URLhaus Database

You are currently viewing the URLhaus database entry for https://www.sadafdamghan.com/wp-admin/23532374972840/cb9j64n69cFZqDzjx1s/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:752521
URL: https://www.sadafdamghan.com/wp-admin/23532374972840/cb9j64n69cFZqDzjx1s/
URL Status:Offline
Host: www.sadafdamghan.com
Date added:2020-10-26 16:49:04 UTC
Last online:2020-10-27 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 16:50:16 UTC to abuse{at}hetzner[dot]com)
Takedown time:14 hours, 14 minutes Good (down since 2020-10-27 07:05:13 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27File-20201027-SJ735.docdoc 0f84086df046d8247545c6850bdd674cc2ec7f6917a000402e5601f869877440Virustotal results 28.57%Heodo
2020-10-27ARC_20201027.docdoc c8a26a6bf04fa1b4487e91652089536164904c9871390ff9384b964ab9ff8923n/aHeodo
2020-10-27file-2020_10_27-1471491.docdoc bbcf342f38fad4cb3b252689523b40dbee9d9ac7fc13a132a7159a2319704997n/aHeodo
2020-10-27list_20201027_K99053.docdoc 025c53c15a718576f252e314fd616fd0254ba584908745032798dcd45f930eb1n/aHeodo
2020-10-27LIST 2020_10_27 89508.docdoc fad3876dba63b039b011d17ca535f18ea1961cc3569c9ea39a813f1d887ab8b2n/aHeodo
2020-10-27Doc-20201027-42602.docdoc b2dd36198ab64fa72b4d6eaac45af4c16d8e108a6449b40ec93f42a177fa185dn/aHeodo
2020-10-27arc-ITW4879.docdoc 124f56eaa0b487e7b12b941084ad16075fec2f6f8f9016dd7366c8c33d18f531n/aHeodo
2020-10-27arc-2020_10_27-WA335.docdoc ba8769c88b663f9b0c6c929dd205c97e2309d714936a6f17d5e2eb479e8a48c1n/aHeodo
2020-10-27DAT-20201027-IGF436599.docdoc f715e2571cf2bfd37aa823b2ddbe5462575a40ed082e3b039329ce574a2be700n/aHeodo
2020-10-27File_20201027_73304.docdoc 9c8e29cf162bd43604573c0a82cc8375a4f728d790c0c5e9c090b23672e5e529n/aHeodo
2020-10-270380_HG960.docdoc b476a22032820fe10208a586bc4a6d4e0cbf3c24aa884da7fa6563758151493dVirustotal results 52.94%Heodo
2020-10-27Untitled.docdoc 850d6c02cdf898bc72beada105c810692cb2bfdb8fab3b14e772c2076db9b99fn/aHeodo
2020-10-27Untitled 1776936.docdoc dea0bc4c6fff09c2bd1c8a995db1da421b50f9e57b107db26bc5b71dba427610n/aHeodo
2020-10-27INF_20201027_74506.docdoc 7db77f1a42a01fd8da4a5ca5eed3c944f6cc3db9caef5ac3e8b5d420b970b612n/aHeodo
2020-10-27560L-2020_10_27-QC624803.docdoc 63de45b66603ef77afff13bd0ba2dc21747b5f6d5b0f4aa2ab8d3d373d5c4b68n/aHeodo
2020-10-27rep_20201027.docdoc a8af91bef70904171bef405f02b5defa05d6b30f158c7ad6360a7436e6b7be3fVirustotal results 48.15%Heodo
2020-10-27ARC 2020_10_27 IZ041322.docdoc c34b033be6ccec716ff4925ce6e96a65872b23103b659fa24f079d99711963bcn/aHeodo
2020-10-27file Y99791.docdoc 82bc786b9af204285f0f89af1602a8e5e1b5df8a914084602d45eabc08922607Virustotal results 50.94%Heodo
2020-10-27doc_2020_10_27_JQL036.docdoc 34552d4adde7395abb5b114284e79a47c0aab68c0ab1fc62affe993b7373852eVirustotal results 48.39% Heodo
2020-10-27FILE 20201027 ML7523.docdoc 4be5a08e5917bfda74c71ec644045bbf4a80fd8d4a42606da954548f86b90765Virustotal results 46.77%Heodo
2020-10-26Attachments 20201027.docdoc edf8d1c6eaf9fc29cd8dc065087f100ddc1e811bb4279f1650627028cd2a3c08n/aHeodo
2020-10-26DAT_K674.docdoc d51e0046c1cfccdbbee59aa82fdc5780aace64ee8225348e067170db0a442ba6n/aHeodo
2020-10-26file 2020_10_27 187.docdoc f620c363a605c7c11abe0ed6c9f919168781361df2901e24752c0ebd428c4854n/aHeodo
2020-10-26Attachments 2020_10_27 7095181.docdoc 73d1b4c3fb5a035d592fd68fb3393cbfbd659c6fb165d4aebb3c1abd953aa593Virustotal results 40.74%Heodo
2020-10-26Attachment-2020_10_27-RT813330.docdoc 9624eca338cef03d8004d874cd0c774bf67ece67290d5a0022da8117345b11c6n/a Heodo
2020-10-26Attachment_20201026_P74125.docdoc 31086afbd5dd032e22abadd031a2e61e2af43af502a030068c2c5376efde09c2Virustotal results 32.76%Heodo
2020-10-26UNTITLED-20201026-M63707.docdoc d90ed0030c1275bb1ddd893fd29e73bdcd9ba1321e78c8a7525f30e5786c4431n/aHeodo
2020-10-26list-2020_10_26-TZA818.docdoc 4d7c83ab9cbadd584834009dce7bde2c59c2867fab78b643766b83bab6899445n/aHeodo
2020-10-26DAT-2020_10_26-P9402.docdoc ff5007b5761e068b27ecde2c4c2a63d1ffa24ad25ea98ec266369b5ed35d8d17n/a Heodo
2020-10-26Doc_2238.docdoc b1b9d4c785c61ee38c3c543ce248b7e2380a84b608eafa74a370d0a95d0bad4cn/a Heodo