URLhaus Database

You are currently viewing the URLhaus database entry for https://marginatea.com/wp-content/plugins/coming-soon/zka04522/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:255248
URL: https://marginatea.com/wp-content/plugins/coming-soon/zka04522/
URL Status:Offline
Host: marginatea.com
Date added:2019-11-18 22:29:40 UTC
Last online:2019-11-20 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-18 22:30:11 UTC to abuse{at}mochahost[dot]com)
Takedown time:1 day, 15 hours, 19 minutes Poor (down since 2019-11-20 13:49:31 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-20mfhh1w54m8pw.exeexe 3cff0dabe2415f9eed5a1737d28e0fa5929d83471d7a60c4577f6031d924b5f4n/a Heodo
2019-11-2063kpgck.exeexe 7b270987232a95869d2b35dcd1ab60fd690747ee67d7605b9b5625c41f0aaf10n/a Heodo
2019-11-20qj2m7b.exeexe 2b5be25a78f9ee3f629a70e7440ad33985260a85dae5059fde686bd5e674669bn/a Heodo
2019-11-202720gykrtsit6.exeexe b8c3d412e6a55412a69496c48a2615ae3b578ab7fc45829c52f46b8765d8f384Virustotal results 12.86% Heodo
2019-11-20brkaudkawf.exeexe 24b14dd51b4acc4f14882283452b825be30fe52ad879a8156278e2a8092c3736n/a 
2019-11-20strwb26849oeh1.exeexe 1ffe40031ede5a6dd14734e7facd5833137f0c9a0ed893c0259007a457f09334Virustotal results 12.86% 
2019-11-20th59igcv.exeexe a0920c07f30238ec8f626d831a0dca0c80b4a6c7bcf9f98f268574762614cb59Virustotal results 12.86% Heodo
2019-11-2078bozbh9i0sc.exeexe e357af2db4c516835b08c04d62e1b5b8cd82ddf222bdfa0603792233d040df70Virustotal results 14.93% Heodo
2019-11-208zjdp6kjgekh.exeexe 4fd5a522be66c449da98a1c608a3f2c91ffe7d2fcc129f0e7e708bade2190072n/a Heodo
2019-11-205o09hk.exeexe a1b58f64b1382ba1599a548ba633d8a3c9357ec5244b850c9842a57cfb64ecdfVirustotal results 12.68% Heodo
2019-11-20t6sr81kcs.exeexe 9a7118076f73908c67e19edd6ab842446127687d57e56c10359e4d16cfb06aa6n/a Heodo
2019-11-197iveaooblr1wf.exeexe e7cab728e16f4372d4b9ac3c6482d66a8907a3df64e556e15aed9d7970881e73n/a Heodo
2019-11-199ncxy.exeexe 1bdf5f641ed0c1e88adef54c2a086e0ad279f7ab5d700b1d5a6caccc80f8aae2Virustotal results 10.14% Heodo
2019-11-19zg7nhgrny2o3g3.exeexe 6ba7e6f5ca2359c650ddd0d9d1f902d05b9cd62965bb5af744c9bcc90871fb6bVirustotal results 14.49% Heodo
2019-11-19sbsz6jkdv6jum.exeexe 94d52698b61914055275c49de0cc35db6bd3509a07766e4e63408611d8479891n/a Heodo
2019-11-199a7y8bg.exeexe 007430ece83c4492f9d2c67a7f175173258e079b5087b663fca10671a8ac6530Virustotal results 15.71% Heodo
2019-11-19om2b3wxasixalmu.exeexe 1b596b9e8a2d973d6e26de47777a2d03364c4ffaf8bc33c7934c1c0b514b17f7Virustotal results 14.29% Heodo
2019-11-19yle69bxu9u7p0m3.exeexe fa1024757d4358c002ad7c79c2d0357df6d5e32c4d972061a2bc8762d57bf173Virustotal results 13.04% Heodo
2019-11-194gfe8cvg.exeexe e3ace1b226a34cb0fca21878c44bc469e0ee9c021bda912af09fc9c1c59546a1n/a Heodo
2019-11-19skhf4qp4wfu4gx.exeexe 6bb5bc98b0cbefd3423cc0b425d57121a7b940dd287826be5334620f2498c5d0n/a Heodo
2019-11-19tu1taj90wgk8f.exeexe f061b0603a470a31b1166d596f97d0a592619a4e76f04e7753b7d5d00b9062den/a Heodo
2019-11-195d60izdase.exeexe dc832288557dd5c098d60bcf4cc2e0e5cd4232dc951028e4b2bec00f90a31382n/a Heodo
2019-11-19kko9l5snl.exeexe a925e4c3d68666328d1491518cc90bc8bf6da719b8aaf722e0ab717ff08858a8n/a Heodo
2019-11-19rmp8dh.exeexe 2294fe779843173b5d30ac5530dca07c3c8968a3176b0a7096fe35259e660177n/a Heodo
2019-11-19r3h51rtpf.exeexe 85f120e2f354dc15cca457acd4f794b057cff99eaf70192c95f8d28422922c0eVirustotal results 17.39% Heodo
2019-11-19vyu9jh2s1.exeexe 6933aedbed8ae3b420c764237cd65b3c235f12574b5d03dfc49ed99d0867bffcn/a Heodo
2019-11-19bb5p3ao0nlx.exeexe 1bc6da2dfa926b3bd2d0febd7e2df63bf00cc1d79e7c9c28b685a7db26b2d30dVirustotal results 15.49% Heodo
2019-11-19pcu9ykyhhg.exeexe 6f645602875b6159d0c6b34e2467022197e2ba531656e2dc6075474e842a1809Virustotal results 18.31% Heodo
2019-11-19kwj9nkr2vn.exeexe 0edab19fef4e79b890c83ad217df753426db550989e9dc7d3ca737b22f5fc266n/a Heodo
2019-11-180rhuar.exeexe 52e80d23edec3a0102635499e9f63963ab266dbbcee78b2e2913f0551b488c25n/a Heodo
2019-11-18dos7clw7.exeexe cbe327c74cde9cc116582b308dfd1f31cb99de1257d311a8b098e171a13167ccn/a 
2019-11-18ipzklxh.exeexe 6626782fc2c6a9aae8e90f5e4e99cefe94e2f016e8b9de657c8e56e38e592272n/a