustotal results 40.68% Heodo
2020-07-28YY_ZLL_070120_CGG_072920.docdoc 26c4e8ead2701556bd3d09795db4bb4cd554b40cf9f30b9e76b7434c0e6e96fbn/a Heodo
2020-07-28REP_PO_07292020EX.docdoc 63c74b892d39492d60408cece9e71cc78d5bb63eb8f598ad5d4f1f375c2745fdVirustotal results 40.98% Heodo
2020-07-28DOC_I4N6JBKF2T0H4.docdoc 50563ca2e8c59a4a909655f6fc73f1b3700042972dba5cf08ccd036321098da5n/a Heodo
2020-07-28BTY_070120_OOV_072920.docdoc 942f521ccdd9490b25a14dfdb03ff9e8ff7bce4d9d0ad9c5a5fe684216b81579Virustotal results 43.33% Heodo
2020-07-28PO_07292020EX.docdoc 462d953bcff28b211276e898a81f38ce8cce30d3643e78580610b85d2be8daf8Virustotal results 40.32% Heodo
2020-07-289092236472.docdoc 040eb6591f2ab93e8868b61948d73fe36651ee8af6e4f2ee985708a9ec43126an/a Heodo
2020-07-284CXP8LK6X.docdoc 97d5842fe4efaef26c0274fe3aecd3a2218c4aaa83693f46788da63b6b9a5a25n/a Heodo
2020-07-28Z_43299994.docdoc 9ba684d3bb94c46b9c7476bf8ea2ecba98cc9e6975bb465242081e17e69ff0b1Virustotal results 40.32% Heodo
2020-07-28NJC_LY9IIC5FXD.docdoc 87135faebfc31f34c94e02ffd43281b0e6cc7055ec6ef5eb5d60b29df1009c22n/a Heodo
2020-07-28NJ7430393562GY.docdoc 9bf049c3356bbba6bc9e82bd698a785902daf6069e90ac638d402f83c4cd9d59Virustotal results 40.98% Heodo
2020-07-28UQ_TG8369531392WK.docdoc c3c5633aa6844b78f5fd68ab867c7f0ee8c3cb63387b2b497ea29bcc8566a2f6Virustotal results 39.34% Heodo
2020-07-28INV_PO_07282020EX.docdoc 5a5a1de568829f744aa5dafeff7301a0cd703b4815e4be3a77f7dfca352438bfn/a Heodo
2020-07-28INV_PO_07282020EX.docdoc c2dd657c048f69cc272050ec717b2c8d31cb310b02e2fc5bd920783a0cab340an/a Heodo
2020-07-28R_PO_07282020EX.docdoc af26c866db5ba35031339b3165820e6b21f8dd848ec1bc66c960a8d8de2fc31bn/a Heodo
2020-07-28BAL_IM3758271880ZM.docdoc 271265337665d4b6dcfeba3d1e2acf6de92e94f23c3c82b272dfac52c38fa571Virustotal results 43.33% Heodo
2020-07-28RIUA_PO_07282020EX.docdoc a6858e9165456c23bb7896862f4d3ec153bee00b02c3b2598e0f8f1cd3cb1b39n/a Heodo
2020-07-28INV_31500860971504973.docdoc aee8c34f1c430fedfc697089732e0d51939863f4253fb7455be1773ffea8de0bVirustotal results 42.62% Heodo
2020-07-28DOC_79044058.docdoc a44f6b82eb6565507c10805b73d3bee4da269d02c659532abe1f4a278c9446a4Virustotal results 42.62% Heodo
2020-07-28PO_07282020EX.docdoc e0c8706f01f812beb106bfb124ddad3456dd4e33159910d1c9588ac63e00c2abVirustotal results 42.62% Heodo
2020-07-28XQ2021777395MS.docdoc 181a733145822f0c1256bd24fd8e19ff7f1217f6166e56dafb7075bf6fc54a06Virustotal results 42.62% Heodo
2020-07-28BAL_70872531.docdoc cfe67567737aa3c2dcdec28c0d6873e5e340c8ad049faa917c527f54e1c1875dn/a Heodo
2020-07-28INV_PO_07282020EX.docdoc e85502045fec3d9af13567ce4608221f4b92f8b0262e4bae4dd305385079e63bn/a Heodo
2020-07-28PO_07282020EX.docdoc da3bcdea8cc3b33756792fdfa11bdef92dd36e4620ada8b660fc12cc211b4281Virustotal results 39.34% Heodo
2020-07-28DOC_PO_07282020EX.docdoc 9c8f04c408fe3170c3f9d50092fa7bc79b072ac1bfe7c985dd2887d8581242f0n/a Heodo
2020-07-28INV_720467111015318775.docdoc ed68893c9c4a4e3abfcfa85ca077b8d013605d2994fdd6c42b2858cdc2bd30d8n/a Heodo
2020-07-28NHB_070120_INM_072820.docdoc 33892c4fb618745a9020642ae7ab40da499637463bad8dfde420034b8f9c92a0n/a Heodo
2020-07-2877233208896.docdoc 3462186176f663901dcf8db6383a21ecf0995c392966bd5e17f518fb7c0f6961n/a Heodo
2020-07-28R_32142890008353244.docdoc 878399ac6fca1894c7e9acc48eddb6a535513a4fc7b0b8aa410b19c0f85cf361Virustotal results 38.71% Heodo
2020-07-28QWF_070120_UON_072820.docdoc 6277f4f92177c8a9d172a70df991b4b7d04cff62b0f2e04e78d277d2aa648411Virustotal results 39.34% Heodo
2020-07-28R_53874740.docdoc dcab281c030ca8ebd833b95d2379df634eec571e1ae19b6aad70ae1a0eb2e07en/aHeodo
2020-07-28DOC_TR7801939323AK.docdoc 4fdb97a98c47101b9d2c0308f3c3a9d4fd53c97fd7a0d7937ee3f292c51f8757n/a Heodo
2020-07-28REP_BWK_070120_XIS_072820.docdoc ed4024fce07b85826628652c11e196b53b0633533386c39e09fe15bd4cb57a83n/a Heodo
2020-07-28DOC_OP5557727467BL.docdoc 69314a5a40529facfde61bb78562869e4ca9a67ba69a3028d376a265e174ea6cn/aHeodo
2020-07-28REP_X0F7NT52FIDY9U.docdoc 0908f65f4fc6bbc55135748a1dc9f8120e504195f01caefafb80e6d7639f32c8Virustotal results 39.34%Heodo
2020-07-28REP_PO_07282020EX.docdoc 8a02a02bf39b80d809da634fe105c29a2b012acfa59c4eaedd94360fb5fbd2e3n/aHeodo
2020-07-28INV_JK5557965424ZX.docdoc cf482eff94c49c1487a1c7c401c67865d9df95c86e576a6db7186b5f85e046fdVirustotal results 38.71% Heodo
2020-07-28F_PO_07282020EX.docdoc cd8165b730d0801f2eb1524b1a430abe1d69e7105b2a898fbcca440afafd8f01n/a Heodo
2020-07-28DOC_ZDF_070120_CLY_072820.docdoc 502f2432a2c035f0d1f94c39051d8f92b1600da2fc0510fdaa6f6e2419f888c5Virustotal results 37.70% Heodo
2020-07-28REP_80516833.docdoc fdde330e67f0b2cf2cd499acbcbbcca1a12933d471fcb2da5fc9fcac5ddf188bn/a Heodo
2020-07-28BAL_58234692.docdoc e515d978a1880553c889434a86aa3300f62c9893cacb5682ad990fbd53808de0n/aHeodo
2020-07-28FILE_JR6769784587OB.docdoc 1f2d563a9cc13dacc7e5ca5d6b8745f38a4244777fc5ebde045785790441b196Virustotal results 37.10% Heodo
2020-07-28SJUY_08704466.docdoc 20d81ffc64ba89a114dc4ee30c643d555945ab0ec0f3a17c96b56d6087ef3b13Virustotal results 42.62%Heodo
2020-07-28BAL_YNUHFLNKMGK.docdoc 3bd36ab32026af0a6cb457a12a0ba75df13d8e6a288da64ca838af0bef9c2e24Virustotal results 44.07% Heodo
2020-07-28WT604S66.docdoc 4b0e153c6b865d8301d0b569169faf4acbe77703f624f14215b5b5b04759462bVirustotal results 42.62% Heodo
2020-07-28FILE_PO_07282020EX.docdoc 1e687ad756dada51e71738e9b4af3eedc481d865f7df0bd32500ea50bd16233aVirustotal results 42.62% Heodo
2020-07-28K_VMS8A37L3QXU08I.docdoc 388d49d105196dea02e96ac0172560dff1d9862e5b8910e7af963585439dbde3n/a Heodo
2020-07-28PO_07282020EX.docdoc 8cb2ee65b209dc77c33984c49bd4ed006fddd9fb40132c166c494f47cafbd5bfVirustotal results 42.62% Heodo
2020-07-28C_6847263782591.docdoc 29c42aa5892fede943d2975f64abfccbcc8cfa164a85e278753f970a17d010den/a Heodo
2020-07-28BAL_PO_07282020EX.docdoc 2b4263841c81074211dd59e820bf05562e5c59be8d38bf8791a0a21753cdf504n/a Heodo
2020-07-27028880177305264440441.docdoc dd1fe9f11a267149ce356a768d071605c1972fd10d1f7a57a29fe8a2c8fb41c1Virustotal results 41.94% Heodo
2020-07-27GWH_070120_JXD_072820.docdoc 3e21349ba3bf686515975146afcebe14651b2304ec58b47bea6b87b5fbc79a69n/a Heodo
2020-07-27BAL_40H6J4UN.docdoc 2bd01d881217785295064f5e2d94720a9d0952d1ee3888349b008bce7cf5dd8fVirustotal results 41.94% Heodo
2020-07-27FILE_50857762.docdoc 0a2efb0dfe85f3fb776bdfaf83eb0b8b4f17d2f52d4a75552928b1ef7ff1f76dVirustotal results 41.94% Heodo
2020-07-27PO_07282020EX.docdoc 2ae67471c658ada5648053a5da6b55d64bb0f6de4ee16ebfcbc335055b398f1bn/a Heodo
2020-07-27INV_48852764.docdoc df3f07a28988e65741321c968afd02eaf8a49fa2dcf2e2f2685d04e13a236122n/a Heodo