URLhaus Database

You are currently viewing the URLhaus database entry for https://komakmohajerat.ir/wp-content/CS2JQGZXHGQOBD6/ZR8DHD44NKpNc3MFo/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:753711
URL: https://komakmohajerat.ir/wp-content/CS2JQGZXHGQOBD6/ZR8DHD44NKpNc3MFo/
URL Status:Offline
Host: komakmohajerat.ir
Date added:2020-10-26 23:06:05 UTC
Last online:2020-10-27 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-26 23:08:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:3 hours, 6 minutes Good (down since 2020-10-27 02:14:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-27File-2020_10_27-DC95086.docdoc 7db77f1a42a01fd8da4a5ca5eed3c944f6cc3db9caef5ac3e8b5d420b970b612Virustotal results 47.54%Heodo
2020-10-27Mes 20201027 1279620.docdoc ba144b2c722855e58aea0bc21aafb2692d8b535dc920fa40677eee2de5baa662Virustotal results 52.63%Heodo
2020-10-27UNTITLED 2020_10_27 288929.docdoc 39bc04da6b9d4faad7b5cae654c8f59ad7ac01b3fb70e293d8fbf1b5b6e15c61n/aHeodo
2020-10-27Attachment_20201027.docdoc 98ce88c9f247c75c579d1893aa0e20cd63f5a61f4b7ab7a70b4e138e34fed993n/aHeodo
2020-10-27dat 61514.docdoc 82bc786b9af204285f0f89af1602a8e5e1b5df8a914084602d45eabc08922607Virustotal results 50.94%Heodo
2020-10-2751710617 20201027 E746438.docdoc 627c23b11e6048db0ff6e2a44fc9bcd0555c4aedfd31ee768b764b084ecfa5c7Virustotal results 51.85%Heodo
2020-10-27inf_2020_10_27_686250.docdoc 4be5a08e5917bfda74c71ec644045bbf4a80fd8d4a42606da954548f86b90765n/aHeodo
2020-10-27rep_20201027_796.docdoc edf8d1c6eaf9fc29cd8dc065087f100ddc1e811bb4279f1650627028cd2a3c08Virustotal results 42.59%Heodo
2020-10-26REP_2020_10_27_UP938.docdoc d51e0046c1cfccdbbee59aa82fdc5780aace64ee8225348e067170db0a442ba6Virustotal results 41.27%Heodo
2020-10-26Attachment 2020_10_27.docdoc a5f3e8db8097e0528055b569e19bdda01a51fe0e1f03614930c5c428aa0e8b3en/aHeodo