URLhaus Database

You are currently viewing the URLhaus database entry for http://my.alphaschool.ir/wp-admin/wtz3t204h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:620400
URL: http://my.alphaschool.ir/wp-admin/wtz3t204h/
URL Status:Offline
Host: my.alphaschool.ir
Date added:2020-09-29 03:10:07 UTC
Last online:2020-10-04 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 03:12:29 UTC to report{at}parspack[dot]com)
Takedown time:5 days, 12 hours, 17 minutes Bad (down since 2020-10-04 15:30:10 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30R_PO_09302020EX.docdoc a3d743d11312e842641d3124985266cfd1471f8d21881fb7dfc8dfa9cbd1fe47Virustotal results 26.23%Heodo
2020-09-30PO_09302020EX.docdoc 499e1db2bcd68d444f9d810f5489c4bacfc42b709036484694dfab71fcbe1153Virustotal results 25.00%Heodo
2020-09-30X_54065358859786413161012.docdoc 728b1a60c5af8cf394d48d6bc7a6a273117da463ab6316c2b43a2fe72b26709cVirustotal results 26.23%Heodo
2020-09-30INV_PO_09302020EX.docdoc 89184bca1106ed62901477bceef09ee282bceca404d17c44630544fdd803cbbfVirustotal results 25.40%Heodo
2020-09-30REP_87913593.docdoc 86f7e3cb36503bd4d36820857fa1cf349e4e14af26612ebbf4855fe68b2fde22Virustotal results 25.81%Heodo
2020-09-30BB8OW441Q0.docdoc 54f93880d0f4c65aaa29acd1dff0cb761aa8dc7388f96435e8c55ead32b30dfeVirustotal results 26.23%Heodo
2020-09-30REP_53651090.docdoc a6bda5016faa4796392e20bb0d8076147b2d6ea0f899019aed66cab6a4ad220fVirustotal results 22.95%Heodo
2020-09-30DOC_GU6843937001HK.docdoc e0598f2efbf03596b6fc2d73a58184b9a4d4277d2fc01322308e86a132582e2dn/aHeodo
2020-09-30OQQ_090120_TVF_093020.docdoc ea04aeb35f3ee924c978225fd95f2fa3df8a4847a761685ad79f96c82886f80dVirustotal results 22.95%Heodo
2020-09-30DOC_65701187.docdoc 67d5b3c3ed94416daadf1bb5fd4eba9c72b57c7b8f1d7d1e40a7a3def981adc4Virustotal results 22.58%Heodo
2020-09-30W27OFN1DAJVA.docdoc a4764b420e55695dd9b02d5ca980f126958001ea30e96a74b2e9321661bf38ffn/aHeodo
2020-09-30PN2197302567UC.docdoc 7d2c8d827a62c501876d11119d9989eae86dc953f1f0ced0c65a9567cb616fbbVirustotal results 22.22%Heodo
2020-09-30PO_09302020EX.docdoc bffc637d28966b991a1135f37d733cd4d1041f8fad86215d623d14b6b0ead577Virustotal results 22.58%Heodo
2020-09-30M_ENS_090120_NDT_093020.docdoc 380569af88b834f9d208236fa12e84cab31e0caf8793dacf54e7d8bcb290e5adVirustotal results 22.58%Heodo
2020-09-30DOC_1YZRAR23I9L0CMJJ.docdoc 3e6e31b97b51015205df9e5043f01adddd0e5cd8248bac5bb0a7e7d75b5684bfVirustotal results 22.58%Heodo
2020-09-30DOC_1YZRAR23I9L0CMJJ.docdoc 3e6e31b97b51015205df9e5043f01adddd0e5cd8248bac5bb0a7e7d75b5684bfVirustotal results 22.58%Heodo
2020-09-30BAL_MTI_090120_JDU_093020.docdoc dae3de0260b268fd89734a96196759e0a878835e38a868db1ec44194c212e1f0Virustotal results 22.58%Heodo
2020-09-30INV_PO_09302020EX.docdoc aa20d5b64ffd09ab64443f3159ab02394d97ae2baa93aa75de32fdbdf7f30e6bVirustotal results 20.97%Heodo
2020-09-30REP_PO_09302020EX.docdoc e67c373437e7408c177a503ca9bcfc8ccce61d14cfc636074bedb0937c41eb67Virustotal results 21.31%Heodo
2020-09-30H_987162246763184841786.docdoc 8cc454cbd44284ac4a4b398e7fb7e8ef64466cb44537458d884f54fea7d6374dn/aHeodo
2020-09-30LT_BCY_090120_WGK_093020.docdoc 786c646aec87e25c98dfbac09f886f13f05a1e6690baf9974f99f1b37b6f3713Virustotal results 20.97%Heodo
2020-09-30P_3ULV87SKHWH.docdoc 070fa7b00421948236bfb6bd84797e0ffa8f842cf034d0086b4d9f3fb5391649Virustotal results 21.31%Heodo
2020-09-30DOC_ZR5059685294SE.docdoc 0c169d8b50436ffcfc67dc75e5a8534829a932697bf5e79107b4ecc423e227f9Virustotal results 20.34%Heodo
2020-09-30BAL_EHDH8KB7QXLWK3T.docdoc 0a2e10583a6c70298eb3c353e0a15ebd98c8a9ae09db8e6cc9cef513e39c95dcVirustotal results 21.31%Heodo
2020-09-30INV_PO_09302020EX.docdoc 7a824b0902c4e58a3bc225caede89cabfc440904f63680f791b4a6421f1500c8n/aHeodo
2020-09-30UCD_47295799.docdoc f753b7a2b5babbf0b90ff334a9ef900a447d43c76c85cd43aed4f4c01db9bf8aVirustotal results 20.97%Heodo
2020-09-30968779080615557803040.docdoc ecc336e27a1ff6eba45106abf4d47adf3ed98c94f40a5dfc80e9e3287d79c099n/aHeodo
2020-09-29FILE_RY1301231725IC.docdoc e05998b05bc8cca5bb90b40ebe39ab34c4e1a36362390dfcfde996139ef98c71Virustotal results 32.79%Heodo
2020-09-29FILE_HQZ_090120_PNT_092920.docdoc 17e0c4c7423cb7f691ab0220a7a66e2fa7c48530973307f7d66a839c9109fab4Virustotal results 32.26%Heodo
2020-09-29REP_10808501.docdoc 9243618e3533ddf75d1106555b3aad908b5a34d8ae7a1065a683bf73e6b21a4dVirustotal results 31.15%Heodo
2020-09-29TH6054583013FN.docdoc c1446a72e2576d95b24898e5014d628598195a914aaa2a04374e7f70bc758675n/aHeodo
2020-09-29DPM_090120_LKN_092920.docdoc a06ad91cbd8e1a2748921479a01b93cba5910718c0975e9cc5fd8a71bb5e823bVirustotal results 31.15%Heodo
2020-09-29INV_PO_09292020EX.docdoc 5ef294f07935f058d75cb1588cb92c95325d7f2d888d38db85d1083041ea4fffVirustotal results 31.15%Heodo
2020-09-29G_PO_09292020EX.docdoc c69c21e4a5c5a3aab97f8686c02ea866d7334da7c2d7d5509ad1b4ebc56ec006n/aHeodo
2020-09-29CD_PO_09292020EX.docdoc 521b43b0a4013e7b1407116f9896d153d7401ea8eda3b29b63b64b744596a651Virustotal results 30.65% Heodo
2020-09-29REP_DL6393656323VF.docdoc 44227b77d84cd888cb5d44f59159a5bdc0c7b3021042e2d2814718e870c2b237Virustotal results 33.87%Heodo
2020-09-29X_ZP9338986305DB.docdoc 6d00d6451661d40ba68a9650bead442eecae2c92266613dd9577e380f31f9644Virustotal results 35.00%Heodo
2020-09-29INV_29495554.docdoc af66021f5673c71460b46b35f0d09a751b24676c36e0a9524e18841c4c4dcb80Virustotal results 34.43%Heodo
2020-09-29FILE_20672591.docdoc 3bf884e5ad0e7ae1e5bda8efd025ebe7502e8446e0675345a83138de1f052c2bn/aHeodo
2020-09-29I_4830061074.docdoc a379c99d0452638d4c8f009ee52263def6724224858745b1828a7141006c8647n/aHeodo
2020-09-29FILE_78684214.docdoc a24ff1a3bee9fa6a1feb6a52c64d85af2811d52e9bccaeb05a7abd72b2687120n/aHeodo
2020-09-29REP_65625290.docdoc 67453aa858ac24a5403b4bd5cc27a734bc73baed1a8d891fcbcf0dafaf280d53n/aHeodo
2020-09-29INV_VD6480799449YA.docdoc 3bee6ffea2b95238a17e5c61ee43b33b9c17b6eedaea7c334feb7f13ce90bf07n/aHeodo
2020-09-29JJO_BJ0YTC6.docdoc 745c43f7578cbd7dc997f5fcdb6f547c74055514e0120e14dbcdc4772babb5acn/aHeodo
2020-09-29DOC_52379658.docdoc 2c95d5fcdfdb060215112fb122d9315d7e155ffd00e61593df65e257922e252cn/aHeodo
2020-09-29DW7926496739VY.docdoc d286eeb463240cec38ca707bac6d0bab917ed05ed87cda5f42f3865dd2cbdc1dVirustotal results 23.73%Heodo
2020-09-29REP_99960776930484.docdoc eea701d39d78082b503779228c5870d61185b6173afe8df2779e26d8f2dea897n/aHeodo
2020-09-29BAL_JAF_090120_JGF_092920.docdoc a23ae220744a77b4f8258813717519b846ce178047b5a0f8078bd1be4c80c392n/aHeodo
2020-09-2980636510125220848333343.docdoc 21c42b3464c194f0cfb5308bffc5fa0290c1374a0f2da944adaa0c84330119f8n/aHeodo
2020-09-29H_345084343.docdoc 52d4d3ba3631c4dd2d1c90876ed2268eb3da0bacc02fd451a5ea5e4c84bd96c8Virustotal results 24.19%Heodo
2020-09-29BTTO_YTW_090120_FYZ_092920.docdoc 36bfa7a98a671adc28799b87a656330d4ea7cbd8c52fbd6d75d77049acbcf95bn/aHeodo
2020-09-29P_JV4ZPVOFHQ6G2.docdoc c3954486dd6baf409dc2dc6dfe8f865fc58f1d4ad1c9daac5ca0fb51147d6ef7n/aHeodo
2020-09-29BAL_79056783.docdoc 9d68d6c0dbd8d2b75891facc554399f92ee472d009e367d4d94f7408303ba258Virustotal results 22.95%Heodo
2020-09-29FILE_UBH_090120_PDS_092920.docdoc 11a15490c73f98ac1d0d1caa24d7643be4c4a1e8ccb97c68112844bbc1ec12f6n/aHeodo
2020-09-29XQR_090120_DCU_092920.docdoc 9837d0e98959e8df159836eb545f5246cb56cfc6834a2c5e7165a3d6ab093aden/aHeodo
2020-09-29OQMS68JFEBS45.docdoc 68a9ee794307f9d9834945084a0412835b4b80754f558094acd6f3b5d6cafee2n/aHeodo
2020-09-29ELU_36131847.docdoc 4b40209defb6a8ee079d69bd340f6539efcb4d3852381ee79a94227bec9f56e7Virustotal results 24.59%Heodo
2020-09-2909898881.docdoc f5013fbc3f4e685f68f19711624f55a63fc7ff5dfa0005f8c16803761c7d2788Virustotal results 22.95%Heodo
2020-09-2909898881.docdoc f5013fbc3f4e685f68f19711624f55a63fc7ff5dfa0005f8c16803761c7d2788Virustotal results 22.95%Heodo
2020-09-29INV_PO_09292020EX.docdoc a916028a8065134286abed17393e55e315c9ba012558b7a0875e09ac2ff95e50n/aHeodo
2020-09-29ABO_090120_RZN_092920.docdoc 5cc2ba0f2f951a4045c7a3b85e3c0c49e32c14ab752b3e3f0b3bfd09f8a67eb4Virustotal results 48.28%Heodo
2020-09-29INV_41523666885100.docdoc b172d2ab044bb42d8fc4206feb9293fb72d9893d242685ae4e7a20d8531c7954Virustotal results 49.12%Heodo
2020-09-29DOC_9M4B8CHRF7FDM3PX.docdoc 27442f20eb59b4d209325e6568821d54267357d72c350b9aac8bdbe721e0235cn/aHeodo
2020-09-29BAL_62442972.docdoc 93e49c537d860ec3dbcb23e79f1eb2c52610596ff0dc6e7fedd5e41ade84841fn/aHeodo
2020-09-29BAL_PO_09292020EX.docdoc 1b42960531845b815714f61fff4022939441d337491d719c2f2c3c08ba21cfdfn/aHeodo
2020-09-29ZBEVW8Q7X0TWE.docdoc 5812d0ad109d6f40968469204b6745f68b91371d185978b1538b763789ec4098Virustotal results 45.90%Heodo
2020-09-29AF9340167485QQ.docdoc 7e85837a8b4971b1014e74d107d5cf4f797470db1b9823a8bca7511a0d991c96n/aHeodo
2020-09-29FILE_67455660.docdoc 2a3f6b0511a5d81890b631c4159682d4c6771e181f35bce18e814cf8d07d9eb8Virustotal results 45.76%Heodo
2020-09-29REP_PO_09292020EX.docdoc 760dab7018f626be3c6aaa9e57e0350cea3ae2cb057de45687c1f251aba72f8aVirustotal results 45.16%Heodo
2020-09-29REP_BJ9UZJVK.docdoc acfc7c7ed7491c577af0b27a6ad5a3b553df2d12ea4ee0cd53e5781b6c0247b0n/aHeodo
2020-09-29V_0RBEUVIPUC.docdoc f017fb57e3d63cad2e865981e345ac9c31f64c1114aaa4e21c6aeff31cbb13d2n/aHeodo
2020-09-2974535486.docdoc 89f5b88958abac65d6204a2ac80a96cc1d696d85feec26f1dab1119c707dc0a2Virustotal results 45.16%Heodo
2020-09-29REP_84607142.docdoc aec0879b78a9a099436d59b73582462c6149429a5b11474954ba0fa0b75d7c64n/aHeodo
2020-09-29DOC_PO_09292020EX.docdoc 18b180a651a5c1f82e1e37fa36fc92e6c0e2516bf788cf33ab3f6f6681be6cc8n/aHeodo
2020-09-29REP_JKH_090120_QFD_092920.docdoc 80c77811d31daab98c1ec0882d3c59b98ad3faadb511c21e4ac662cb9673e1b2Virustotal results 41.94%Heodo
2020-09-29P_00934151.docdoc d3b204a9a314a83910394cbfc8ce9a3ee143f7dff5fb09a1f17b138bd042f27an/aHeodo
2020-09-29FILE_7499262270181663375693651.docdoc 665a83304be8126632283c77fd184c5093b67885447b2ff3832e60ca7131675bn/aHeodo
2020-09-29INV_PO_09292020EX.docdoc ccc18b91da784754f83482778c7bfc1de931b4416de9957b6e7b61b25d8d43caVirustotal results 40.32%Heodo
2020-09-29BAL_MCGLX4Y0VCSD.docdoc e5d1b3e601628703582a921fef151b6f35ed2776cd4a18887cefac671899cee6n/aHeodo