URLhaus Database

You are currently viewing the URLhaus database entry for https://mnn.pasokhgooyan.ir/cgi-bin/lm/afs5zchjbxbu-4226/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:440614
URL: https://mnn.pasokhgooyan.ir/cgi-bin/lm/afs5zchjbxbu-4226/
URL Status:Offline
Host: mnn.pasokhgooyan.ir
Date added:2020-08-25 01:22:50 UTC
Last online:2020-08-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-25 01:24:09 UTC to abuse{at}aminidc[dot]com)
Takedown time:3 hours, 56 minutes Good (down since 2020-08-25 05:20:25 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-25form.docdoc 3ec9b1ad13e150dbaa252c498499665a993728f63d9f243fc71f6d564b18e684Virustotal results 42.37%Heodo
2020-08-25X0398 invoicing.docdoc 0ec54a3de74b2ce33a52e61dd413cd982256f6ebd129aec2eb96f88422c75c28Virustotal results 42.11%Heodo
2020-08-25Payment status.docdoc 41a664685a5b717edfd22f809d6d17fb7dfe646b4a5c27087f94b05ad5da7df5Virustotal results 40.68%Heodo
2020-08-25Inv_8493.docdoc 61814b42da2c11035f8c0707be022bc67ef8598918c9c9d1bf890e4e7b07cf7cVirustotal results 44.07%Heodo
2020-08-25Copy invoice #355247.docdoc d18b82df0184f35eb170be8177238aa8237ad55cf40a7a0ddcf3aa0ac63b9763Virustotal results 44.64%Heodo
2020-08-25Invoice.docdoc 3d5befca940c74791b04702d160818375925273dcb1a343e05bbe3687dc17a51Virustotal results 38.98%Heodo
2020-08-25Q2768754542UJ.docdoc 06ada13b3b4ed1fafd3c2f9121a778788cb8a03e98081fedd83ecbd2580435f5Virustotal results 39.66%Heodo
2020-08-25XJ0841 invoicing.docdoc b3a8749c2e42dc0b9548be2b11e932ec01b589ba5ae75ae96dcdaf4f1de88f86Virustotal results 42.11%Heodo
2020-08-25form.docdoc fcd403ce13660e21c77d6e5cfd6eb32afff4ff88ab361a477a25d2fd1bf9ffean/aHeodo
2020-08-25005645479912.docdoc d88ad8af3cdc4ade883d0afff8c98114ac25e6619b3334d3a51a12b4455d3734Virustotal results 37.29%Heodo
2020-08-25RQ5118663793OL.docdoc db78896d8992dca8991556b8c86d49f8b09400f1f7ca3fcd7201a59405e6afa9Virustotal results 39.66%Heodo
2020-08-25Electronic form.docdoc aed4d9c834ec0c4cb3adb05cfccbe8c3a3416d0c13895a41cef0e33e68e34848Virustotal results 38.98%Heodo