URLhaus Database

You are currently viewing the URLhaus database entry for http://hero-niroosadra.ir/wp-admin/docs/zemflpm2i/an1818217722536cda07dud95/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:444398
URL: http://hero-niroosadra.ir/wp-admin/docs/zemflpm2i/an1818217722536cda07dud95/
URL Status:Offline
Host: hero-niroosadra.ir
Date added:2020-08-26 12:58:03 UTC
Last online:2020-09-18 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-26 13:00:05 UTC to abuse{at}netmihan[dot]com)
Takedown time:22 days, 20 hours, 13 minutes Bad (down since 2020-09-18 09:13:33 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-05INV_Z4VNV891.docdoc f33044fc348cd18b856fb0ec93c0fee8622189e6c1a3bb7297c9730b2004616cn/a Heodo
2020-08-28INV_Z4VNV891.docdoc 3ddf3600b1feb4c4e8a3ae126b798a2e61ff41794ff84e9f28d87080811c4899Virustotal results 31.03%Heodo
2020-08-28L_DV6332567969OU.docdoc d1511a600b9d22d7d714df89c667ab913ccfe116fad6aa3759320416e83f6e23Virustotal results 28.81%Heodo
2020-08-28INV_010966489190.docdoc a4117099377670eba3962f275ddd4d5588e792f7bbb92134f206d72bdc6968e6Virustotal results 29.82%Heodo
2020-08-282ZP194CI2HYM4WU.docdoc 1183c3e3ce698e995f25ecf45a98cebceea253ff0caab2bbef1eb4c4c178eda6Virustotal results 28.81%Heodo
2020-08-28AKN_080120_WLB_082820.docdoc 897badf4396e30453715e24d47447d219f4fd288e60ae52935136278138dedcaVirustotal results 28.81%Heodo
2020-08-28FILE_FOG_080120_LRY_082820.docdoc f35f09ee31dc9ba4c3d871882fadeeb10ed716f5a87be56e6129b111b6e5e34aVirustotal results 48.33%Heodo
2020-08-28KEI_080120_GKD_082820.docdoc 83bd77af9348dcaab22627b6da43c1397e4f30e6e34db85498fd5ac87190a341Virustotal results 45.76%Heodo
2020-08-28BAL_7CMB7QNS9PAZY7M.docdoc 77ad3c40bc0967f1848893236a278bd997369b4203652af056b735d8378c6079Virustotal results 32.76%Heodo
2020-08-27485969743539728111.docdoc 8af87576d720df41fd511b0b3ad755aa048e80c9202fe1b1814bb17053a550ccVirustotal results 32.76%Heodo
2020-08-27XHB_TD6317724863HQ.docdoc a6a437a4d50881bf70e6ad3696bfd9cba38f06647aaeae5ecb221e68145759eeVirustotal results 33.93%Heodo
2020-08-27BAL_42816307.docdoc 35da2a043122e43ce1a120246b4e1087eeb78de3d7ba0ef7cf2f33b0a7f470dbVirustotal results 32.76%Heodo
2020-08-27U_71501626.docdoc a86cc60b85cf0dc5ce206c99179a486a81d96cad5afc105540f46e946e233aecn/aHeodo
2020-08-27EKZQ_81921408.docdoc 74ce7c1487742580d604a0e07317d772272965e55be0033732fb44ed733d178dVirustotal results 32.76%Heodo
2020-08-27WIC_635I71VDWCHUQK1I.docdoc 3a13bb9f65644d87b9e28eda53834cecc03be1ff8f059b9cefa61e5570ff76c1Virustotal results 32.76%Heodo
2020-08-27INV_2W2I4D9JY0DTQ8L.docdoc 88272a0a9f91640e16316607609f6943039742a1474f7f81c8711114ecfff227Virustotal results 31.58%Heodo
2020-08-27INV_MEK_080120_NOB_082720.docdoc 0b2a7a41ca14a8e7a64742388cc6f78e3816c332553c8707976f4b4c9ece4d1eVirustotal results 32.20%Heodo
2020-08-2795087514276086.docdoc a943fcb717ffc0c4a656e231f7fc21bcfc04099db295369eb1b66b86493e9b7dVirustotal results 32.20%Heodo
2020-08-27PO_08272020EX.docdoc 40183421d20c7dc59f165e796a0fd33f45d4564a62b0ab4e6f2759f824283268Virustotal results 32.76%Heodo
2020-08-27REP_579729260727.docdoc c6081344c883e627f79612b8bcaf44b55befbbb92800f6a709696a3749180534n/aHeodo
2020-08-27SZCI_SPS_080120_UCS_082720.docdoc bb699717744f27bea319547bf28c60bf7f8f2e77ba8b4af89e00f5b6aaa09f5bVirustotal results 32.76%Heodo
2020-08-27PYB_UUI_080120_DEL_082720.docdoc 72a047a55409445c1767467b0e67391b0fbdb99be5b2e6a5457df52c7e2ef398Virustotal results 41.38%Heodo
2020-08-27A_88977784.docdoc 6dbec06bb68d12a098c69b60e637339f4ca5104299c2f7896eda3613bcf420f6Virustotal results 29.31%Heodo
2020-08-2779409924.docdoc 2136cb67c60f9d08a5305401c1c4a33d58bf58038a9ce7d125d6ecf71e73655dn/aHeodo
2020-08-27YM2552378610BN.docdoc 1f7ed0ccd130a0b63ad568b735ad629f439919389015594a0a8c62b9f7e2460fVirustotal results 28.81%Heodo
2020-08-27DOC_PO_08272020EX.docdoc 0b996a31427775476402581dd429db57db41e3a98ed148776a2ba8f0b6cc1a75n/aHeodo
2020-08-27DOC_94183730.docdoc 8b1e85e899250ae238664c29df61c908610d31299f75ab0da17ab24d8e89725eVirustotal results 29.31%Heodo
2020-08-27DOC_2409392211267189576.docdoc 9da0bc4accb834cc8113bd486eab319aebee0865f6d09ceeb8517bd26c46fb68Virustotal results 29.31%Heodo
2020-08-27DOC_08965979.docdoc 63d5f79e05174cba8a5d193204e864185ebee87d45bb3c6e3dc4739ebd947d70Virustotal results 29.82%Heodo
2020-08-27INV_8198142076549672598.docdoc 9d2134a692b839f211eac6c767d4d2bd34c403cf29d221579e8d146f338b95bdVirustotal results 29.82%Heodo
2020-08-27PO_08272020EX.docdoc dca5bf3ec81849f15a96ff016d862539ecab9711026c0dad8dfb63e8fcd6f256Virustotal results 28.07%Heodo
2020-08-26DOC_PO_08262020EX.docdoc ed89cc17ed8978fba123c35b81ab3492672011b981288e57cc7d4f35ba874908Virustotal results 27.59%Heodo