URLhaus Database

You are currently viewing the URLhaus database entry for http://crdu.shmu.ac.ir/wp-content/Sep2018/En_us/Service-Invoice which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:51634
URL: http://crdu.shmu.ac.ir/wp-content/Sep2018/En_us/Service-Invoice
URL Status:Offline
Host: crdu.shmu.ac.ir
Date added:2018-09-04 23:26:35 UTC
Last online:2018-09-12 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2018-09-07 11:46:28 UTC to abuse{at}uznet[dot]ir)
Takedown time:4 days, 18 hours, 34 minutes Bad (down since 2018-09-12 06:21:08 UTC)
Tags:doc emotet link heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2018-09-06Invoice # 93F11450.docdoc f9d812532014170f0edb4197795632073b14f62eb2fbad89fb3f6c5a01474b54n/a Heodo
2018-09-06Invoice.docdoc 2a255834d890d8c82125c3701f929fbedabe2093c81e604d53621b83de0c509cVirustotal results 26.23% Heodo
2018-09-06Review invoice required.docdoc 2a3de196bcf5a1a6c0388a0549a23abbf9ce1861e4089ef0d352883c8c3e56f1Virustotal results 26.23% Heodo
2018-09-06Invoice # 6D58268.docdoc 67e29bcae543f0e2ecd958afa8015ac6b72d3ebc7be13f1450dec2bcc757653cn/a Heodo
2018-09-06Invoice # 2WD19592.docdoc 58159af5dd02c6ad0409c44f2e5857c61f56434a0ad805da154671739375cf8fn/a Heodo
2018-09-06Review invoice required.docdoc 3674df1d3b0a673b80a50f176d5fb241d5ed82675be0dbd6acf7a5fdaec4edabVirustotal results 27.87% Heodo
2018-09-06Inv. no. 850RT517228.docdoc 1ad60397502466a4d9d0bcf79f2307464342b926141a3b9ca38d5d2ece216a21Virustotal results 27.87% Heodo
2018-09-06Invoice.docdoc 4203da09b117b21f0c758378fb9839260b17872351de0a90a270027d0c15d76bn/a Heodo
2018-09-06Outstanding invoice.docdoc e8adc207df1a47dbc8fecb66c303437146bfc44b0d3f3822f8b3d3c35573de6eVirustotal results 54.24% Heodo
2018-09-06Final notice.docdoc 10b15f27ea2171d08ce96fa1ca590fe3087b5af324582fefa333240051580f7eVirustotal results 50.82% Heodo
2018-09-06Invoice.docdoc 1be0616a59db3aac71a93a4b2197cbb51e0711a533d1fd585435fbad9d916375Virustotal results 47.83% Heodo
2018-09-06Outstanding invoice.docdoc 4418c312da2426e8efd480434168c95427f3853e2c9f41f326c1412370ff431aVirustotal results 46.67% Heodo
2018-09-06Statement as at 06.09.2018.docdoc 96b60ded9ee0e8bd55ec5d1b4c34f3e0eea61e0bbaa8fcf193fa6a511d6616b4Virustotal results 46.67% Heodo
2018-09-06Statement as at 06.09.2018.docdoc c0b8bd18ebe466754287750a2c21807e2f1438c32902df92490a84d71d5b772bVirustotal results 44.26% Heodo
2018-09-06Invoice as at 06/09/2018.docdoc e5189a5ae04977c103a33e27522c37ea3401c8a00f8f2c561bc8109444b0cd9aVirustotal results 47.46% Heodo
2018-09-06Billing Invoice - Job # 3310653.docdoc 1c7ac3f0f213a6628455433131b5673c84746fb55b37036642d381d3333708ben/a Heodo
2018-09-06Invoice.docdoc 3b481406e54ebcb7fce8636eccb681945384a9112cb90cf7f53dc73fee904821Virustotal results 47.54% Heodo
2018-09-05Invoice as at 06/09/2018.docdoc 20b9108674f61c9c77765f5c63ae759185eb5af223570f84e4394e7d7e74b620Virustotal results 45.76% Heodo
2018-09-05Outstanding invoice.docdoc dd37edcd061cec244bc6abdc3d9618fddc5c875659daee1b6fd81c201e81b492Virustotal results 45.00% Heodo
2018-09-05Review invoice required.docdoc 2a51c5beb1217d58a521aa2a94a1e90119071880d23105d3c33f17d5d4628ea7Virustotal results 36.67% Heodo
2018-09-05Accounts - Invoice.docdoc 69958a4a14dae0727e7ed6dad4f186aea9016567a21444ae9514773ee451de9cn/a Heodo
2018-09-05Month notice.docdoc f833a2e863302e5d6475616cceec0a722d5dea6e72414622c34b7c3ae1790920n/a Heodo
2018-09-05Invoice Query.docdoc 428904f2720ba3faeda8b1573850b0ab6007286b6384fa7daa20cd078ff94b9en/a Heodo
2018-09-05Latest invoice - 926598.docdoc eb4e0db25ffe298103a4545da1ea4a7baaa4f682b0423514750cdc7be12be2e1Virustotal results 31.15% Heodo
2018-09-05Invoice # 14S70561.docdoc 3f6a4518759a1937a8f01b4be9c6ea2213767e4beb208efa5c6e9462e95ca8feVirustotal results 32.79% Heodo
2018-09-05Month notice.docdoc 41a7ef5cc5ad4b4ba9203ae229ed26ad4a4844710804dd5f11874133553e1d46Virustotal results 31.15% Heodo
2018-09-05Final notice.docdoc 46d81e2fd19c2c3cfc9f8562967f2eeef71159d9819db16dbe9dfabb195b8d97Virustotal results 44.26% Heodo
2018-09-05Invoice.docdoc 16d2a4c6c5f94697fcfa589f451cb7c7c463f1e24916fd75fac15f4a2768c6faVirustotal results 37.70% Heodo
2018-09-04Latest invoice - 617876.docdoc 109e078fde005b6a6f7f9c691169bc215c094316992c46f1dd9a6b6e27d69348Virustotal results 34.43% Heodo