URLhaus Database

You are currently viewing the URLhaus database entry for https://dz.martinface.com/uc_client/available_array/m2b5ak5gnfnqu_6gp65uv1s299_portal/gzcnvnz3by_z702s8x/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:415261
URL: https://dz.martinface.com/uc_client/available_array/m2b5ak5gnfnqu_6gp65uv1s299_portal/gzcnvnz3by_z702s8x/
URL Status:Offline
Host: dz.martinface.com
Date added:2020-07-20 14:34:12 UTC
Last online:2020-07-21 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-20 14:36:02 UTC to ipas{at}cnnic[dot]cn)
Takedown time:11 hours, 56 minutes Good (down since 2020-07-21 02:32:39 UTC)
Tags:doc emotet link epoch1 heodo link ZLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-21arc_20200721_MWP756930.docmdoc 1236dd4116a2c4ba4427175d0a3e88c848f70dc6219f6b22f1997ae3ba80ba14Virustotal results 31.67% 
2020-07-21Arc_V8878.rtfdoc ead83fc91ca4d61d49957be440350122ea7f083e14b61eef430b9d7c5eb3f9a2Virustotal results 31.15% Heodo
2020-07-21rep_20200721_LVD1669.docdoc 49b857e2068f710d1facd444264c6d8804ecc9e2ba9660953b24bbf213cc66baVirustotal results 29.03% Heodo
2020-07-21List_Y071.docdoc 33e64096db5340fb26c5b5d6f9b1dd89674d3a77a96a25fafcb878d9929fc9daVirustotal results 31.15% Heodo
2020-07-21Dat_20200721_QJ237963.docmdoc 99c6c8f02c2fef792bc8a5a6406b0baa294156cb38b8df191f98cfb5a90547f5Virustotal results 30.51% 
2020-07-21LIST-2020_07_21-Y52591.docmdoc cce8e5e706869261ede523822b673dd52e48d4351de8600f5ac209a7f0189629Virustotal results 29.03%Heodo
2020-07-20MES_856.rtfdoc 0d657d365282571dcf58adbb3a758c81fa3df50bc081a60d01f14c5431b9492eVirustotal results 29.03% 
2020-07-20arc 20200721 16028.rtfdoc 518def77204a86e55289809beda7c491b0f9ab290b10d7b4bae1c670a0f69c8dVirustotal results 29.51% Heodo
2020-07-20INF-7423351.rtfdoc 68f85e639cf07fc84c8204cec1bd82fd8985d854aa17d02c89b58b255b98ed48Virustotal results 29.51% 
2020-07-20INF_2020_07_21_0715.rtfdoc 107cf68ace70917126432b415c7a9b4a18e3f87c304c1ea780b1fe0950167c29Virustotal results 29.51% 
2020-07-20arc_20200721.docmdoc 44c487bb620fcaf9ecd88961303e24f705390f3c23b0154b738fd30873832c0eVirustotal results 29.51% 
2020-07-20Mes_2020_07_21_9732243.rtfdoc 41d61ed5ec94c9f81d804487ad8f6132520d6ac7009a8c9a7b0c074ed0748e4eVirustotal results 29.03% Heodo
2020-07-20Doc 2820.docdoc 1269bdbbc40be92cc1f13918a692b34fdfeec466bd7d872863ecc405ff38f77fVirustotal results 27.42% ZLoader
2020-07-20Rep 20200721 1990.rtfdoc 9d397f040fb1768faae4189e4e3e0aa60604b2b86617d979e1f61d90a8798fbbVirustotal results 27.87%Heodo
2020-07-20REP-2020_07_21-FR56333.docmdoc c6050ddd07c6d8c4aee73c52d0e50d6056ebd5f3e82550d8c771fc4353d489feVirustotal results 28.81% 
2020-07-20Arc_20200721_POU347603.docdoc eccf2d10cb44fb11136e2edaf7af5de351637d1479888142221354abf8986760Virustotal results 27.42% 
2020-07-20inf-20200721-6480894.docmdoc ec87e9999c894cdef59c964d06c6de6c7a7134d373b4e754180d90dd5fb23f64Virustotal results 27.87% 
2020-07-20List 2020_07_21 WOI076333.docdoc 5abab6688536c512612b7393fad366109bf1e80149a7d2f03d959f7addc85155Virustotal results 27.87% ZLoader
2020-07-20list-4245.docmdoc 3a26f638eddb01e30b8a712291a03088645dd9d2986cbe415bc1b87cd8eb70acVirustotal results 27.42% Heodo
2020-07-20Dat_493.docmdoc 08f5ec28ca3c972a6d03a47225475ddf5930decbb10ca8de63dfe0544581ce14Virustotal results 27.42% ZLoader
2020-07-20file-2020_07_20-F8845.rtfdoc dc9d3da24212096b6029163166558cefcd8b37aae588dd461d9b5c02700700afVirustotal results 27.42% 
2020-07-20file-2020_07_20-601495.docmdoc aebb6c605f43479215ae38d93b7e2d6edc07769fa39cd79450d94a3fc2a50bb1Virustotal results 28.81% 
2020-07-20LIST-TAS4216.docmdoc 97e66ad16955f21f83dae53917dbdefba08fc07108392a96327eeef55698a04cVirustotal results 27.42% 
2020-07-20mes.docmdoc 6b5e8002c323071f83df953f977caf3a477d1a0c7178e0795674d263bc2dab15Virustotal results 27.87% 
2020-07-20Arc 2020_07_20 6599.rtfdoc ed29b479d20901bb285c8146d9a69a73a34eadaa4f6c86aca69aeefe96f4fe0fVirustotal results 27.42% 
2020-07-20List_20200720_OA4529.docdoc cbe8fa6812edba1a4e2b1fe7c30f6cbf05f21e5935e95ecbdda6d3f5d3b6de9eVirustotal results 27.42% 
2020-07-20File_4797246.docdoc 36a8c92bf1e17c731797dffede2d91ede145d83d3328bac42e2b046f296abf77Virustotal results 25.81% 
2020-07-20doc-20200720-763.docdoc d560fc37f131e03b741770ee4f23d889ba5d3bdedf3ec68efbcc8bd470e0d8edVirustotal results 25.81% 
2020-07-20Mes 20200720 UM8199.docdoc 8005b9ca1985b623968849a6db53eaa3dfa9e3a93ac623e439235d133d2042bcVirustotal results 25.81% Heodo
2020-07-20FILE-CBD66184.docmdoc 2ed0a17884d80b91110cc117b3963361ae603c91ce2cd60de6131972d6a047b1n/a Heodo
2020-07-20LIST_20200720_H7381.rtfdoc 4fe945b83567f1855dbc8ea4f8e0e0e2258117238ca2184dd10ba6cf797377a7Virustotal results 25.81% 
2020-07-20file-2020_07_20-3698895.rtfdoc 31adf970450cb8a76809bff658f19a6e62c31894dee3957e3374752544f042d3Virustotal results 25.81% ZLoader
2020-07-20rep_2020_07_20_II7619.docdoc 50907e00e7354e5037629c8a107f608e8eb29d24e78687d31e055e89ff4e9411Virustotal results 25.81% 
2020-07-20MES-20200720-EY282.docmdoc 9a5b99fb5558fc141343ebdcd0429d151840f7a5b8978f2a6584127455562d92Virustotal results 25.00% Heodo
2020-07-20rep-2020_07_20-PNG93556.docmdoc 27e86fa1d58f503821260db0fd9caf987e41fc1a7595ade7d3e9a7a6f7058ffbVirustotal results 24.59% 
2020-07-20Rep 2020_07_20.rtfdoc 5ddca7e14995275b692b30e3a111d3f9c3be92247d826cfdc9dd64394ee98ac9Virustotal results 24.59% Heodo
2020-07-20file-W984.rtfdoc 0d11a9ada31fc5442e6fd95bb8c653ee496cb2b12922933383296efe319185e3Virustotal results 24.59% Heodo
2020-07-20Inf 2020_07_20 086.docdoc 832b91234d64a43383ec26a920d563fb0dda9d01fd4eadf921b788dbfe60c8f4n/a Heodo
2020-07-20Inf-2020_07_20-918279.docmdoc 7c61c2eb287a285f8a1d86aea750d83d26b19682bfaef685835d0722f219cc6cVirustotal results 25.00% 
2020-07-20Inf_2020_07_20.rtfdoc da8a9079a2ecaaf3eafa33ae0eadf2359975ce5b650921ebf15249c7fad07bbeVirustotal results 24.59%Heodo
2020-07-20arc_2020_07_20_Z9731.docmdoc 4d2a05f2d82b15cf0f0b86c50a4fa08f165b111aa03ce72d523695db2ace926cn/a 
2020-07-20arc_20200720_291.docmdoc c940abd4ccf7201c6709aaa6ca888e4c501d94e70c3c53c995c8ca4616c4efa3n/a