URLhaus Database

You are currently viewing the URLhaus database entry for http://irangamelub.ir/wp-includes/LLC/VCbIlQafIMXFCVbZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:719779
URL: http://irangamelub.ir/wp-includes/LLC/VCbIlQafIMXFCVbZ/
URL Status:Offline
Host: irangamelub.ir
Date added:2020-10-19 20:28:04 UTC
Last online:2020-10-20 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 20:30:08 UTC to report{at}bitcommand[dot]com)
Takedown time:8 hours, 50 minutes Good (down since 2020-10-20 05:20:10 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-2005060084-2020_10_20-O18896.docdoc 87a7289961845b4c5d06554d318aa51a1e4fc5aeb580d9dea164398d968caf14Virustotal results 43.33%Heodo
2020-10-20ARC-20201020-H094.docdoc 17bcf85c3e8000d32daecede094fee54c474bc66ab96fad5dbc428959ee0166bVirustotal results 45.16%Heodo
2020-10-20DAT 2020_10_20 EKB565.docdoc 44c2c1f67fd38ab65b3a8424f7d5ace8c5ed6e044ee2cf9171a215b37481999aVirustotal results 45.00%Heodo
2020-10-20list_2020_10_20.docdoc dc30111a52e8e826eb02cccdc474040ffdda79e363e873f4e17dd1e45b52ca16Virustotal results 44.26%Heodo
2020-10-2002964RI 2020_10_20 MN354.docdoc 427356e6cb2bd5180118dd4c2cf522c27331b85388ddf6405839f2a60baf8d49Virustotal results 41.94%Heodo
2020-10-19Dat-20201020-831430.docdoc 9ae6be8f5b646a1862d814e91092889f433abe7f883de9dd29de175305e3ea45Virustotal results 40.32% Heodo
2020-10-198030XHT_2020_10_20_016613.docdoc 53a8e85b580a174428b6aea5df11ebd5adc7e51dda9f0a65f02dce58d7fdaf41Virustotal results 36.54%Heodo
2020-10-19LIST-2020_10_20-60552.docdoc f20ae55887630c0152d93851005ecc79dd5be55e7d50db99e2e81c799c841d37Virustotal results 38.33% Heodo
2020-10-19Untitled-20201020-736103.docdoc 27e44663219563e7600f8b9da77ab67915fe6f480b27cf6ef50da02c475ea10bVirustotal results 37.10%Heodo
2020-10-19512MK-TGU683111.docdoc 690a4efeaba7d8fb29ee6f9d39381c4f7ac5f540bd5e6ee68505e61e3969d07cVirustotal results 37.10%Heodo
2020-10-19Inf 20201020 Z630.docdoc 462d667db40bf34b4c87eac6795e3be18930efb8cf95f78c3a6eda8d21d6c95bVirustotal results 37.10% Heodo
2020-10-19Mes_QXI381550.docdoc 32e363a27211e8611e12839054d79162639aeab7df60f9040c45ed5748ec3777n/a Heodo
2020-10-19WEU818_20201020_6851.docdoc 2d5db19f14ba5acd1290b35efceb0d2a5fb4b948cc627ccfd3fffa7e41136fb1Virustotal results 37.10%Heodo
2020-10-19LIST_20201019_EO946139.docdoc f411abc0842fb6ed73a4289b5d99b75b99983571b7cdabb113ec585bf64a09f6n/a Heodo