URLhaus Database

You are currently viewing the URLhaus database entry for https://marginatea.com/wp-content/upgrade/93t/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:257877
URL: https://marginatea.com/wp-content/upgrade/93t/
URL Status:Offline
Host: marginatea.com
Date added:2019-11-25 09:51:03 UTC
Last online:2019-11-26 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2019-11-25 09:52:10 UTC to abuse{at}mochahost[dot]com)
Takedown time:1 day, 6 hours, 0 minutes Poor (down since 2019-11-26 15:52:30 UTC)
Tags:emotet link epoch2 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2019-11-26g1Dj9g0LgwF.exeexe 3ca24b93494bb37287fe07f4a6fd2301a2196f2ca95fcd1ee873d04db8c6f0bdVirustotal results 22.06% Heodo
2019-11-26ssWKkGIQwiiJ.exeexe 0efe94c34bdfec7472ab76cfbf4cfa0a7b0fe792e6a683aefe99bd4042dcf47eVirustotal results 11.76% Heodo
2019-11-26EHTW.exeexe cfe438c4a7700a3fb3ae9bbe03e0ba86bc65273b9bcda34a8ba298c69527801fVirustotal results 14.49% Heodo
2019-11-2626AEqZNnQttki6U6P.exeexe 27d39ef5e11b297900011bddf56a27369c28e26a433f417dd2d83c63a4a024b7n/a Heodo
2019-11-26OBCyrodDAUXvCt4E.exeexe b7b02be11906120cee18404ac0e474f05406b868a19546069fd935c9164a233an/a Heodo
2019-11-26dhv.exeexe 9a8e9fbfcf788fe12c03b3c86fbdcb2d6b9e344622bc32e4651a05d7d155caadVirustotal results 8.82% Heodo
2019-11-266qPv4nsl7P.exeexe 2bd362b1b1d40dca063a8724598af78d6e5483a99519e48ba7a3b39391acd969Virustotal results 29.41% 
2019-11-26USM0h.exeexe 31ac968a569582d1668c913689db98e5022f41e248371dbc4363e196361ac89dn/a 
2019-11-26bniqoPOPqd9LuM.exeexe 7f39464941fea0aaabaf984b6e4714be0a248fe23f1c7454c9caf4f4112e7728Virustotal results 20.29% 
2019-11-267JN1H1Q.exeexe e5db961594d193cb515f5e9538c7843c44fcd8cf80dc2e47d8c663af14f288a1n/a 
2019-11-25avohIa.exeexe 7013664f5297df77c2f0af1b9c9feb309eb406370b8278658cca7fdd43a3912en/a Heodo
2019-11-25V7y1iPf7NDO7BLQdmrW.exeexe 9d5d19879955b1f8040f5dc5e3f4480bf454368dd8e98099a720be2948b53902n/a Heodo
2019-11-25GLE30Ap6.exeexe ae942ac0df226afd76361d0e76fcc02b5c9ea54bfdbe42100ecb6f47968d2b2dVirustotal results 22.86% Heodo
2019-11-25aOXWV8cyF6.exeexe dfeb8fa5a5eff0a2e48db2e62088ebc75624bd83fef7efb15ccb4bc7ac02bbc9n/a Heodo
2019-11-25ck1GyZ4S.exeexe 25ca902b6f9552b80c0457962d01490cb362c16ebc2b1933939d34b1ae2c95adn/a Heodo
2019-11-25oQldjvK8SsCVCV.exeexe 4f99d88505910dbb6af6f4ecfcd810cf4dae7340a1356b53c139cc63f531c683n/a Heodo
2019-11-2529.exeexe e82ae799e874dd634baa1a6118269cab69d0f86f7c90667bf7b742cc6548d60dn/a Heodo
2019-11-25DAzqZlNH4oI.exeexe a82ea53528dd916b60591719cd04a5d1be763178f703468cadea25bdd7ee0da3n/a Heodo
2019-11-25FQD9UcBDjqaaPEslo7.exeexe 912fc43e9476524739f219e5332933a41a5f8e1377080e0656defbdfed973d84n/a 
2019-11-25BRTDMlMhH4uBrs39EgL.exeexe ea430ac7466adc4d1237c7c71dc3ade0744aa882b90be69c46d45e2a618e7aa2Virustotal results 11.76% 
2019-11-25ey20.exeexe 0a4f3d0cc6c83032ed394ceb8e15b6bea38e8c61301a5097f4d9a60d02c07671n/a Heodo
2019-11-25vLtDSB4HTLOs1x.exeexe 2368878b707f172651e079acb9ceab7a2a524a28b6f071874e8d787b86d53146Virustotal results 14.71% Heodo