URLhaus Database

You are currently viewing the URLhaus database entry for http://crdu.shmu.ac.ir/wp-content/0160015RUTNUSJ/BIZ/Commercial which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:44075
URL: http://crdu.shmu.ac.ir/wp-content/0160015RUTNUSJ/BIZ/Commercial
URL Status:Offline
Host: crdu.shmu.ac.ir
Date added:2018-08-17 18:54:13 UTC
Last online:2018-09-08 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:46:28 UTC to abuse{at}uznet[dot]ir)
Takedown time:16 hours, 49 minutes Good (down since 2018-09-08 04:36:08 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-08-18BIZ #074B.docdoc 54279b6bd022f238cf0ed29e236d1801ba9a64326cf273713a1ae27f3f5b3269n/a Heodo
2018-08-18PAYROLL #2WJEC.docdoc e3eabb11ef2ce3a6dbb7826d3c38ee54ac0d3db70d849fdbd47786572459db53Virustotal results 37.29% Heodo
2018-08-18PAY #287WTNDLAWZ.docdoc 28d8b85c8ac6cfc335fd728eedcdeddb816f585acdde3fbd827de70f1ce611aen/a Heodo
2018-08-18PAYMENT #7HCLPVDS.docdoc 8ab8e9404a90291ab1f7ab4f84ead30211b6524f1ef0104cf6bda0e69a644930Virustotal results 27.59% Heodo
2018-08-18PAY #3314055OFC.docdoc 5d16f44d3de9995ed89b911658aab0511dcd834244b4cff9825354d97324ec0cVirustotal results 25.00% Heodo
2018-08-18PAY #92OBTVCHM.docdoc 987b7718ab13a4544b4dbf72c4d104c1f5167264b686c657239413da8ebb727bVirustotal results 25.00% Heodo
2018-08-18PAYROLL #173171W.docdoc 5376c945be32cd52561d7bd333d149d8b17479da3ca3ca23f1afd164314faab8Virustotal results 27.59% Heodo
2018-08-18PAYMENT #0443MBJOCDHF.docdoc 05ffd1ab139da8d53e13eedac3b6d5a2a50e7278fada4df5aee81f76e5028fedn/a Heodo
2018-08-17SEP #6258111JIGYVSDG.docdoc 31fc0494c40e707a95f6ba25a3f2c82c47b38a9462d571d01bbd02d49ca484d7n/a Heodo
2018-08-17SWIFT #59975FRE.docdoc 500b5b69e515d684d7dddc8d259df07ae3e002f080bdb8695d14f1959ddc359cVirustotal results 25.00% Heodo
2018-08-17BIZ #5885JSN.docdoc f6d4fe4cdd98c36471e7904e2dea5ad3e3d78d7232fedbb60c90d53d011fb894Virustotal results 22.03% Heodo
2018-08-17SWIFT #069ERBDIWRH.docdoc bd75a590438ff32615167dc230167f6f343749a626ff71f4ef7981fec318924fVirustotal results 39.66% Heodo