URLhaus Database

You are currently viewing the URLhaus database entry for http://ekramco.ir/english/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:440943
URL: http://ekramco.ir/english/swift/
URL Status:Offline
Host: ekramco.ir
Date added:2020-08-25 12:20:05 UTC
Last online:2020-09-22 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-25 12:22:02 UTC to brandon{at}crucialp[dot]com)
Takedown time:28 days, 10 hours, 9 minutes Bad (down since 2020-09-22 22:32:01 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-27PPS_5315359195342727304451221.docdoc 281c220748df633f657b9fb07fe12a2b29d23abdcfef091d03b7d7c2cb9028baVirustotal results 29.82%Heodo
2020-08-27PO_08272020EX.docdoc dc87163b11f6657c6bf7480620e8be8324e0a4c2a564bfd395aad39cdd86fc1fVirustotal results 29.31%Heodo
2020-08-27INV_JOBC5W294ID.docdoc 38923432e3f3c288a95ad269e276d83fc311457e325def95858c499997a5e00en/aHeodo
2020-08-27BAL_PO_08272020EX.docdoc 6fd8df41a454fd5cd94079282364950f554b86e679c9ef87ff59d082afd47f8cVirustotal results 29.31%Heodo
2020-08-27REP_4RYN7XDVZ96UCZ.docdoc 8b1e85e899250ae238664c29df61c908610d31299f75ab0da17ab24d8e89725eVirustotal results 29.31%Heodo
2020-08-27DOC_712097602542746807668.docdoc 59102c908645acebebbe3a0565e89b326f3ae44dd1f0babf9d10a47a01e1b46fVirustotal results 29.63%Heodo
2020-08-270E7FB93DUKV.docdoc 151815029e695cd4af22c16d6eb0aa00c3ad74ba422c20d22e9bedf220485490Virustotal results 28.33%Heodo
2020-08-27DOC_JV5838806969GE.docdoc 3599cbdbe9bf9bc3a8a824fe0b4df98018df67b9c07cbaafa6331c4fdb68208bVirustotal results 28.81%Heodo
2020-08-27DOC_6RK4IA2Y.docdoc 8b2913bd0d496c2ddee3d882e6beca79b084016be7fa9cce5bce003acbc9aeb5Virustotal results 29.31%Heodo
2020-08-27HK_PO_08272020EX.docdoc c9bf4b4a386bfcde7c1072c3c00f1d708885dc202c1472658b0ef712f39d7867Virustotal results 27.59%Heodo
2020-08-27DOC_69624586.docdoc cc726b1b282963ed12f0894d0adba0ac1fdbe450c1db6761bda676005b7cb051Virustotal results 31.58%Heodo
2020-08-27INV_PO_08272020EX.docdoc b08d1b916d15ac5bf1d1c22d10c91dab42aa65bdc7d422c115549f18e598beedVirustotal results 29.31%Heodo
2020-08-27FILE_PO_08272020EX.docdoc abf0bc27d555c075d94aca0ac0eb6824f009e704fa575b66203e46e30e32ff8dVirustotal results 28.81%Heodo
2020-08-27B_SMH_080120_ULO_082720.docdoc 5b4cc759465eba517672e7e962d625475b75585dbebe2ec51a07327cab3a7b4dVirustotal results 28.07%Heodo
2020-08-27DOC_PO_08272020EX.docdoc f8c2e1e1cec6f084c1af444e45ad2e66421abe66724f2b6542e42768a1226120Virustotal results 28.81%Heodo
2020-08-27BAL_7015326422435.docdoc acfcabc48ac33fb560b1f8b103eab9dcec9d15938b713a81f07ed018d24bc8d4Virustotal results 29.31%Heodo
2020-08-27FILE_PO_08272020EX.docdoc 41213a4adcc07029d82e0c00a9932eb28ea7e5c9a41934e40ee35de060f8ecfcVirustotal results 30.36%Heodo
2020-08-27DOC_63767626.docdoc c1010a64991ed1fa9519bd2ff0ee0abc2b87853d34efd4a6c2e3f6a7b4fbaa75Virustotal results 53.33%Heodo
2020-08-27FILE_XL4804981240BB.docdoc ccd219a6f531ed3f9ff84a1ce8e664e71c3dcc4af09fe196889fe1e1b69ed956Virustotal results 31.03%Heodo
2020-08-27ROIX_78878373.docdoc 5651215bf90d3d27bf652a23f6f4ab03e32a080fba71d964022a87038fa6f1b0Virustotal results 55.93%Heodo
2020-08-27PO_08272020EX.docdoc 96ca79965f32aaf2b62d64767a1b73c5c33974afa8e7efa8b99f300478bbfa84Virustotal results 28.81%Heodo
2020-08-27FILE_ZEC_080120_MFJ_082720.docdoc 16d6be55ee176b177950348259b45429b0337137e64ff4f1584f44e6efa449b0Virustotal results 31.58%Heodo
2020-08-27BAL_73696003.docdoc 9284c7e6b91850c02fecc222938859e5545d62484b7d969c48c182c17b4e328bVirustotal results 30.51%Heodo
2020-08-2719115454.docdoc 41627e3471672730007dc13d026ac234950ae1f71564721c77dd5aff29e9c51bVirustotal results 32.14%Heodo
2020-08-27DOC_UA3480719948YH.docdoc 5e2acb078bf706a90389d90636ddaf5d332c47325336781c2ab14600e34adb05Virustotal results 31.58%Heodo
2020-08-27FYH_080120_BJU_082720.docdoc 68fe1fe9c32a72de136138a8c9952544fbe09ba873719d3406f5d2b9343bcc93Virustotal results 28.81%Heodo
2020-08-2720841983.docdoc 874b498a569260ed044256f13bd87d1a3697f02a17a364d2d61ba9005e12cd25Virustotal results 28.81%Heodo
2020-08-27INV_6009995002238622852904510.docdoc 8d55499216baf8d4336c908f7cfe243e51a6da3542a26504de0c18c18febbfbbVirustotal results 32.14%Heodo
2020-08-2726296847.docdoc 521dbd127364c7a8744078a12535bd421548c07546903c67998e8bc576c5836dVirustotal results 30.00%Heodo
2020-08-27ZMA3KTY1W.docdoc 7e6ae0bfbd08090276dc8821dbac500fae364dab68dad84b1fc2c4d971080dccVirustotal results 31.58%Heodo
2020-08-27WABMK30NB8RWGRAJ.docdoc ecee3946c7811821a799182055a523e8a0d6fde0e8898aa18b6226979f69f0d5Virustotal results 30.51%Heodo
2020-08-27PO_08272020EX.docdoc d8b2892cb235a6a574651012133c78ab0928fdd3ce752cc0699681a373778c04Virustotal results 28.33%Heodo
2020-08-26DOC_I5KKEVC2FIWT0.docdoc 8e10e66383c3a944eeeaf0bd48edb8dd7fc0231e33c7c1a42c22df2f6351be95Virustotal results 30.51%Heodo
2020-08-26LOSSS0KVRU.docdoc f745d063038b7bcae3c19cd07cefa9488c5df1d744a2a272a5f8399a964270c0Virustotal results 30.51%Heodo
2020-08-26INV_VN1665182590LK.docdoc 418cc4b29a2f7c05861556be1785c3b31dc530a4042c65c36253adb162a34d7bVirustotal results 31.03%Heodo
2020-08-26PO_08272020EX.docdoc 04d53867d9a85922c8e95c2c5ac2e27ba3c75ec87d1ceadc4ba5b065e4b51c96Virustotal results 31.03% Heodo
2020-08-26GD1CHG4JQ8Q2.docdoc e9a8e8368de08a89501486255c2feed64f65e3de714cc304d72d18ed2a6987d0Virustotal results 33.33%Heodo
2020-08-2633146802.docdoc 4b9b0079604599e5cd8b5c21a7fbec3c3c6f244c517df6bc274a0f5fa2940869Virustotal results 31.03%Heodo
2020-08-26WO8164876005IC.docdoc d6f8e60e80e4142bd6e6c2162f5b44596f03cf98b415d29a0099e3462bc60dc1Virustotal results 32.76%Heodo
2020-08-26PO_08262020EX.docdoc 7fe66f85659a10160846a834f8b4befde4e554e2c6e6586097218eed58c96790n/aHeodo
2020-08-26PO_08262020EX.docdoc 7fe66f85659a10160846a834f8b4befde4e554e2c6e6586097218eed58c96790n/aHeodo
2020-08-26FILE_VJS_080120_NKO_082620.docdoc adcff3f1b60e737879478f5ffe1450906166be8f4b197343ea2684bcb11d1f1bVirustotal results 30.51%Heodo
2020-08-26QCS_080120_YTW_082620.docdoc c63d0a1da663784ca7f4cece401282c716aa51b606e8298350c1fd4807cb4613Virustotal results 27.59%Heodo
2020-08-26W_PO_08262020EX.docdoc 39fffa400541356137e91075849e49947cd4864baeeacbc328e6aa73f52ef4fcVirustotal results 33.33%Heodo
2020-08-26REP_PO_08262020EX.docdoc 71a9af3c869b41333224d9d53eae47aba49f7c8512250f3286ef22680bf6ef9dVirustotal results 32.20%Heodo
2020-08-26FILE_RTZVI4T8PR43R68M.docdoc a2d2b5ff33238837657a8bd6b1eb1b5129ae430e64c02d459085d597d3c46e3dVirustotal results 32.76%Heodo
2020-08-2640487706564.docdoc 3afc78f029bb37949650170083203869c970ca766b2155e134e76a2ec9242499Virustotal results 32.20%Heodo
2020-08-26DOC_4A6WVA47T.docdoc 73bd8ccbf6c6ab32472c5784a7979a150437174459c01a7398945c2867eea506Virustotal results 32.76%Heodo
2020-08-26FILE_PO_08262020EX.docdoc af5e077f1915828d85cb8b2e854ac2c634e10cd249bc9ca36bfdce6210a78289Virustotal results 30.00%Heodo
2020-08-26NK4851157445RQ.docdoc 5579c8a6c70a4ddcb5e1b224ae15dd71779df902af733644093911a54ebfe5bfVirustotal results 29.82%Heodo
2020-08-26NTOC_AVX_080120_ZJH_082620.docdoc 45bf1064efa2a04f4bed2c8f62d414e6fa68f63c92672c6438fb27c9dcf53d9bVirustotal results 29.31%Heodo
2020-08-26YHQT_2977953623799744.docdoc 4c41348a4e6380aee6bed7a144ce0a2f0f99d289c713425a71c23db2ebbefd46Virustotal results 29.31%Heodo
2020-08-2634307604.docdoc a356e5e255cba02c8e3e973edcf986a20bff8764ba83a2bb53b55dba03d5529cVirustotal results 26.67%Heodo
2020-08-26REP_PO_08262020EX.docdoc 6dd3e6bbc0eea4a8b5a155e9c5ecf6731f98e487ce6ac53020fed4afb8363f7bn/aHeodo
2020-08-26D_UZGSVAYMS144CV.docdoc 1c78723c1b5b80a28a823310405f7bda1bb07ed0c94d433eaf5581c4409f8199Virustotal results 28.81%Heodo
2020-08-26M99N3I0.docdoc 0fb8cdd6e033deca3e95931c9f20ddab1df2d839911cb271774ae42cf5460094Virustotal results 28.81%Heodo
2020-08-26FILE_TFY_080120_UTV_082620.docdoc 673dfbd1e8a6cae6500c6bc52686bc69101e89a34d4f579b1f3b5a45174ef250n/aHeodo
2020-08-26DOC_QEN_080120_WXM_082620.docdoc 04c871d208f036de0564f672c588b02133e404885077c81fd692c49021c5ee46n/aHeodo
2020-08-26BAL_MQM_080120_DCU_082620.docdoc 2ca1220391f688c0267a3514e58dcd2ed626b961a1a9c912ed7fe64696367200Virustotal results 27.59%Heodo
2020-08-26REP_PO_08262020EX.docdoc 0c96443c933d94eb5dd8cc1af29600409b0fa6cbb09308d6a633c3b8d1b0b466Virustotal results 24.56%Heodo
2020-08-261241145450126645.docdoc 0322eae38619df582bc680d8fbde3a8a8f4b9e2c02b689db2d863c62f88c559aVirustotal results 26.32%Heodo
2020-08-26ZTJ_080120_GIP_082620.docdoc 1c90a374e62e6e686113692aab71497b6456e206a6d5eced8d8ad393c47aded4Virustotal results 25.86%Heodo
2020-08-26DOC_D9OXIPB5ULSSQ.docdoc 300cf0fd3de72ba9c28fc5428b8fac05aa455c7d7ffffbf3ae72db863f7fec1eVirustotal results 29.82%Heodo
2020-08-26WZ5953530394WD.docdoc 40387fe6e6a66244dfe24e5e9f6f88ca7111c0331b4239de96114a8d3b9b2b63Virustotal results 29.31%Heodo
2020-08-26DOC_FQJMXRGYB.docdoc a4b0033aace38e2c6d2dfadfe6776527459551c761c232558d3c573220f5c15fn/aHeodo
2020-08-26REP_540774159839127471504661.docdoc be20bc80f9d87b64f7cc9155e66fa2bc345578f828dd6f4cc21e01f7257c5247Virustotal results 29.82%Heodo
2020-08-25DOC_BWSUS7EVI86H.docdoc 8fca1b7834abd4c497c08643e11210ec88d3dc33c3d75a94f72f2039b584bf94n/aHeodo
2020-08-25DOC_PO_08262020EX.docdoc f8da60fee5fe2ddbc43a2bdbd1d34276166364d1fe05e9193c71ef71719e12e9Virustotal results 30.36%Heodo
2020-08-250125512625451522298529309.docdoc 96cf35f6327ac19150ac2a61cd40a8832253a659d1332b0065b37223a9d455daVirustotal results 29.31% Heodo
2020-08-25442973602139.docdoc 2a887378544614c46e38a88749314ed26f0f588fb80229eba306ae6a31389bfcn/aHeodo
2020-08-25DOC_09703105323236222790676.docdoc 696268abaa7fca009d2d755c96a4aab42d5aa9d20f5e586480896798e975b44eVirustotal results 29.31%Heodo
2020-08-25FILE_PO_08262020EX.docdoc edc3477618d76e98889e1be29182a8db3e21ff561eaea309e12070219788bab4n/aHeodo
2020-08-25416868781265240690076756.docdoc ca6f09e280c79e230c8a7909509fa0fe1f754862e8ca8b74dcc77bbc0dfb3d62n/aHeodo
2020-08-25FILE_15850255.docdoc c0bc03edcf17373ca7bcc145fddea1578f8998fb6f1d400d3701ebbe4ac1c833Virustotal results 29.31%Heodo
2020-08-25PO_08262020EX.docdoc b7d31d0d2e6624c23fdf8a2c989875d78052e661f92c0839d379c4197a188415n/a Heodo
2020-08-25FILE_OOI_080120_LVI_082520.docdoc c950095f3d0d6dba2238da696f4dcc3cb37b5a06fbf8c0bdaf7035697322a876Virustotal results 29.82%Heodo
2020-08-25INV_PO_08252020EX.docdoc 96eef74c59d9b8b47979fbaf2552a9735dcddef28df0b5b87655a4c849f9d853n/a Heodo
2020-08-25REP_AU2754386427NH.docdoc af6b3f177c1e4755a276700e2b50a76facb1c7434a2c2f291539bc2b70eba147Virustotal results 30.00%Heodo
2020-08-25REP_I6PX5BEU764AF.docdoc ebf572465108b8645ca9637d9c17b4fe717d4d99f3d4dd29046a22a8f608bcebn/a Heodo
2020-08-25INV_BAX_080120_YKI_082520.docdoc 6df73c12c0fd3d14d52b73a259377877667321ae14aa65c66dc0703702faae5eVirustotal results 41.38%Heodo
2020-08-25SI_PO_08252020EX.docdoc 2005da08cf5f5e5489e2eee91a32b61ee7c2da83fcbd47f566eb7a3a29388151Virustotal results 41.38%Heodo
2020-08-25DOC_369040133230377577277475.docdoc cd5de7d65b2e9b1096050ce5dc17eab61c74558a8570d384af33e78dd2d9b025Virustotal results 41.38%Heodo
2020-08-25DOC_PO_08252020EX.docdoc c52d43a72bc36aa33659558cfb0788b7c919cf70f6d6c98be550891ce51556abVirustotal results 43.10%Heodo
2020-08-25REP_PO_08252020EX.docdoc 16d0ce3d4bd3827c29631fe350fb1be165d20da43ff1bbf0178358617f1040d4Virustotal results 41.38%Heodo
2020-08-25DOC_74168676.docdoc 8238f8a38b9f7d6b3ad1f545ee622a56c42a1f7095c3501a2607ab942badda6bVirustotal results 40.68%Heodo
2020-08-25REP_HSO_080120_RQZ_082520.docdoc 5ea798c77e148ba56c705159bad7572cc32b08d35f1490759356a6d114d50a2dn/aHeodo
2020-08-2591078921.docdoc 3dce2355e30fc9c2bcf1011d6e069107e0f65eef8e4b8dcab989ecdf8bc55407n/aHeodo
2020-08-25TS3576567771OO.docdoc 31b667c4a36243119386974054815bcd6f58ac21d868084ff020986f1b28cb30n/aHeodo
2020-08-2592488813.docdoc ce1f2360dc9f394ddeafd0da572fc80d6edb4b444eccad414a79cb0a77bd8046Virustotal results 32.20%Heodo
2020-08-25CW8TCYO7B.docdoc af47b502a8a50cac62e1d264219056d986f81305a62bf0469e433a70e939bc23Virustotal results 28.81%Heodo
2020-08-25INV_96656120.docdoc e06211b96198e300977ef5f59cf0badd6899b4e387a2b82068e4d0aea2b1d40dn/aHeodo
2020-08-25RYEYSWRVBP.docdoc 10216de03866c86a163d074495bfd71636ac299c24a2c6f0d482a733a5582c62Virustotal results 29.31%Heodo
2020-08-25BAL_0278481789002619069641.docdoc 9782513596cfc5b6c1085aab702486a584065a2801f69b7b671c7d5d347534eaVirustotal results 28.81%Heodo
2020-08-2581683046.docdoc e189b649155ffb3328d6463ee06e0c0c461e3b361841be116f1f7a63efe11cc6Virustotal results 29.31%Heodo
2020-08-25SZWV_PO_08252020EX.docdoc ae2415bcc28be74ba8a8c4aa9b98bcc4125881032b2429b9bc3bcac2860c185bVirustotal results 30.00%Heodo