URLhaus Database

You are currently viewing the URLhaus database entry for http://ofishyar.ir/css/closed_SoNrk2AO_G4dH87KGO/open_forum/XTHK2_vd2KkJM5Jw28/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:432659
URL: http://ofishyar.ir/css/closed_SoNrk2AO_G4dH87KGO/open_forum/XTHK2_vd2KkJM5Jw28/
URL Status:Offline
Host: ofishyar.ir
Date added:2020-08-13 23:27:07 UTC
Last online:2020-08-15 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-13 23:28:03 UTC to abuse{at}faraso[dot]org)
Takedown time:1 day, 12 hours, 53 minutes Poor (down since 2020-08-15 12:21:40 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-14rep Q956.docdoc ef74176e721ebca726eef481f3a962d2d56d605bf9ec1cb3c5858a1fbc61b07dVirustotal results 37.93%Heodo
2020-08-14dat 20200814.docdoc eb8626c09f81f7723ee7afa0cf39e78db7be79b5e5522f82ed7c116eb5fae52fVirustotal results 37.29%Heodo
2020-08-14rep_20200814_KGI8185.docdoc 3fd35a3cc362b58b5c94ac63923bf17f681cd3e9c9c3fb349071d87b758d3686Virustotal results 37.29%Heodo
2020-08-14FILE_2020_08_14_E649.docdoc 7a37b617ab9dfd1a2b7f090067cde1c83470fd44cd6090994090ac04638304b5Virustotal results 38.98%Heodo
2020-08-14MES-2020_08_14-567.docdoc 750f4237628ffd460893c6534883f476f6d461970961beb9c1222b05b59d2c2cVirustotal results 37.70%Heodo
2020-08-14REP_20200814_CU25242.docdoc 6280278fef02126376fca03e39598bb3c17632cafd9fa99d26694b43c73da6c2Virustotal results 37.70%Heodo
2020-08-14DAT-EVC95815.docdoc fe72004e6a838fcb078f8b14b9e31e68d627ab0aefdf9bd24c5e9db91e96f4f9Virustotal results 36.67%Heodo
2020-08-14DAT_2020_08_14_L989.docdoc 2465fb97adc0bcfd2852bc97bf6a929405c2b0c8abb85b57d294befdefbac099Virustotal results 35.59%Heodo
2020-08-14Dat 2020_08_14 987.docdoc be002af97ec2cdb43edc083f492340be1995195c05bcd860b3268acb96e2c539Virustotal results 35.59%Heodo
2020-08-14Rep 2020_08_14 3786.docdoc a5aaa7a63b5ec81fdfe4916e720a21e4df252c2d3823d6558f0593cb1f4f65a3Virustotal results 36.07%Heodo
2020-08-14inf_2020_08_14_6616336.docdoc efd285d45835c318c4e079fae4840399a89ae40bf6134dac6cef9e7483e9680cVirustotal results 36.07%Heodo
2020-08-14MES 2020_08_14 2952.docdoc 1c09a7e4afcf582fb0ae2170a0375571dcc9ae463e6c9f29770a590039704a44Virustotal results 36.07%Heodo
2020-08-13File-20200814-HJH6150.docdoc c660380b581ba0b1e12f563b83f542961d51fcb0b0e7d052a1b5dafe83718eceVirustotal results 35.00%Heodo
2020-08-13ARC 20200814 YWN71370.docdoc fd5a39ed7a75423ea00e6cd96b70da25b1a7aa0247eb0b9ea039ccfaa1f7f732n/aHeodo