URLhaus Database

You are currently viewing the URLhaus database entry for http://behnazazad.ir/wp-admin/public/zu6eomt5/m13a31xn1t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:618270
URL: http://behnazazad.ir/wp-admin/public/zu6eomt5/m13a31xn1t/
URL Status:Offline
Host: behnazazad.ir
Date added:2020-09-28 18:14:06 UTC
Last online:2020-10-03 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: unixronin
Abuse complaint sent (?): Yes (2020-09-28 18:16:04 UTC to ripe-abuse{at}0-1[dot]ir)
Takedown time:4 days, 18 hours, 25 minutes Bad (down since 2020-10-03 12:41:19 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-3003278916044198686.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.22%Heodo
2020-09-30F_55758699881996886547.docdoc 8ab2e6cb8892b88bad960fc01887038298cebc93804c11f3bf92624541fd00deVirustotal results 21.31%Heodo
2020-09-2937648308.docdoc 76d3bae4ebe683a5d3ff0d90971119c287a3acbab073e28b979ad7eaa60e37bfVirustotal results 27.87%Heodo
2020-09-29DOC_EE7837188868HA.docdoc 14e6ea40cc1e124fe353ed7aeb27490dad58d6a116bfddc62aacaa02921c5d88Virustotal results 32.26%Heodo
2020-09-29BRAQ_EDN_090120_POV_092920.docdoc 9df925653c851406413f14b7476717e284adf2a52f3ade096f1180b4cae87031Virustotal results 24.59%Heodo
2020-09-29M_PO_09292020EX.docdoc 1b2178832ee64a78fb24f7846e95c4084c6d0656a4504c264e0d9c5b0516e31aVirustotal results 45.90%Heodo
2020-09-29FILE_E8KDG9214CK7.docdoc c44638748bc8cb1ffa71bdf33c4168a31fe040d6d5dec68f28650b86a4b23c53Virustotal results 46.77%Heodo
2020-09-29IY8066239572PK.docdoc 45e97570fd10c8eb0957ca5b1d503d457681e75e5cc9a885394b17425496d58bVirustotal results 46.67%Heodo
2020-09-29NN3BY2FA0APGLQ.docdoc 1af9c4541fd3967f4d9820ee633cde8bee8d73612d046cba0456debdf28313aeVirustotal results 45.16%Heodo
2020-09-29YQW_090120_DVS_092920.docdoc 15d3403b8d1d07b8b635e79f0fd458c3961ef5b48d60d19b6596c9c1028a2662n/aHeodo
2020-09-28DOC_C45W3U8SP8IM8M.docdoc bceb1b46f7099731622c35f1e66fe7519b41666875e98060735db9253302753bVirustotal results 30.65%Heodo
2020-09-28DOC_118770609.docdoc 8adce4f06bd6eb3deb4d60c3760080dbaf9ef27833690302e72e9ad946a3d385Virustotal results 29.51%Heodo
2020-09-2834195092231.docdoc a5a023e17e92bc3fcd171e69ccd37fe1f09b68a0e7a5f01c52a66e1822023bf3n/aHeodo
2020-09-28KI8585436964RT.docdoc 911ddca29162ab27987b28ddad247944b447d1b9dd25519d5146239566695b37n/aHeodo