URLhaus Database

You are currently viewing the URLhaus database entry for http://hajifaraj.ir/hajifaraj.ir/sites/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437164
URL: http://hajifaraj.ir/hajifaraj.ir/sites/
URL Status:Offline
Host: hajifaraj.ir
Date added:2020-08-20 09:49:12 UTC
Last online:2020-08-21 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-20 09:50:05 UTC to abuse{at}hetzner[dot]de)
Takedown time:1 day, 0 hours, 19 minutes Poor (down since 2020-08-21 10:09:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20INV_EEL_080120_SQC_082020.docdoc 123ba583a9ad8848142156dd3e087a6d746ba164b07681d1a0893f45af6b7cban/aHeodo
2020-08-20H_27038939.docdoc 02beded3bf97160a812d8bd478ac0f798e12c3b82c464bb8429c8a5d78ae0c3cn/aHeodo
2020-08-20PO_08202020EX.docdoc 713e8a1be959b7dd6086d6db1966d903ebbcc7c9b3df5fe7d7d5e0033bcf4f4fn/aHeodo
2020-08-20DOC_925301624817.docdoc 3d3214a91f8fa0fe6c54f9de7d331ac31f1a562aa0c0b0e33fb5aef75163ff95n/aHeodo
2020-08-20BAL_66337046.docdoc 2704479bb70ab89f699b958bff80a648c4c3b03d3875afd7cf5d833fd625e037n/aHeodo
2020-08-20NAIY1N1M3WT0O.docdoc 62aaaf61f90d1c3f0c657fb7c0698dc7e72492a3e762c2161612a93b9ffe2aa1Virustotal results 23.73%Heodo
2020-08-20S_0911653976556810544760040.docdoc 29b52f890109db1441bb1fab0d062383405b49e076d6f8c04c40644a9cfda15fn/aHeodo
2020-08-20FILE_PO_08202020EX.docdoc af814b93d391c55cf505da148f1c2115049dda290499697b1b91cf51e099828eVirustotal results 23.73%Heodo
2020-08-20ETV_080120_ULL_082020.docdoc 66adaecff904f859044c0d2aacc5bf77afc7928a3827c0e75dda7e79c0c29601Virustotal results 22.03%Heodo
2020-08-20YKA_TH0DQIT32ABZFFRF.docdoc 73bfcb9214b001594d3b0d3cc9c11c8ae9b0c2f57e4b75b8772cdad41a7e3c28n/aHeodo
2020-08-20BAL_7OLL99LH0HYFN.docdoc 0fc24e52f38dc2987ac5826abe05dc4861ea6207d44b82b557222611f19173c7n/aHeodo
2020-08-20MTI_080120_RBY_082020.docdoc ab47a062dbbd97fae72fe297e5cffaea9d96c74395b5e6e3113c55364df5f6a1n/aHeodo
2020-08-20DOC_78415128.docdoc 6999b90afceb089b399c074269f52600ddb3d7aee434cfba9a1896c8213f4df1n/aHeodo
2020-08-20DOC_036475594916656699382.docdoc 568471d2d31e15f9b46076ae0167cdda7da49957b7cb120d330a0e450bc2c7f3n/aHeodo
2020-08-20FILE_35567208.docdoc cc9254149ac0a5f25e859e00fd4ae509b05a23e42d49708d4c0a15e4628b1c66Virustotal results 20.69%Heodo
2020-08-20FILE_CAK_080120_DTI_082020.docdoc c4d72dd24ca207058b0934dd1e28840b1c2ba319b959da0132aca80464d52475n/aHeodo