URLhaus Database

You are currently viewing the URLhaus database entry for https://roobazar.ir/wp-admin/IdWop1jP9RgxdJULzaFzHYaWOUTvDZZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:758821
URL: https://roobazar.ir/wp-admin/IdWop1jP9RgxdJULzaFzHYaWOUTvDZZ/
URL Status:Offline
Host: roobazar.ir
Date added:2020-10-28 01:34:09 UTC
Last online:2020-10-28 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 01:36:57 UTC to abuse{at}faraso[dot]org)
Takedown time:7 hours, 12 minutes Good (down since 2020-10-28 08:49:35 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-28Doc_80896537.docdoc 4a40f7f94b6987d15605eb7e6ccd22baede35a72d60278537f9aedbd6d7a909fVirustotal results 28.57%Heodo
2020-10-28ARC_PO_10282020EX.docdoc af7a1932766cf0a2a6bc07298751e49a47f81b2b7f255579bcc6d1a93f335af4Virustotal results 29.03%Heodo
2020-10-28INF_GML_100120_CWP_102820.docdoc 4da551741b2fdd1985b8f8dd865cbc2ee100a8d82d80a39e33f56dbda25b4f1en/aHeodo
2020-10-28Inf_IYW_100120_NTP_102820.docdoc 86cdca7c9ac7ecd5defa0fb8c374cd773aad5df00d6678e7f5addc0268a097e3Virustotal results 28.57%Heodo
2020-10-28C_88776920.docdoc 089982175b8c27323227a0cbe60942992e1cd89852436e481f6947e75cb25d67n/aHeodo
2020-10-28file_MT7259389889KD.docdoc 68cb170125b6d8fe85e4573f3324f27ca595e8a2a2f0d624742c817590b42765n/aHeodo
2020-10-28FILE_76J9BGZ.docdoc 087c51a90ce1975819e515fd65ce7583219cb9a7eecfe2c20191cf2d1196eac9n/aHeodo
2020-10-28V2RX5IS37RG.docdoc f605f4309f21e3797ba0f7b9440dbd45fb913a363be8a0e774040e92e05418fdVirustotal results 35.48%Heodo
2020-10-28Attachments_KORY6ZFU2QX.docdoc 9c509bf6c3b7824436cb299b2efffd013f3b0b156e9398a6975b71b50152cac3Virustotal results 40.74%Heodo
2020-10-28INF_ZOK_100120_WZW_102820.docdoc c81da9358cac9552a6d4005fa1c6ed570a70d9aaca86836e670acafe475cf882Virustotal results 32.08%Heodo
2020-10-28VSJ_03475190.docdoc 0250f0fd12c78f615ebd384a8bda63e6ff45039b0005ab5211ae72a4ab4b97d1n/aHeodo
2020-10-28INF_PO_10282020EX.docdoc f43cc95ed3a2f8900938c6a240d69a2de909494821ee8308e740e2cda2fd31d7n/aHeodo
2020-10-28LIST_365736724.docdoc 3120df1e06f01820a9e9aaf64e33f5ff4b4e39647ef7552f6f98535a9c17e68dVirustotal results 31.48%Heodo
2020-10-28FILE_GOWMMV2.docdoc d3e4041b0325e0794fe6a1b0a78783b8c05b595f0631c24d7d8e11c53fa5e8e4n/aHeodo
2020-10-28DOC_PO_10282020EX.docdoc f3caca68ae462481d5bac777996fa838a0dce95c7eb782713404fa5e3712a2abn/aHeodo
2020-10-28FILE_47629382.docdoc c3e8b7bf6e9c96cf2335ab8c491d537cf81a2c322e9b305fd0545d051c613a83n/aHeodo
2020-10-28UNTITLED_198822140851.docdoc cf6945d684eb6962274cca88159c3f88a0a5291a81ac0d8831d9f6496b005c33Virustotal results 27.78%Heodo
2020-10-2825844038101891.docdoc 384f0ac6af41ed895424d29854b510286d7b1c075150dbd313f8682f26eb4249n/aHeodo
2020-10-28arc_YLB29NE87PB.docdoc 43159cae0059060554e0c283a577d48c0b825e44856b3afcf24ac2f6ef831334Virustotal results 28.30%Heodo
2020-10-28WI4592506571PZ.docdoc 5e692d0f6341638d540a0dd0458062a4852cdc65dd6551956aaa28c4d417416an/aHeodo
2020-10-28DAT_TL3461940353TE.docdoc 42437dded751c17d78164701713e5a181726b5fa47472556a1eaede5aac86c17n/aHeodo