URLhaus Database

You are currently viewing the URLhaus database entry for https://betacenter.ir/wp-admin/MYEFYnAOvgMdmh1GH1wGvrhfcMtYmobFWgRzro6Sibtqv8ennxAxcYiBEdBfjYuq33Lq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762103
URL: https://betacenter.ir/wp-admin/MYEFYnAOvgMdmh1GH1wGvrhfcMtYmobFWgRzro6Sibtqv8ennxAxcYiBEdBfjYuq33Lq/
URL Status:Offline
Host: betacenter.ir
Date added:2020-10-28 18:57:06 UTC
Last online:2020-11-02 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-28 18:58:08 UTC to abuse{at}parsonline[dot]net)
Takedown time:4 days, 23 hours, 59 minutes Bad (down since 2020-11-02 18:57:37 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30L_6091084782133563.docdoc 023fdae311195c64889d2c87831a470d7c4826a755cd385729dc6bb02281c4e5Virustotal results 53.12%Heodo
2020-10-29T_YUR_100120_ZGU_102920.docdoc 6df480c2f89e67bd88a1ef3142106f925a45830756da26077582ef439dd4c5b8n/aHeodo
2020-10-29doc_JDBQFQV.docdoc 4a64cdcef15cb3314d81486a5c6c1fc590e6579da756365b73c08c8adae77b95n/aHeodo
2020-10-29MES_08994454.docdoc e3a96d2e3adca1fc3dfea0ac14af9b1d4cec3a20d9d7c6874edf1c6fec60d90bVirustotal results 38.10%Heodo
2020-10-29PO_10292020EX.docdoc 4c8eeccd2a16f80874acd0057d5ec622d3701e32a3198bdb763f39e39ea28982Virustotal results 38.10%Heodo
2020-10-29Dat_CW3661471536IW.docdoc c848e58e6eda265a519b7b901623769948e5bba84d9d240638af3bb235587028n/aHeodo
2020-10-29FILE_SKC_100120_DKF_102920.docdoc b89f3ae4badac97fc44a153bfb215de77641bff4cbcbe7ddc321af38e097f2beVirustotal results 38.10%Heodo
2020-10-29Doc_QS2413214128WW.docdoc b97d2b5410d55c774746d336facb4fac9b81552a5f84073496d20901af3c5f71n/aHeodo
2020-10-29mes_PO_10292020EX.docdoc 22f759f5ae2843757236454a0578edfd716dcc446d3b1db698bb404fc0277fa5Virustotal results 39.34%Heodo
2020-10-29Z_PO_10292020EX.docdoc 16593eef39e8c04fdbb6390954522fcbb430e3d131921c0b5f4e9477ebd794f9n/aHeodo
2020-10-29PO_10292020EX.docdoc 46e6c0f62d299a4510ce400f90d5f8e2280b0ffa5e465ce7433624327bc07c0bn/aHeodo
2020-10-28HSVSTNDEXB.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 25.81%Heodo
2020-10-28Doc_WD4626994847NG.docdoc f22f6b796d73cadef21281fb4120d425395b7c6457e38524dde128830ccfc02dVirustotal results 25.40%Heodo
2020-10-28file_34202282.docdoc 8adec8b07c6dffa1c8019b0076e0ae870dbfa2a40941b64f4bdb96adff5e0b30Virustotal results 26.23%Heodo
2020-10-28file_64912875.docdoc fc6ba0089f3355775a62f986bcdebe3bf7d58d1934d524e952f9279bb82cce68n/aHeodo
2020-10-28rep_33807580.docdoc c79ff6d2cb77b1d4e7bc6bea1ea1b05d78d536e72254e93dbaeb1122ff214d8eVirustotal results 22.22%Heodo
2020-10-28rep_87307534.docdoc 7384af9684329dd3916fa070ae356428bfb6f43d3ca6aa725f92d696dea83f41n/aHeodo
2020-10-28E_59991661.docdoc c2d24878a478d12f42849ded89565fe77905f7af790b6a7272ece4fc9db45fe2Virustotal results 19.05%Heodo
2020-10-28Mes_PO_10282020EX.docdoc 5da940231b1ebc70e4c974d89da825e72365c081f4b224b0308a7298de66a788n/aHeodo