URLhaus Database

You are currently viewing the URLhaus database entry for https://behtarinbime.com/cgi-bin/e8tmBlPrv9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:764660
URL: https://behtarinbime.com/cgi-bin/e8tmBlPrv9/
URL Status:Offline
Host: behtarinbime.com
Date added:2020-10-29 10:06:05 UTC
Last online:2020-10-29 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-29 10:08:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:4 hours, 32 minutes Good (down since 2020-10-29 14:40:46 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-29Attachment_16877720.docdoc 29808c9db3a80e9ed46d4aecbe478dd8e57089d7e2977c916421cba71b0d6c42n/aHeodo
2020-10-29inf_PO_10292020EX.docdoc 5db58ed4308eeb76f9c66c885d4f1b53530d6c42eac9d755e67bf41989094087n/a Heodo
2020-10-29DAT_PO_10292020EX.docdoc 02ded378bb9171cb19579495299062441281f67002a8f88beaee43c2dbdd94b4n/aHeodo
2020-10-29FILE_76580712.docdoc d7edab7749baa696b995be184437050a249c40992deb7cbd3472cf93fd8a154fn/aHeodo
2020-10-29FILE_BC0616978165ZM.docdoc 93ef9ecf091dd0a2f463f8b10a73d301ad965547315b43fcd5c1a4995c513525Virustotal results 20.31%Heodo
2020-10-29X_08684658.docdoc 8b4afb8076a68f93b44032c82700252f8971b853903b31fd0eaf50671f7c3cd7Virustotal results 20.31%Heodo
2020-10-29arc_18803818.docdoc b3fa2642d482abe33fb06c5480db8883954bb076b663c838f67dc4966b89f71dn/aHeodo
2020-10-29I_160801963497355205.docdoc 3a1dd7ec119b96ea68facb223082a398ff4c038e58e7d166c80d7a7d4a3758abVirustotal results 20.97%Heodo
2020-10-29File_OK7944634909RU.docdoc 2427ee3cc0798fcee02c718a1fb58d735d9cf3b0ebd9bb10c14cb9326bb5e489Virustotal results 20.31%Heodo
2020-10-29ARC_21433302.docdoc 371a442d56b47bd24ec601a710beb116a75f09be269d0a2e18b29d6fe0927bc1n/aHeodo
2020-10-29Untitled_ADH3G8OOMODQ6RU.docdoc a943a1b78c2ddb8ea536ad08b2eaaec624c324079322f272f1e1a319b5603a28n/aHeodo