URLhaus Database

You are currently viewing the URLhaus database entry for http://afranoor.ir/admin/lm/gfgx8psoojpg/u9eu45949356gty80e7syvb/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:420608
URL: http://afranoor.ir/admin/lm/gfgx8psoojpg/u9eu45949356gty80e7syvb/
URL Status:Offline
Host: afranoor.ir
Date added:2020-07-28 10:42:11 UTC
Last online:2020-07-29 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-28 10:44:03 UTC to abuse{at}ovh[dot]net)
Takedown time:21 hours, 45 minutes Good (down since 2020-07-29 08:29:13 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-29L_2798107656562725275006.docdoc 9ee009dea50f0125325d62473cfe14613ca3098555ff14345600be9cb1add50bVirustotal results 27.87% Heodo
2020-07-29BAL_39216774.docdoc fccf70d8d89e60e1121cdc6b1ea78acec628a2f192e60810ec0948a20808fcafn/a Heodo
2020-07-293XNP4BWTBFZSC3V.docdoc 6a41216f74505746cd9e27126335988cc5ef4727fc68e2375fb50dea917e4a0eVirustotal results 46.77% Heodo
2020-07-291345004229820280147623637.docdoc 5d022a451650f6f56f406617294a4445538b97a8f88aa1b89e72480f34ba8bc0Virustotal results 42.37% Heodo
2020-07-28A_PO_07282020EX.docdoc 3ed97b5c98bb43b9d6a5042b5617ddebe018c780836be36dfc96b78865a851den/a Heodo
2020-07-28REP_58577444733438916981.docdoc 23e1d0fb6402aa2ac81451e4ae00536b42dccd9afec3acb8aa10031f79ecf7b3Virustotal results 40.00% Heodo
2020-07-28REP_SDT_070120_HPY_072820.docdoc 3ede822580b26357e4126b461a884666c12bb750fc30415502dfc452f5b04c30Virustotal results 39.34% Heodo
2020-07-28INV_36257350.docdoc 8d27e36fe079fffb278a007a07dbcbfb37ae765b71bcefb8e0e41c4a70101512Virustotal results 40.00% Heodo
2020-07-28REP_PO_07282020EX.docdoc 3cfa0e1a69a37f7910cab652ceaadb108f9d26c5bd3b377d3d6ccb0e09de15d0n/a Heodo
2020-07-28INV_44015625.docdoc d9e1b8b8313a688c0096c914d0cc62aed82170a3e85263d69ef058de2d978b15n/a Heodo
2020-07-28BAL_PO_07282020EX.docdoc 78343bb65eecfad5b62d2de0e25b21a708b837293f90cfd6b1bdd8e8cb7d8014n/a Heodo
2020-07-28BAL_09154228.docdoc 8568762e1933e7b9acb305ef10ceef97fae4501ae0f805ad873393f9459fa229n/a Heodo
2020-07-28PO_07282020EX.docdoc 2099d5d04c39f86f1da8058861951deb8c6ef875e5a77272709f711e80a3d998n/a Heodo
2020-07-28REP_DWM_070120_TOM_072820.docdoc dcab281c030ca8ebd833b95d2379df634eec571e1ae19b6aad70ae1a0eb2e07en/aHeodo
2020-07-28REP_DWM_070120_TOM_072820.docdoc dcab281c030ca8ebd833b95d2379df634eec571e1ae19b6aad70ae1a0eb2e07en/aHeodo
2020-07-2852BAS5NBZL1CZP.docdoc 7880dbee79353af6a070ba20eda972b3ef7abad67d3c309d064ced44676ed6e4n/a Heodo
2020-07-28INV_58661860.docdoc 23c51d3c717104427e3ee990c8db28900701083c086707b24493ad7f9968be97n/a Heodo
2020-07-28PO_07282020EX.docdoc 774e1d5f651e05ecfc169249d2a301bfd4f8e8d81b85bd3683a9b0ebd8b38281Virustotal results 40.68% Heodo