URLhaus Database

You are currently viewing the URLhaus database entry for http://betacenter.ir/wp-admin/MYEFYnAOvgMdmh1GH1wGvrhfcMtYmobFWgRzro6Sibtqv8ennxAxcYiBEdBfjYuq33Lq/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:762968
URL: http://betacenter.ir/wp-admin/MYEFYnAOvgMdmh1GH1wGvrhfcMtYmobFWgRzro6Sibtqv8ennxAxcYiBEdBfjYuq33Lq/
URL Status:Offline
Host: betacenter.ir
Date added:2020-10-29 00:12:09 UTC
Last online:2020-11-02 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 00:14:25 UTC to abuse{at}parsonline[dot]net)
Takedown time:4 days, 18 hours, 52 minutes Bad (down since 2020-11-02 19:06:34 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-30L_6091084782133563.docdoc 023fdae311195c64889d2c87831a470d7c4826a755cd385729dc6bb02281c4e5Virustotal results 53.12%Heodo
2020-10-29Doc_PO_10292020EX.docdoc 4b6b29d5c14a6ed0524d46202796bf0f9bd18650fa3f44dc5d01e1ab93652600n/aHeodo
2020-10-29DOC_32119605.docdoc 915d8c2a128f74e323ef7a2045f9ab90f17d3747f3ed2c090fd247f7f9f88fcaVirustotal results 38.10%Heodo
2020-10-29FILE_19964380.docdoc 4bfdf04e63422e1f2b89b19ccdd74439826ca27342cac0f98e259109043cb251Virustotal results 38.10%Heodo
2020-10-29arc_PO_10292020EX.docdoc d1235f6f23271030ac07ac42abbe55dc13515c9fb8586418eb81a72055ffb2beVirustotal results 39.34%Heodo
2020-10-29DOC_JP0827599714KE.docdoc 393cb1523cfa3f9dc1d2a45e467810be8447ea0f58435edf5bfd1e0938e293e0Virustotal results 38.10%Heodo
2020-10-29list_093043906719457.docdoc 384a86ce03971610e03d72c4c46dd311c1719b3264e1f8724c6314a5f724b5ccn/aHeodo
2020-10-29mes_PO_10292020EX.docdoc 22f759f5ae2843757236454a0578edfd716dcc446d3b1db698bb404fc0277fa5Virustotal results 39.34%Heodo
2020-10-29FILE_YQ5004562692JH.docdoc c353f3d728d9ff052a3ee47d7dd1c5e8bcd8813238a8e20f2f2d0a97fe5bd8e0n/aHeodo
2020-10-29PO_10292020EX.docdoc 46e6c0f62d299a4510ce400f90d5f8e2280b0ffa5e465ce7433624327bc07c0bVirustotal results 36.51%Heodo
2020-10-29doc_WB3LSKS6.docdoc 56b4b239b93d5528e7f80a5bddef47bcbe22a9318d3abf88be53dbb4aedd66cen/aHeodo
2020-10-29Untitled_53750477520146204453.docdoc 2a7fa7333c9651955476107db7c4fabaa333b34c5c6938bfad143ae443d94dd7Virustotal results 35.48%Heodo