URLhaus Database

You are currently viewing the URLhaus database entry for https://sadafdamghan.com/wp-admin/23532374972840/cb9j64n69cFZqDzjx1s/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753461
URL: https://sadafdamghan.com/wp-admin/23532374972840/cb9j64n69cFZqDzjx1s/
URL Status:Offline
Host: sadafdamghan.com
Date added:2020-10-26 21:46:03 UTC
Last online:2020-10-27 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 21:48:06 UTC to abuse{at}hetzner[dot]com)
Takedown time:9 hours, 8 minutes Good (down since 2020-10-27 06:56:42 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27Rep_20201027_58937.docdoc 03c242449bdafecccd13c4a77493c1baeb80117b2360cd7796e96f93b37fae6an/aHeodo
2020-10-27UNTITLED-2020_10_27-JN465.docdoc 0faabd3dbd6164cf0dd2361ad5fba3999dc153c2765f8a398c8bac6bfb025c72n/aHeodo
2020-10-27rep-P735228.docdoc 25e2948ee6dea97044697955af64bb89205f75802bb417e426d6d3ab8dc908dcn/aHeodo
2020-10-27LIST 2020_10_27 89508.docdoc fad3876dba63b039b011d17ca535f18ea1961cc3569c9ea39a813f1d887ab8b2n/aHeodo
2020-10-271156153_2020_10_27.docdoc b2dd36198ab64fa72b4d6eaac45af4c16d8e108a6449b40ec93f42a177fa185dn/aHeodo
2020-10-27mes 2020_10_27.docdoc 1218dae61d7d72bd4387dbe5dba12a8ca87f4fe817fd909dcd856d0384717a72n/aHeodo
2020-10-27File_2020_10_27.docdoc f9cbf5e9736dff2700f0a73937e5143d63fb6d868ca8e5bcc0f0072b23a47889Virustotal results 53.57%Heodo
2020-10-27DAT-20201027-IGF436599.docdoc f715e2571cf2bfd37aa823b2ddbe5462575a40ed082e3b039329ce574a2be700n/aHeodo
2020-10-27Inf L965568.docdoc 638e44975f0b3264b96dc36febaf47327594bcb7bb203aa8d3cd6caa6aa872e3Virustotal results 51.85%Heodo
2020-10-27Doc-20201027-3901.docdoc 4a18ab940330fb73c1e289748a3cefa188091c8ea0d7babad686162c011b9cdcn/aHeodo
2020-10-27Untitled.docdoc 850d6c02cdf898bc72beada105c810692cb2bfdb8fab3b14e772c2076db9b99fn/aHeodo
2020-10-27list-2020_10_27-RDC60481.docdoc dea0bc4c6fff09c2bd1c8a995db1da421b50f9e57b107db26bc5b71dba427610n/aHeodo
2020-10-27MES-3600056.docdoc c5b2b6d6d926cbb08bb1a896e3b97451b28ece77c39c0896948b761a5f58ee63n/aHeodo
2020-10-27INF_20201027_74506.docdoc 7db77f1a42a01fd8da4a5ca5eed3c944f6cc3db9caef5ac3e8b5d420b970b612n/aHeodo
2020-10-27063332_20201027_079.docdoc ba144b2c722855e58aea0bc21aafb2692d8b535dc920fa40677eee2de5baa662n/aHeodo
2020-10-27ARC 2020_10_27 IZ041322.docdoc c34b033be6ccec716ff4925ce6e96a65872b23103b659fa24f079d99711963bcn/aHeodo
2020-10-27UNTITLED 20201027 LE25670.docdoc 34552d4adde7395abb5b114284e79a47c0aab68c0ab1fc62affe993b7373852en/a Heodo
2020-10-27list 2020_10_27.docdoc 4be5a08e5917bfda74c71ec644045bbf4a80fd8d4a42606da954548f86b90765n/aHeodo
2020-10-26Arc-0968.docdoc 5af94d5b1e905c40d01805e011b493589549f37de4d6eb3e1b68044d47d8988cVirustotal results 41.27%Heodo
2020-10-26Inf-2020_10_27-036.docdoc 83977121b9e97f87d650fe12845d19e59c28ab763af8051d755ea26ca2ae9821Virustotal results 41.51%Heodo
2020-10-26file 2020_10_27 187.docdoc f620c363a605c7c11abe0ed6c9f919168781361df2901e24752c0ebd428c4854n/aHeodo
2020-10-261140_20201027_25050.docdoc bc23d2f73145ee8b7cb2c6599d33dfba5d95c4a49b2f8deab7fd2fe9f2530b9eVirustotal results 40.32% Heodo
2020-10-26mes-2020_10_27-CPL337.docdoc 4e166862bb4b0cd09fb6d5fde9004ac49c14d9ac11f8e9d37f551c815721128aVirustotal results 38.71%Heodo
2020-10-26Attachment_20201026_P74125.docdoc 31086afbd5dd032e22abadd031a2e61e2af43af502a030068c2c5376efde09c2Virustotal results 32.76%Heodo