URLhaus Database

You are currently viewing the URLhaus database entry for https://1horse.ir/wp-includes/parts_service/ANy9hEWx0n/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:610118
URL: https://1horse.ir/wp-includes/parts_service/ANy9hEWx0n/
URL Status:Offline
Host: 1horse.ir
Date added:2020-09-24 14:32:32 UTC
Last online:2020-09-28 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-24 14:34:02 UTC to abuse{at}ovh[dot]net)
Takedown time:3 days, 16 hours, 0 minutes Bad (down since 2020-09-28 06:34:17 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-27arc-58700.docdoc d45880473c5098805fac94221c1a8d160d65028a7ec34bd85ec8e56782c57fffVirustotal results 49.18%Heodo
2020-09-24arc 20200924 89532.docdoc b14f597524f1d15a0fa2821d6000ceba85ccbc12fea8116c91d6bc24349bf39aVirustotal results 22.95%Heodo
2020-09-24MES_2020_09_24_HYZ950636.docdoc 441ad457e4ddfaca677155904b89ca29985e8a97d7b9477c7629d7e3acbcbd43Virustotal results 22.58%Heodo
2020-09-24File 20200924 64653.docdoc 531cda86b86c944133a24ae5428baf0f0de2eec8e5326ba1d15101ba7d1357fbn/aHeodo
2020-09-24dat 20200924 DE96456.docdoc 963ac9c75f4684b43800ebc6cc5e1b94d27f2d8087cb41741025b4d20e66d92fn/aHeodo
2020-09-24ARC 2020_09_24.docdoc 72109e7b06a85fac7f992e5bcc4215e1d36adbeb5a208dfb6c787ff75fa7322cVirustotal results 32.26%Heodo