URLhaus Database

You are currently viewing the URLhaus database entry for http://ofoghzagros.com/wp-admin/attachments/RjZgeQk6sFOBciQn7l/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:624675
URL: http://ofoghzagros.com/wp-admin/attachments/RjZgeQk6sFOBciQn7l/
URL Status:Offline
Host: ofoghzagros.com
Date added:2020-09-29 19:34:04 UTC
Last online:2020-10-09 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-29 19:36:32 UTC to esmailian{at}hostiran[dot]com)
Takedown time:9 days, 20 hours, 32 minutes Bad (down since 2020-10-09 16:08:46 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-01dat_2020_10_01_264.docdoc 7864011d471f60276a1a8f1f3d6e7578a2aa50df32a139c796cdb0ea92b311afn/aHeodo
2020-10-01DAT 2020_10_01 294822.docdoc 40221abe560080243497513ad209ccc44547a051839b9fbf63f90d06e60d01c1n/aHeodo
2020-10-01Inf 2020_10_01.docdoc 473dd492323f957f2e279d73dd8aa9582365020ba800a3969c435c7a9a69f10cn/aHeodo
2020-10-01Untitled_2020_10_01_606575.docdoc d69c55c3fd6ac15d34a268863676ba3c6ab5432022fadb56a326e19d6c194c97n/aHeodo
2020-10-01ARC-2020_10_01.docdoc b20ac0a4b40e64a92fc621a6b17d5394de64c8aff0c57022e488b529866eb7faVirustotal results 20.97%Heodo
2020-10-01ARC 2020_10_01 LPP258198.docdoc 6e479b2ad5944afd22a2e516b58a97af6cf1e4ee558ab6c7e4302d2c9928b878n/aHeodo
2020-10-01rep 20201001 12663.docdoc 5dc35d0f237e44b3377a6e13ccea24f31517bc05dfc92d75a91a5343b6c1a9ebn/aHeodo
2020-10-01Dat-2020_10_01-22511.docdoc a2bdc474a5f371cab83004e856bcabe60d9eab2ea3c70babfb04a5d7c4d126faVirustotal results 21.67%Heodo
2020-10-011128_WWJ576467.docdoc 1fad0d1e9f92471ad92d8d22694e3fc307735bc004af3b0c3a402f22fa6eed3dVirustotal results 20.97%Heodo
2020-10-01File_2020_10_01_BI681411.docdoc fb67d18808f34180ad4381fb4f25f4f5f2d5888b7f1754fe0e37450d145f1f55n/aHeodo
2020-10-0105532265.docdoc 211f2c462c3c6a670add324dece52fa65dfe0be419f4f6fbf97c1d2b76064607Virustotal results 29.51%Heodo
2020-10-01Dat_BP2621.docdoc 42924445248925ca63dfe357ea9bb0db36187cc9ab8ccbf32dff5aace6cffbdcn/aHeodo
2020-10-0155071115_2020_10_01.docdoc 2daed7426a6004656ac72c724385d6e1a0f050392c5696d572d82142e1ee54d3n/aHeodo
2020-10-01arc-2020_10_01-A21373.docdoc 526cd15ebb75a2c969720137e43ee196453d4ca3af2c45b9da57fa31de578525n/aHeodo
2020-10-01Arc 20201001 813280.docdoc 746113af0253d11772b82c935ec29f4686e5a6ad13798afc399e00556208bc24n/aHeodo
2020-10-01dat 20201001 YNJ364.docdoc 7429eb4c7aa5cef498281fc28ae0563cf6288ac9e648a5246d4169c04851a3a0n/aHeodo
2020-10-01Arc-2020_10_01-7674.docdoc 027b39d7358ec5bffc52928ef8236adc97babedbc2660930703c101ee8dea040Virustotal results 29.51%Heodo
2020-10-01MES 2020_10_01 127.docdoc 172501fc94085c45c6767dfe4c639f3cf899a1e5ed1fd55fe64f24246ac7abf0n/aHeodo
2020-10-01Untitled 2020_10_01 XO921.docdoc 4bd8263c0751db82dbb92c4c6fc12a02050ca69256a36a40ee79b994a0cdbe8bn/aHeodo
2020-10-01A5259.docdoc 8998ec032fa30214eadcf34d4ae6d8bd530957b55675e54b57665b2c1e2f4408n/aHeodo
2020-10-01UNTITLED-2020_10_01-9250.docdoc fa402b46a58df4de9b7f67dcd0b60999758aa5223df069063ad1780aa750e108n/aHeodo
2020-10-01Untitled-2320122.docdoc f9a2c035b1b044de880b93f5656846750bbb7710042f746070a78d7c63f543bfn/aHeodo
2020-10-01LIST N499.docdoc c6a5e92e0cb32aa9793cecb37169e0f19bfff5a681eb8afabb7fdfa50b3460b6n/aHeodo
2020-10-01MES-EP34445.docdoc eac89add4434c6c66f2a1a0a1e47325ed6e128df191a9d071876eb27aec35494n/aHeodo
2020-10-01LIST 20201001 ZAI396681.docdoc e38287f1b647f4d256a667999ac40b6d99ef0c0555f54275c08874d77bead623n/aHeodo
2020-10-01Doc PPB797787.docdoc b485e78d9d359908adac14d8704a16c7c807990e55333c254e78aecab1f49bdcVirustotal results 29.03%Heodo
2020-10-01ARC 483.docdoc 8fe81e1ef89033a5b0d49b07f90a5e3642117bd7fe3de8d0dfdcad5e740b9160n/aHeodo
2020-10-01inf-3039456.docdoc 1602d8655094a28e4a57ca5925f75d554d1b3e50d86bc343ea4f3bc82a82ca3bn/aHeodo
2020-10-01File_2020_10_01_A104384.docdoc 0e679fcd3e3930b25a4dd0e52276852fd343c4756bee0468b2e1feab00d76127n/aHeodo
2020-10-01INF 20201001.docdoc 53f54414b908517e13b7e991516ff1e547fa3251a30b2acedebfc9b5372442d6n/aHeodo
2020-10-01list 20201001 977.docdoc d199ffc644282ddce1abe32fe185f18f4ab42f281a15f99ee3009741007e1ec4n/aHeodo
2020-10-01Rep 2020_10_01 520.docdoc c94992c8c874b0d45a2c8bdb534d13766c0ee32768709103fcd79f992a2aae5dn/aHeodo
2020-10-01P56379 20201001.docdoc 969194e274b5cb496b8ad0c40cf036c6c0a8a4bc4de73599cd2b8020284cfdc4n/aHeodo
2020-10-01file-20201001-VVT485.docdoc 68a9aec657c1f8328678d879279fb90a5c21f9f527f0c08b1a23a3f576dcbee2n/aHeodo
2020-10-01FILE 2020_10_01 STQ7296.docdoc 4e29f93d23065a600d39a4f1db754b951bd6a38706c145d990df65d6ebf5b6dfn/aHeodo
2020-10-01rep_2020_10_01_1605.docdoc dc08afe4ed308f6184aa8d80fd1fb44a00cb3c46c7f3b4a49702845b145d3fc0Virustotal results 37.10%Heodo
2020-10-018513CM 2020_10_01 487.docdoc 46a59f3fe0efcffcdfcd2c366c3cda5205ab4f7c79e6c11c1bac4ea7247906d5n/aHeodo
2020-10-01Mes_2020_10_01_ARI3194.docdoc f4aeb1fb3ee7a1e47154bd3b5b2209626b73ca9812072ce7597fd191cc384e93n/aHeodo
2020-10-01File.docdoc d66305170c4d1718156918c0580b9ebb5b1186ca6df4899f266ff1d1bd0cbcffn/aHeodo
2020-10-01Dat_20201001_2964.docdoc bca937c5b07cf43a6469fae63640f655c5bbdacff9c671b53965974a5203c262Virustotal results 37.10%Heodo
2020-10-01doc_KKS995283.docdoc b2af72414cca6a559fbc5e9254b6080ce9d292ef4b2a37d8973118f7fffca277n/aHeodo
2020-10-0156468_20201001_5265.docdoc b3776f674d9ce6db3d98ad056a43c66c185a8109320db88ec042c4224ff2d5ffVirustotal results 36.07%Heodo
2020-10-01MES-2020_10_01-965.docdoc c37536624e100c6928618bde49c7c002a4795fe400199b57806f7e5a6bfb1c4en/aHeodo
2020-10-01Arc_HB90832.docdoc 2ce45b11fa32eb63d439d9a9faeda5a4bbf6739316516a3d5d9e3a3d9e44f0d7n/aHeodo
2020-10-01inf_2020_10_01_69920.docdoc 2316491908b1b0175a9782d21fef85f16d29b5dd05d72c00c8dc943ee110afb4Virustotal results 35.48%Heodo
2020-10-01LIST.docdoc 85226bf4b5aae875eb53ec867bf5e5349c57c45cca5e2077e05eb090328c4d61Virustotal results 35.00%Heodo
2020-10-01Untitled_2020_10_01_LMU193.docdoc 0c0381a7bb4ec4098028f1d61410ffd974a4208f412fd5fec4db2ee06113fd00Virustotal results 32.26%Heodo
2020-10-01707002_20201001_R2398.docdoc 625b3a690caaa5c130c9cf6aff2104b733573c0124222e7761d9d9abd7f5bc03Virustotal results 29.51%Heodo
2020-10-01mes 2969.docdoc 36b825e5f10075c6d5dc769f9ce6d8e200283cf0b8b9bdc0e0a4c69229164962n/aHeodo
2020-10-01LIST 20201001 32630.docdoc 1127939b95fc439579b8513866e2a50ebeb5657a717a1d6425d49782213b55aeVirustotal results 29.03%Heodo
2020-10-0144086861.docdoc f599f04651361e4298bea8b9c219e4588d021a8cbf00802660a69c92584446d8Virustotal results 26.67%Heodo
2020-10-0144086861.docdoc f599f04651361e4298bea8b9c219e4588d021a8cbf00802660a69c92584446d8Virustotal results 26.67%Heodo
2020-10-01File M32991.docdoc 40c1adc94c0e2bc34dfb84c1c426ccbf50749fe7b5d367759bb22cb69cdf3764Virustotal results 27.42%Heodo
2020-10-01464934_7465458.docdoc 1065e6daa80b86a72a1d83d506754e2095355742ba0162e798a32fe05d39c265n/aHeodo
2020-09-30Mes-20201001-CT480506.docdoc 83528dd86f27eafffd6b8b9bc31bcd40ce046ae2f1eadc585ccc3125af320625Virustotal results 27.87%Heodo
2020-09-30976ZG-2020_10_01-DUY1555.docdoc 22fe0364950c229cd81ec4900c5082c63179d87b3475e0ba2533f7d02d0a9658Virustotal results 27.42%Heodo
2020-09-30inf-UYX896554.docdoc 24a4f7d8cf601311928b7d9c78fd6067e4b6e6a47c641fbdc86703b0dd3f1ee7Virustotal results 27.42%Heodo
2020-09-30Mes_20201001_0200.docdoc 4775719b443e192325610b1eb79d188314e42c2dbdd27c3d2aaee14a082a5176Virustotal results 25.81%Heodo
2020-09-30inf_LY784837.docdoc 59218dd633aa6e55d901c1a8227ace241e21d80c34af6fbd4dd99400832ef122Virustotal results 25.81%Heodo
2020-09-30Inf_20201001_582746.docdoc 7b2561cccd85d4a2dd4d7c8c873b6e498f1030c959b48a8899a4032502d0c4c4n/aHeodo
2020-09-30Attachment-TZ934294.docdoc fe188a82b959918eac4007d04f619ee4ad081730eaa6da718e8e4e0cd9d594a0Virustotal results 25.81%Heodo
2020-09-30mes.docdoc ace7c44fed1f38871ec370fc6b6c083e3834294d3f6430ffafce94847c4ac514Virustotal results 24.59%Heodo
2020-09-30Rep 2020_09_30 7973.docdoc 164fe479632bdf27098b3df0069d2cd134548e39cee7d60201a17b4ea0579b90Virustotal results 24.19%Heodo
2020-09-30mes_20200930_77553.docdoc e92f158f2faa36f1af7c6995a3e4433ef891eb4dcfa6a15c6ad994527c01d680n/aHeodo
2020-09-30Attachment 4814.docdoc 9d324dca782f0c31fabf90945e2299934a2a4a5f08c328100843fa3c06380300n/aHeodo
2020-09-30doc_0497263.docdoc 02198f1315ee82122a2ea1c3eca55fbe9a061bf7d75e9db6c7b0e49bbd7108fdn/aHeodo
2020-09-30arc_20200930_QAT441.docdoc b04512682b99769e9f703d6e0d527806605144a0c723b530c2467182ad6cd807n/aHeodo
2020-09-30UNTITLED 689.docdoc 2d9e75292b55b3da07fd07a437ba2963d5e46d7f2610cf07eb6c16fe9795bd99n/aHeodo
2020-09-30FILE_2020_09_30_LVY099170.docdoc 6d252cf9f5ba5ca72addfd64afee22e96d0205e1f0dce0fee750a463e1f3166bVirustotal results 24.19%Heodo
2020-09-30file.docdoc b03527f06cf23a197a3ed8826c8e376391264fa6bbff6dac29b2ef9af6dfb8c1Virustotal results 24.19%Heodo
2020-09-30rep_20200930_3761.docdoc f47d11699a95847586f0da23f16b981f953514459199b7edd30f723054c057f7Virustotal results 24.19%Heodo
2020-09-30Attachment_2020_09_30_I5516.docdoc 23929af7e2725266933c2cafc657a7a095d42ee57beaa65c45d573614720a51en/aHeodo
2020-09-30LIST-20200930-UB2673.docdoc 45e1f883fdc6cad4f635eaef749c53e835d79fc175cc58e46113473d6c93d76bn/aHeodo
2020-09-30dat_20200930_841823.docdoc fe2b3b26f27a28edd30637e0731391445f14567e3b456f3ce5f2250d3ba58d71Virustotal results 22.58%Heodo
2020-09-30inf-2020_09_30-Q483517.docdoc d369ce3145ebcff9f0c8a26e73bc932142a4dac2dfac18a840976d66f8c427baVirustotal results 22.58%Heodo
2020-09-30Arc-2020_09_30-691.docdoc bb859c1cdc55c8efda32c573ecc7e09c0692cf12de6a7c4bdc300e6e86456782n/aHeodo
2020-09-30YWG05528 2020_09_30.docdoc bba8eee6c7052816d44796927ca6001f69f76e479ac041cf0331e13e167d0b99n/aHeodo
2020-09-30Doc 20200930 UVT33434.docdoc ce437cd41adb6661b0e4389bcb5f69ac300b5e9c7fafe156dec9f8df767b625bn/aHeodo
2020-09-30FILE-2020_09_30-4377248.docdoc 2e596652391370bfcf5e776a4379dd5061fcb4441200889c726c34ea6207ee9bn/aHeodo
2020-09-30Arc.docdoc 0fd48786b12e8874cb785d93797affdebf211a8f67c6a295a1a95758003d0efbn/aHeodo
2020-09-30Attachment_20200930_57715.docdoc 90de4105fc91aa76e474d5d94fe9fd26b8d6983986653c2d8592f39376ba5652n/aHeodo
2020-09-30Dat.docdoc 2fbc53c50b9b33c49311e11a41aa64660b305c9c7d4a4db3986c59a1a77696a8n/aHeodo
2020-09-30Untitled-MN67980.docdoc d1d29ec48f52dafe3baabff310d309ee7de8c725618d5db63307636e5ff68f4bn/aHeodo
2020-09-30arc_20200930_8134.docdoc be1d469e7f434641202ffde45e666cd4b1d255814f8cbf344a3aff1e78e86768n/aHeodo
2020-09-300359-2020_09_30-N793205.docdoc ce1d7fe9a715dbd5b408b17ff12010a67d3d1d002a9484370931304e35254f12Virustotal results 22.95%Heodo
2020-09-30LIST LRM717743.docdoc 9a188064a2a9086199f61142baab865667e9293f4147c5d5fbdad9f33a9435a8n/aHeodo
2020-09-30Inf 20200930 KV304.docdoc 5bf5490d9daa5f884b6597377c8d3f4200a86f12a88c613b3b633681f3998191n/aHeodo
2020-09-30FILE-382140.docdoc e03fed3300d293debbc3a22ecad92ca0d5081711bb790d7a954385a2abf5ba1fn/aHeodo
2020-09-30INF 15088.docdoc 5dc39fed6361864ebfcfe504125bbc05e085ad4f1fb6c92a3367bcad83b695cbn/aHeodo
2020-09-30Rep_2817401.docdoc 76e9e55c307f36acc01ada6e260d9bf3c42193efdf36fed710a1bcd58594f0afn/aHeodo
2020-09-30FILE 2020_09_30 6253.docdoc 256502742604a44a66dbaa6aa7212ceaee9208fb4d81a2bfce33ca99cf8bf91cn/aHeodo
2020-09-30inf 20200930 368.docdoc bad41fd54566d0788fee3c04e575f002e704a1f814e82f99956132b14e7ef9b8Virustotal results 22.58%Heodo
2020-09-30DAT LH789.docdoc 11d48758db4b97fe1625c9d80fadcb112fc27ad3fc1bf4028fd1e8ff5a3eb9d1n/aHeodo
2020-09-30DAT 2020_09_30 2621766.docdoc a3f7b976b0c108284bf0de59187798f84d509ad7182c92761cedbb9b35ba4a3dn/aHeodo
2020-09-30rep 2020_09_30 5606.docdoc 848472a593e725755e8a0b52a61189cab28bedfa9f8d62a7a528790838e7d9acn/aHeodo
2020-09-30dat-2020_09_30-X094.docdoc 665096dfe25e4e636f41d66df9cc4cfb35a0a347a0a1424b191c7b5834179dbfn/aHeodo
2020-09-30Dat-9790.docdoc 740e43567145812a52fc449cd0b44e6aae69157aea605122c661688f820eb440n/aHeodo
2020-09-30inf-Z03940.docdoc 7464edd6b84b35d71ec4b891bd85c2918da1024f18f49f0e06192b440eb5f364n/aHeodo
2020-09-30mes_20200930.docdoc 22f844a158ab002c4375f2234f5a539f0b1b5199f33b442d4869765ea22ca27aVirustotal results 47.54% Heodo
2020-09-30Attachments_2020_09_30.docdoc 9514f8559ebc3346ee2ad8a0dc066f680f456064bcb9dc07a2b528f14293d522Virustotal results 46.77%Heodo
2020-09-30dat_20200930_A3032.docdoc e0241059c22b3f4c297b2b6d6c3d0d854d45f39af3ec08495ca2b04025772414n/aHeodo
2020-09-30969G-2020_09_30-L39371.docdoc fe7a953a524746ec38ded3f4aa02efd66cb67e9223f9e01150cdbb36101696d8Virustotal results 45.16%Heodo
2020-09-30LIST-2020_09_30-4733.docdoc 267561ab8d4856ba0064185a8d6269693f1c580b721f16db305b6a9299f5c41dVirustotal results 45.16%Heodo
2020-09-304368897 8245.docdoc 89512a4396d991ea5a6384037a7418d9f30bfe1d444f2fbef7a0c0b5f2f421d4Virustotal results 45.90%Heodo
2020-09-3016982FE 2020_09_30 Y2478.docdoc 18c9ca3eaf44c72da3a3b8a071775d824b0c4020005a02f213b248ca246e95f4Virustotal results 45.90%Heodo
2020-09-30Doc 20200930 R920.docdoc 892d8f9cfb26bae3277304d3396027dd55d0899e78181a1431bb43e29dd3e857n/aHeodo
2020-09-30arc-20200930-YGA577.docdoc 9d14d3ff8abad95d71af0043f19dd1644cfa14ceb0a6ba617a49f3bd559523cfVirustotal results 40.32%Heodo
2020-09-30Inf 20200930 4303093.docdoc f8b2d066f5a3d657edb1544f9df31a9a7b3121c5c14ddb1b96b50ddd69b44c22Virustotal results 37.70%Heodo
2020-09-30XBI741-0315.docdoc 058c2e8f57729727ed29b3c713fb0147a3b79eb1ca1360453aad3185f45e41c8Virustotal results 35.48%Heodo
2020-09-30file-L05308.docdoc 329d9911d2004877126f938ba6875d9f348d33b31e1ccd880a2a62adb461d1a9Virustotal results 32.26%Heodo
2020-09-30arc-YFN927.docdoc 3f2c230c00d8140a1297b360252ccc7a30d002e039359b9a9d3c08cbfd378fc6Virustotal results 32.26%Heodo
2020-09-30rep_881236.docdoc 07f05248ebd561f95c8b5988fddd0396c6d3c0a61015e3cf154e1e97f2af015aVirustotal results 32.26%Heodo
2020-09-30arc_2020_09_30_528.docdoc 10f4a118d75e59c1f0ae83e7e44c9553fd6925a4bcf21a4cb62559c38c550147Virustotal results 31.15%Heodo
2020-09-30Doc-20200930-J418137.docdoc 7d9b105bc30d62bcdd42543f64fbb302ff4a66be6a6d588357338a2437f9af74n/aHeodo
2020-09-30arc 2020_09_30 052.docdoc 02c3c1d0653a24c203ad1bcef154e65e155db910100619634569eed5982b5d26Virustotal results 32.26%Heodo
2020-09-30rep RN0876.docdoc b89e3c01c95337c6976cfdbc20163b4375eb1a0a76a87335e891fcd932c361d1Virustotal results 30.00%Heodo
2020-09-29Doc_XQ92085.docdoc dc873a463b8cbee41eb8683d98db5a331553402391ba1c16e664c7034eb1acafn/aHeodo
2020-09-29file 2056855.docdoc 1d742e585ed7b4c237726a945da11795c46da01716e9da561d98fff100ee938fVirustotal results 31.15%Heodo
2020-09-29Untitled_9482.docdoc e7d3de1844977926a2db718f9070a7a0e3558b8a8b50961f39271e286a423963n/a Heodo
2020-09-2953055 20200930 7024879.docdoc eeb152640a9662420b865da4ac765f66469ebd7aa3568a51b62e286ce5806435n/aHeodo
2020-09-29list 20200930 2847.docdoc 004d7159e2360d1569de7849fbd5ffa3e63968d011834c565255ade18fcd54cbn/aHeodo
2020-09-29INF_20200930_93373.docdoc bd56a042ecf4e68f3f6d427ca4ee9ad03267b1e53db58ae19e8335e34f6231f1n/aHeodo
2020-09-290019241-2020_09_30-828.docdoc e217a7b6b8d3730d1f902b14dce65e6146ed92bf808d911ff003e7dbb8f29a71Virustotal results 19.67%Heodo
2020-09-29Untitled-2020_09_29-DRT33242.docdoc 3ed38db3201fe400b1e0533ba551a1f631a550297afec1d65ce776dc9ed958e0Virustotal results 21.31%Heodo
2020-09-29dat-20200929-RKN945994.docdoc 546e960f2f85a196f5e12d60e0eedeeab059bf99f6e448a7b7f3bd6706b8166cVirustotal results 19.67% Heodo
2020-09-29Dat_2020_09_29_47996.docdoc 66e0d59d4c4e46b4e5589d41dbb45277b6dd25aba1efb68deada81d72a492aebn/aHeodo
2020-09-29List 20200929 1739.docdoc 65b6ad21a24f882ef5e67c7126644c2427a2ede7bba65315180693daa77fb5f8Virustotal results 19.67%Heodo
2020-09-29rep 2020_09_29 WXD55962.docdoc 685e3e4ea0851f195ade4ba3673387a5c69eb1633d3daae4666e5aad9dabaf7en/aHeodo