URLhaus Database

You are currently viewing the URLhaus database entry for http://behnasan.com/wp-content/uZRqx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:434617
URL: http://behnasan.com/wp-content/uZRqx/
URL Status:Offline
Host: behnasan.com
Date added:2020-08-17 13:06:08 UTC
Last online:2020-08-18 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-17 13:08:07 UTC to abuse{at}greenweb[dot]ir)
Takedown time:15 hours, 20 minutes Good (down since 2020-08-18 04:28:32 UTC)
Tags:emotet link epoch3 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-18hv5jgk5b0262126480.exeexe d0876c2f83478d0ef5dfc662264adc79fa519856acd6ddf6b699c1882da946ecn/a Heodo
2020-08-18vfd765yigk000900.exeexe f7222313de2a393133d3a2165491df015853c48a4dda8c77246ab8982dfb16f5n/a Heodo
2020-08-185e4gejm34793173.exeexe 3f2cdcbe2ccc5a09bb2542adddfe008b07706ebfd888703169cf2f212326adb1n/a Heodo
2020-08-18cx3hz9j504313892.exeexe c65feb4e427c214bc7f5fb0cb911c2790803904d59a4ddc4d3a35b3fe4b5703dn/a Heodo
2020-08-180dtwf000000403140493.exeexe b2568822a508fcb185d6cc14c728edf518529d4053746210f5cbcd58ed62a3e5n/a Heodo
2020-08-18uudd3n00002.exeexe 93a07c5f6d16671c69e2a33121e72f91d07500ac0657697b6f93d648e17fc833n/a Heodo
2020-08-17uy00003961394764298.exeexe 3964be58554bb090e71e2b8c1e6c21d9e536919be4077d856e993c2cb2293ad1n/a Heodo
2020-08-17y3cn30828003913.exeexe e6946825b49739f297316f06891341c16db3c212acc40705be762287a237cf4fn/a Heodo
2020-08-17r00072837408.exeexe eae14fbb960d6069319fe78bf64a6c61783af543833e7cf791a0799a2abc86fdn/a Heodo
2020-08-17m2b900557.exeexe f435b7a078b1a2d83b7f38a4aec5e879f7b7062c4422f00185adb7d83f69e3a7n/a Heodo
2020-08-17q2a33314.exeexe 5822644f6c81b2fe87c31a3321088fad1268983fe8a80636d6c7ab65d1739105n/a Heodo
2020-08-1745yel00481319.exeexe 17fc2c80ae176218cf9c17f3d1c6f5e1b89f2b7b1072f8d8addaa0dedca84d7bn/a Heodo
2020-08-17r8000634390811.exeexe 735e25debd7abede76bc6b43455c8ee2d40b923703e31fd4dbbc4d5ec5cdffa4n/a Heodo
2020-08-17kh3p5pt3fwg288627151.exeexe 62ae9b65855aa68ee8859d7a6d11eedc5156e8f72b9b943c1fefa805f78eeb0en/a Heodo
2020-08-17dhpvi9qfnaa00006691432435.exeexe abcef6b8699bbcc1993579b508deffd497a533cb147ba1225f038e78292d2f93n/a Heodo
2020-08-174sbrhzel4e91506449557.exeexe 7879a91e3e6f10f8c264408cc504358a5385c361c490e0d56bc5be9dc21428b5n/a Heodo
2020-08-171yr004.exeexe ea87e1f110fd9e29a53a4de30801d1cf44b4e7b772baa881e400e25fdd1f59d6n/a Heodo
2020-08-17c3ybha735.exeexe 4147670dd43dde30c635331b3f53a78320e23858eda541e02a2813973e0285cfn/a Heodo
2020-08-17ljpbxqzi00667697.exeexe 49a4f496bfb3fe6e270a42c67993672b156638d101f9e74b84efd513c7cd0e14n/a Heodo
2020-08-17bwnwl2j20611.exeexe 27fa09fdda1913b77c456e1bff895ab3c0d6941a493995698610e4f0f90609b2n/a Heodo
2020-08-17b4ruyto7kl0622.exeexe 6571d1d1abc8df01c0b8aed35b73005e996f5b23a86b0d8385040425c224111fn/a Heodo
2020-08-17ye3jr23z6uo7006819007285601.exeexe 42dcba1515b3a77efd333b91d5711082c5ce97e17dc690f42ec737366c10b6bfn/a Heodo
2020-08-17zjtige603.exeexe 946d33573582cd3ce94dde45662a0abc19f7e1157d442f93914c36e92d0ae2ccVirustotal results 14.71% Heodo
2020-08-17r4x00046.exeexe e2b9d7be0c9d5454d38bc9e05416c5294e84b9d9204366270b597d0c59a8db5an/a Heodo
2020-08-17tymynhn21000217573285.exeexe 926425aca16aa5a694312da93d97a9506438e849b3fd10dd1ab00f6387de436dn/a Heodo
2020-08-17n8qymcsl0ant000613889492561.exeexe d9ea7c02bb3650d505d211f7d19085dfcf67c9b3537514313810eb2da36c30d4n/a Heodo
2020-08-17d0jlg06x88rm01671132568693.exeexe ba36a231a0e3081b622fddd23716ad4ab9371d799613135e3e7205c9e84987e0n/a Heodo
2020-08-1797wad08m6173.exeexe 042b7fcd7f48586cb194560a25c959a41bef66281e557fc910e498030ff62861n/a Heodo
2020-08-173p0000263.exeexe 4293e072763263de9127d3b531ff9be53acc70f3b031dc64b7638e01e3a92668n/a Heodo
2020-08-17rxm000057162207570.exeexe 1a06815c32948f480739b67a21c977d10b896b016598a1351c2ec04ca5baaa4an/a Heodo
2020-08-178mt3ejj0mn00002542579731617.exeexe a09d36aab5a085bf2f5317bf29f3c586a9dd135b4110f7a10b4b0324886804d8n/a Heodo