URLhaus Database

You are currently viewing the URLhaus database entry for http://www.ekramco.ir/english/OCT/WaGV7hJSIYtI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:599330
URL: http://www.ekramco.ir/english/OCT/WaGV7hJSIYtI/
URL Status:Offline
Host: www.ekramco.ir
Date added:2020-09-22 18:35:08 UTC
Last online:2020-09-22 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 18:36:37 UTC to brandon{at}aqhost[dot]com)
Takedown time:3 hours, 53 minutes Good (down since 2020-09-22 22:29:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22File-20200923-FZ4784.docdoc e3187dbe7923459b3ea645a3d68b357927471e14d70aa4e542327ad4ef540637Virustotal results 32.79%Heodo
2020-09-22list-3820.docdoc 3581578c9dc74cfccd9fc4db4a1253d45b3155e89b6f731117c15699a3e29089n/aHeodo
2020-09-22O487 2020_09_23 RA902391.docdoc 8031c668f56e12d2f6e1d54f98aea8eca655f14e6dfa3ca6df9da76aaec004f4Virustotal results 29.51%Heodo
2020-09-22DAT_20200922_U3480.docdoc fbeb9d04cda2cdc25d0f83cf72853d3c3240b72ed8047f657e576061c0157037n/aHeodo
2020-09-22Dat_2020_09_22_SK7350.docdoc 6d91b91643e3f32d2bb96bf9dd0b4d7764f594259898185084557fc57a102d1aVirustotal results 30.00%Heodo
2020-09-22doc.docdoc 519ade7779233a4aa1559c30318a4785bb0e2c995a56b01fcf95b4b69e1a3fd0n/aHeodo
2020-09-22Attachment 20200922.docdoc 68489ce36e7548641be6668b08d265ead175025a1650199eb050bee7e4e8566eVirustotal results 29.03%Heodo
2020-09-22file-20200922-380472.docdoc 5231a24a90603fcebbe4e812fb2ac981a788534259a9f3bf6343cef44d447720n/aHeodo
2020-09-22FILE-2020_09_22.docdoc 3a9ad2454dcb31ab7a424d69dee0659c219202415da5f6a02f0de501701f24b7n/aHeodo
2020-09-22inf 2020_09_22.docdoc 1c009a1ea64d66b79cdfd6b376038c334b5d2b492c90aa17333d91b49a354eddn/aHeodo
2020-09-22Untitled DON157377.docdoc 955417c2e173ab3f64f91ad4d7921703e936abfc30a3115a22289becd6fb94dbn/aHeodo