URLhaus Database

You are currently viewing the URLhaus database entry for http://mashhadkabinet.ir/wp-admin/attachments/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:727244
URL: http://mashhadkabinet.ir/wp-admin/attachments/
URL Status:Offline
Host: mashhadkabinet.ir
Date added:2020-10-21 05:57:26 UTC
Last online:2020-10-21 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-10-21 06:08:14 UTC to abuse{at}hetzner[dot]com)
Takedown time:12 hours, 40 minutes Good (down since 2020-10-21 18:49:06 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21DOC_9211778772550263806569767.docdoc a28398627e5a0e0869aa7177f328559dcae1253a785594871a5f33792172413an/aHeodo
2020-10-21I_PO_10212020EX.docdoc 7606c587c9a22687f99deb394aedd9be63d066c53c44d9cb78dc3a03319f670cn/aHeodo
2020-10-21BAL_PO_10212020EX.docdoc 99d7234dc759302b6b38de85547762ca5a46358e93508509b534755c9af8c309Virustotal results 30.19%Heodo
2020-10-21PO_10212020EX.docdoc c0308a4a6567ed36df7165b3cffbe26f676322783de09900dd7b7e6b7d642b97n/aHeodo
2020-10-21X_10035426.docdoc f168ef97aa8cb399a6f327fb6a301f7ae5e115c7ed1ad5c8b59819663bebd7e2Virustotal results 26.42%Heodo
2020-10-21INV_04559925.docdoc 65afacffdde9c2202e28125192dbfc1094522200913e53bd6d003b6a1754f3f7Virustotal results 20.97%Heodo
2020-10-21BAL_O9CMP3G.docdoc 503fdf65f1c044ed826175a175b354f7dfb32e1fb66e83065827d7365f1b9dc9n/aHeodo
2020-10-21WJ9822087656FU.docdoc abd94a7b58ada746b22d9d6a4ef2b3847deda4d5569325459951c0c7f3b2a355n/aHeodo
2020-10-21FY8366681362KT.docdoc 48dcc11f86c806e63c91ec7c94212e16f1ce37001949a1c5ce938839122aa5a0n/aHeodo
2020-10-21LLM_100120_CEX_102120.docdoc f647e044db03f36251bf4a293d89b0d2272806920917eeb10166f289f3a6a503n/aHeodo
2020-10-21US3ZFCSVQI.docdoc aad3348c28dbb9e0a038508e8fde9f2771e550228320b8ebc0f6cf1d11c39945n/aHeodo
2020-10-21REP_LW4738763207GM.docdoc f93730c27fbb9a6c6cc64e5f4d9127854a0c11d165e699569dd0828ebee3ec4bVirustotal results 27.42%Heodo
2020-10-21FILE_53135742.docdoc 64c0402c0b906a218b1e4c2101145066a57b5a034a16a82957081f8ca15b4763Virustotal results 27.87%Heodo
2020-10-21V_OE7QHT991KYS.docdoc 0564c8bd86a30a6d5f73adf8e176a2b82925865e9ab188708c901e865405bc34n/aHeodo
2020-10-21REP_EZ0RVPPBFLSSD4.docdoc 6d21ebd2968beb17398f1ae51734c82dc41ee7eea21a41abf7ede25119c77b79n/aHeodo
2020-10-21SRYO_MA8GOLEVH20AM8.docdoc a2ff9d64e27e7cf089d0bfa4d9bae935db0cc9881bf6767dd311ccf653fe64b6n/aHeodo
2020-10-21680725102715.docdoc 3c7b26a013548adeebf30936453b373c34b920df67fb1b135775f0ea8ba32341Virustotal results 50.00%Heodo
2020-10-21A_DYZ_100120_ZEX_102120.docdoc 28d5bdccce4b904f522a8aeda9f16fd87ea3831634ef34c5a660e3ae21a0229fVirustotal results 50.82%Heodo
2020-10-21XS3311649889GV.docdoc 6a71e77723470c71b7481201af67c2a3fccef877d132370bdb2a3d8a705ce95dn/aHeodo
2020-10-21INV_OBC_100120_PRX_102120.docdoc 5b78a4ef32efd6eba54e53df8b14092631d475f672d60774c26f20dbe0ed5f7fVirustotal results 50.00%Heodo
2020-10-21L_PO_10212020EX.docdoc 7bb0c64469d6f91a86db62a275cfbfa0b6bbf04e10bde77f507649c0adbd844an/aHeodo
2020-10-21FILE_CP2602213082EE.docdoc 70a369ce3943f743ffc7740c3c003a5f00705abf0505641d7d193d5cf79b8dc5Virustotal results 50.00%Heodo
2020-10-21YXX_100120_QJH_102120.docdoc 66ff2845aa49250c6a643867ff07164647006a80a5fadaddb5d41c99fd6b9452n/aHeodo
2020-10-21REP_39390101.docdoc ac7a97c3cec7627c0004f000f937a50d9289722848c8d222f58542043b209afeVirustotal results 49.18%Heodo
2020-10-21G_863793536929958590493329.docdoc 844d9efee04baab149ff86c31963c101151796f861eb84cd816fde655e3f7f78Virustotal results 39.34%Heodo