URLhaus Database

You are currently viewing the URLhaus database entry for http://njlcenter.ir/wp-includes/balance/392dam02nct5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436951
URL: http://njlcenter.ir/wp-includes/balance/392dam02nct5/
URL Status:Offline
Host: njlcenter.ir
Date added:2020-08-19 23:07:04 UTC
Last online:2020-08-23 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 23:08:03 UTC to report{at}parspack[dot]com)
Takedown time:3 days, 13 hours, 58 minutes Bad (down since 2020-08-23 13:06:49 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-2385368118.docdoc 6e331c9aade826ba3e5c77a819bbcd3cea15de0fd225a9bb48937c18be6855eeVirustotal results 64.41%Heodo
2020-08-20BAL_I2TO74WN37M48N13.docdoc 370f13258c923be12a4ce1b761f231bb3cb640389f75c77b5a50180cf21b221aVirustotal results 23.33%Heodo
2020-08-20FILE_970198907594.docdoc 3d3214a91f8fa0fe6c54f9de7d331ac31f1a562aa0c0b0e33fb5aef75163ff95n/aHeodo
2020-08-20INV_85689895.docdoc dc62b29f01e0debdb807f4adaaa4c22ca3f21e5fd5a48e7b2cb6b994d76cb36aVirustotal results 23.33%Heodo
2020-08-20634104429510460900727289.docdoc 62aaaf61f90d1c3f0c657fb7c0698dc7e72492a3e762c2161612a93b9ffe2aa1Virustotal results 23.73%Heodo
2020-08-20FILE_ZM6641227171TN.docdoc 601fd5470b6ef0aa11898d2c1d96a77bf1382dafeb3f1b7c2a3107dc61d426a2Virustotal results 23.33%Heodo
2020-08-20DOC_WA8IO3IPDQXSIS0F.docdoc af814b93d391c55cf505da148f1c2115049dda290499697b1b91cf51e099828en/aHeodo
2020-08-20FILE_26848933.docdoc 66adaecff904f859044c0d2aacc5bf77afc7928a3827c0e75dda7e79c0c29601Virustotal results 22.03%Heodo
2020-08-20FILE_AHH_080120_EEU_082020.docdoc 093c4c10f1ad0e417b62968802b3cf0b3e4b43b59ff54f6c894a005b3de57b54n/aHeodo
2020-08-20HOZ_080120_FYH_082020.docdoc 0fc24e52f38dc2987ac5826abe05dc4861ea6207d44b82b557222611f19173c7n/aHeodo
2020-08-2090392164.docdoc ab47a062dbbd97fae72fe297e5cffaea9d96c74395b5e6e3113c55364df5f6a1n/aHeodo
2020-08-20G986C5A.docdoc 6999b90afceb089b399c074269f52600ddb3d7aee434cfba9a1896c8213f4df1n/aHeodo
2020-08-20H_204981304067361262010172.docdoc bfdf3c9957775bcbc77fd32ca103eb77c0d7ce345a27bde62c3347647ad94a06n/aHeodo
2020-08-20BAL_TT0295643762YS.docdoc 9b8093f8e43a21459619460b9e991aa75ce552e9671b0d1b47ac7b3c638c8fafn/aHeodo
2020-08-20BAL_43138674351651.docdoc 9a3119ea1cf87602be71a2f730687159786a0d5158769f8e2f43456088735d4fn/aHeodo
2020-08-20FILE_PO_08202020EX.docdoc db559c97e2f3e60646551d37c6010a97791d7e078bc814266a039fa0632ae4a5n/aHeodo
2020-08-20REP_TZ1650413105GU.docdoc 3adba5d0d3b9f8425b3f663d9a4e49ea5d5effd605916f354e932e1fae4486e4Virustotal results 41.67%Heodo
2020-08-20YA_25418438.docdoc b1a3a3654d76f8eeaf84cff925c62e4f349407617da64a11c91b03851f5cf209Virustotal results 40.68%Heodo
2020-08-20ZW_16895715.docdoc 77dc94d7a2eb1a8f1f2875ee18a8115333a3c2ab0f0455d8cd46b952f93809b8Virustotal results 40.68%Heodo
2020-08-20INV_IXN_080120_ZDN_082020.docdoc a184a094e50174dc9dc8c5c22ac016c02f3605fd19c733c49ad1ebf02c493f65Virustotal results 40.00%Heodo
2020-08-20G_Z9TYH24PREB4Z4.docdoc eaa1c250dbc47328eafe0c85fab62bcb61bdbca2c66baff441e462b6ae5c1a1bn/aHeodo
2020-08-20INV_PO_08202020EX.docdoc f4bdec707792203de37f57aaa05aee2ce49012f69866816d8275ceed21df1daen/aHeodo
2020-08-20Q_IBCZ96TH.docdoc c4934bfd2c28c0579af2dce890cfb45e1ad7a431c8c7031c0c24ecf39ba4db53n/aHeodo
2020-08-20INV_MU5610697006WG.docdoc 29524d934f54a27deecaedd3e58de8a4490eddc04ac913bcb37c3ca1354c5b06n/aHeodo
2020-08-20REP_OEX_080120_QJY_082020.docdoc 580ae2c3801f24f8be8cc24b136f1d795787ace030c75c837410f5d827ca02e5n/aHeodo
2020-08-2028583929.docdoc 521688de7a4f5ae13f0d5348c2d0c4604f43a409de9751fd4ba6d791f4adc281n/aHeodo
2020-08-20BAL_8T09DFG0X.docdoc 275e276c98e61d33c2852f27d543c9cda4212aa16383e36b2e3651a28070a8fcn/aHeodo
2020-08-20DOC_229425959375.docdoc 60bb16533f938460519528657d8b785485622e3471330a87fa5894fed506eed8n/aHeodo
2020-08-20G_QXS_080120_JIL_082020.docdoc 5debb0401a79585a656197d49e148048a7c7db909c234ae80dd84798e89663cfn/aHeodo
2020-08-20B3DBFQUGL4ESN.docdoc b32f302c129728edd895136f299f0e68031f9554b42be4fd2dd35f80a9b2a750n/aHeodo
2020-08-20PS_239493603246776385064.docdoc be8b2b9dcb90fbaed4e7bc6186fd5dbad93c77fd80cee44717c88ac07641368an/aHeodo
2020-08-20ZV1741741570JM.docdoc 96f7d13cfc1edad4f9381ae98cab2336d39557b2230d88583c92284d6616b4e5n/aHeodo
2020-08-20E5VHRBR7.docdoc f49f483de9c2f5fc441b529eaa889631aa5a272206dfdca519993427403f65e9n/aHeodo
2020-08-19FILE_GHK_080120_FXQ_082020.docdoc a75897a4101123281bbe047444001acc874171e15cc5a6047baa32d5100d4237Virustotal results 35.00%Heodo
2020-08-19N_PO_08202020EX.docdoc 138de9fda8a9fe44c21521bf844b5c799dba01f79e1f61063269649470821b54Virustotal results 33.90%Heodo