URLhaus Database

You are currently viewing the URLhaus database entry for http://alizarei.ir/test/dFFcZPQWhw5Hb8A7gucgNoUgYgSVAIMZQCYekzqvV6VMSUyI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:938831
URL: http://alizarei.ir/test/dFFcZPQWhw5Hb8A7gucgNoUgYgSVAIMZQCYekzqvV6VMSUyI/
URL Status:Offline
Host: alizarei.ir
Date added:2020-12-22 17:02:03 UTC
Last online:2020-12-30 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-22 17:06:25 UTC to abuse{at}parsonline[dot]net)
Takedown time:7 days, 14 hours, 50 minutes Bad (down since 2020-12-30 07:57:24 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-23E99O4GC1HE.docdoc 768f3c029cc79ae21d7c732487da93f0e8c7d19a83737f9ce7e107e3adc9054cVirustotal results 43.55%Heodo
2020-12-23OVI8RO.docdoc 66e2a898e0b029a13f3091ffd91aa453888cf996011f8ecaf3b4a4439b68d413n/aHeodo
2020-12-232R604MII.docdoc 6ed5539e92f43fcde23dc6343c4f41a93050576180fad637adc5014a49ed38aan/aHeodo
2020-12-230P5HOTWB9050XSHT.docdoc 3e9a6799e7ba70727573d5d792394849b0d94f95a6d0d51e46c3a3340314f764Virustotal results 41.94%Heodo
2020-12-23VXGLNMVQ.docdoc 53607b62fc227216a0de7e569922ef170b8d25443b8839f2a77717fddeb43e38n/aHeodo
2020-12-23PGE5VI2IEH.docdoc 94d804683ab1c9195ece193461e872d75b4835c2ee0fc73886dcca02a89463edn/aHeodo
2020-12-23EPZNQMLBMD.docdoc 8aac323bb90b4aa43f663e31e58a2973cf36b32fc5acfeec8d40fca09a50a7b5n/aHeodo
2020-12-23L0YIIU.docdoc 395efc9f98f81ccdcbfe6f9bffdd0e0ea5a2611e4542e43f1241c649713bf46dn/aHeodo
2020-12-23RS71M3GW9NW1UY4D.docdoc 08907511869c01824c3fa593161c3d71a507c9a403faefdb197811e3adaa4f8dn/aHeodo
2020-12-2366NNCM.docdoc 036504550e6290a5bd9b8c67b1e7c22de77c5034c8b51865ebe1c1f8d4d339b0n/aHeodo
2020-12-2332OBI6ZDWECMUDU.docdoc e9df17a69800a02dc5484a6fc60d1e9f19f7059ed8f0ef9c7847beecc39968a3Virustotal results 26.98%Heodo
2020-12-23NA9C63EYUNU6.docdoc 0149c806df64185dc66ee1fdc857e25ee93def1f7db847487674959d2b9306d1n/aHeodo
2020-12-23DGJ6STYS8.docdoc 9bba6813a6a0d038afc8a8bf8cd4e5beb879a954b0789d4d4e02cbd54d5c3795n/aHeodo
2020-12-23FYTZVK753OWMGWE1.docdoc 8f1c045c52f380a3dee934291859c8a03f17ef3f96084c3819678fe14f22c0c1n/aHeodo
2020-12-232YUW1C0LL6MXBG.docdoc 49f4475b4c4b63927d612bfcfc707d4a25237813c727333fbcb42fec441757dcn/aHeodo
2020-12-236GC51N4N.docdoc 59beb0cb64d142274d978c425b55fc8a7e7053f2f8840c09b9d751e56cd6f7d6n/aHeodo
2020-12-23PZPRMURITIEKDE.docdoc d5231db757615d38ce982ea1272ef281efc93dc8105418c890e8f9e59d76ef0dn/aHeodo
2020-12-237IRNT3Y123G7.docdoc 49b57af908f1e6a1383dd5b05ff24cc5208663b87a405e1e35828689f7c9cdd3Virustotal results 22.22%Heodo
2020-12-23D5IR0BPE20KQ.docdoc a8a5d52ccfe6f7bcc1ef7c99087ec90083ea7e3851e760b0653bd4189d54bc9en/aHeodo
2020-12-23LC3NNC8NJ.docdoc 1b1cb32d2f4a43f7bd1699dd46b55f8deed32e31065c9f13c69f2610b96d41c6n/aHeodo
2020-12-23JLVYIKHZVROF242.docdoc 56355a08b488d103b9a4d6226e1cf2cac8bfdc7381febb47feec6b0eff3ac332Virustotal results 41.27%Heodo
2020-12-237BD8VI.docdoc 4a6d02a3adc59903ee067a5abc702d78fb31c61deb56b7360fade2ec85195569n/aHeodo
2020-12-2360KTYGYF02ZEJX6A.docdoc 93901d975d0df11ab32c4eaf841b43684882ce002e1222696c629076b1b81792Virustotal results 41.94%Heodo
2020-12-23XCBO5WI580O0UR.docdoc 70cd2d38d41ecad15addac25c6e09641cce2f946161ecf261e639a09576ecb8bn/aHeodo
2020-12-23T1OX4K6N9.docdoc b534c439ac7a89c6af82331ebd70e5b5ce5e13a2e871bb7ab122b00004605e97n/aHeodo
2020-12-23VJBFB8KBG4N14PF7.docdoc fd76c945ff05629b1e31b55378f97c543c8dce7496389385dae3fd4b8acfd12dVirustotal results 31.75%Heodo
2020-12-23KQS3561647MGFPMV.docdoc 68e9fac6a7996f04c150777aec9f02864a62b4c0d59675625c1801a231461a0bVirustotal results 34.92%Heodo
2020-12-23YD6KUMHY9LO.docdoc 810ffc95c449b426c6bfc03c98c5e10cfbecbfff7858f10cd9c1c5ec29e2216en/aHeodo
2020-12-2368B3AA5GA.docdoc e9c79c389f9e0132834f2da34cf19158e44330446302146e5636b0516d65ed51n/aHeodo
2020-12-2394DN5JLMV9LD57FS.docdoc ef1b1013a1aee1aea1889ea4f3f736bac21dca5f8d940f13dbd2c332a8c8ac69Virustotal results 30.16%Heodo
2020-12-23DJM6ZX.docdoc 4640454cfd6ef0ed4ed3784c186840f5eae9bb870b37064a6f5ee53f245c325an/aHeodo
2020-12-230HFS6X8RE.docdoc e56e47b889fb43e8b9f183ee7abca3a349cede2826008e189de20df4b7bb481cn/aHeodo
2020-12-238WZTPX42ANI1H.docdoc 9c7952a624d186c2b830ab71d66e1e4369b998c0cfbf98bbc7530f5369530000n/aHeodo
2020-12-23Y3J83LJTBBZ5T9Z.docdoc 1f5a0f7a62383b576ac6f661f97a2c035e72d6f054e5b63ea53123ed9081dae6n/aHeodo
2020-12-2360WZT61.docdoc 31f327ab8307786ee50af20aaf5c4c2b6ecc974b69a584c78a2dce04fe5d327en/aHeodo
2020-12-23M3PNA5VF.docdoc c693baac5d3227d362a0fe99ad187c18cde1f45a404c94c881d424023303a744Virustotal results 27.42%Heodo
2020-12-23ER8TTF4JXSVCZU.docdoc 9d2ad424f8d1a39e1cf83b8d64131bc94d8b8ecf787b626e1118e348fc967f10Virustotal results 25.40%Heodo
2020-12-23SL34SALQIMTM.docdoc 64e04bddf27b3d535ea895f4dc08267a98a4c401edadc68e3caf7f6f850c4f64Virustotal results 25.40%Heodo
2020-12-22EKB30SB1H11ZT87.docdoc 000b049debe1595e96d46d2cb910795e269d9d3f1b3210bfa45901356b3b3b3aVirustotal results 25.81%Heodo
2020-12-22HKTESZO1Q1U8M.docdoc 80565ed0ada236540991976a90ebc0b137d35995ba34993db276fd2808832950n/aHeodo
2020-12-22OZ48E2SN0NZXB3JD.docdoc 05c57f48c8b1958bf16f64a292f9aa05a43f6185d02c54a0d8cf03b2fbc56ab5Virustotal results 25.40%Heodo
2020-12-226COQBTGVP.docdoc bdfab9675a34c6da34487f2c70f297960002e6c3c2a8e6fdc60ae7edbe67101en/aHeodo
2020-12-22NFIBZN8.docdoc e2e85f53c26daaa6cc7e1fe602e51f272ac256cc0c23725350d37b4a5a888520Virustotal results 19.35%Heodo
2020-12-2202I2JGRM6EC.docdoc 3a7e77468332deeec16a5228c4b955efb118e0b0d576e638a7a71ac7be04a5fcVirustotal results 20.97%Heodo
2020-12-22PIEA2LWNH715B.docdoc 29d2dd0591e75e000a0c6b8b889a9a1cafe79ce1f5b6a3468d55e31d7a820490Virustotal results 20.63%Heodo
2020-12-22GWPUCZTMHRBAZTL8.docdoc 77b8248db026c5f3e993c6791b25c26813cacf0f6d1f9daa56d1f570b324bdcfn/aHeodo
2020-12-22FH9D01B.docdoc 672fd53363516e84ed426b99e3465bc33a40e08ecad177bad2c69349b92c7828n/aHeodo
2020-12-229AYDBAEQ2CGA.docdoc f7c7d960892c6eceda47d8b21609311323d84eee43e2d6fe065c9c770204941bn/aHeodo
2020-12-221E9H2CS1GCYXS.docdoc 1d5cf0fff53e0485bae46b34b71fc4b886376d458e91b8eb88a04296f36f9aadn/aHeodo
2020-12-22CRVOSAOTC.docdoc 755b0648467884ea407cb2be70ee59bdff597edec6e149816e553134e25aaf54n/aHeodo
2020-12-2221SBEHQKFIN1.docdoc 628715602170e6fa97dadd0ea965652619994ef5eadd84bda8c45db0db3ef0f3Virustotal results 18.33%Heodo
2020-12-22X3A6A6R5FPMF1.docdoc a5bdf83f7a7007f23b721bd73c5219830d2685673835bcb9a2af37e47ad2603dn/aHeodo
2020-12-22R13QS9.docdoc c56452bc0ff9abfcda3df47210eba4e178e55a49d0673f42c9d192ce0234ca64Virustotal results 19.05%Heodo
2020-12-22SYUF5IG5B6XHX8BS.docdoc 636b5138fc52da9fd4cc02ade2b4dc4986baf4b8614fec61d464e4a55f8e7e22n/aHeodo
2020-12-22XXSOAJ6.docdoc 7bf5d728fcd19d3df1127a4d8648cd870c5d123ce9ea4b10eca54cbcd18e10afn/aHeodo
2020-12-22TNV0HW.docdoc c9167679e64cc007f5f7c42c046c9a36b51f62709a3e5b5350fed1fb8ce7dae9Virustotal results 42.86%Heodo