URLhaus Database

You are currently viewing the URLhaus database entry for http://markleonardimaging.com/blog/protected_sector/test_area/8cbyfv54bsrlkl8w_w8zy97/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422466
URL: http://markleonardimaging.com/blog/protected_sector/test_area/8cbyfv54bsrlkl8w_w8zy97/
URL Status:Offline
Host: markleonardimaging.com
Date added:2020-07-30 23:55:36 UTC
Last online:2020-08-06 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-30 23:56:04 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:6 days, 14 hours, 49 minutes Bad (down since 2020-08-06 14:45:25 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-01mes-2020_08_01-AT189.docdoc 92a8c9729a35ef4fbe97b8b931ac2ba3284ff4c1aaaab30eadbe36ad12c75465Virustotal results 47.46%Heodo
2020-07-31list_2020_08_01_K9597.docdoc 4fd05fbbaa5f5944ba99f31291ed14d6991f4084c7c5f7fceb29dc462b7e68faVirustotal results 47.54% Heodo
2020-07-31File_20200801_U01843.docdoc 32f54c3bd9b21015392a22754182187d5ee73a6175f94a247e66e3fc0728b700n/a Heodo
2020-07-31Dat-43091.docdoc 3d5427a07cdecdce3e2943473bf2a141a3eeff0e22919c7b1fe3378aed3d1590Virustotal results 48.33%Heodo
2020-07-31file FCB6091.docdoc c45bcf9a41075804172523238d905c314dea01aad3babafd32cfe0ef52b86260Virustotal results 45.76% Heodo
2020-07-31ARC-2020_08_01-541.docdoc 2f5edec4351fad5521646ffb86ecb8c584fc8da1f3b7852d1302cb8ec7fc696dVirustotal results 49.15% Heodo
2020-07-31inf-LPA543134.docdoc 09b591c165b3ecaa1fdc7b1afc9b6a2f9cd8a49b1e9936d7949a8ebd083163b3Virustotal results 47.54% Heodo
2020-07-31DAT.docdoc a17ff9ede2df1f54aad2ecc11a0cb2fd9ed65e8fd8e4f9b8e2bc68389d366154Virustotal results 47.54%Heodo
2020-07-31Doc L3990.docdoc fe41313ae7dcaf87736d8cfd069d8fda8577fcc2c9b406fe90caed2e64ab2d13Virustotal results 50.85% Heodo
2020-07-31REP 228.docdoc 6845b4264086309f419c423aa1d2d867b27a3d2139e9a348939bf6ad0620c4a0Virustotal results 47.54% Heodo
2020-07-31Dat 2020_07_31 Q45658.docdoc 7455acc02baf730eb4db6110424e796d22b98bd05ca4d2e883b309eabbaba8c4Virustotal results 47.54% Heodo
2020-07-31Dat 2020_07_31 253173.docdoc fbd0c49f5c2708ad67b9d66dc6d64eebc7ab9d234b2b79321393591d081dbdeaVirustotal results 46.67% Heodo
2020-07-31Dat 2020_07_31 253173.docdoc fbd0c49f5c2708ad67b9d66dc6d64eebc7ab9d234b2b79321393591d081dbdeaVirustotal results 46.67% Heodo
2020-07-31Inf-2020_07_31-AMA1621.docdoc c54a83ed7df0a40d62a865853af530ffc4372e2bf7255a43bd6e352ed5ec9868Virustotal results 47.54% Heodo
2020-07-31Mes_43901.docdoc 810d5899f085d1c3160e9a069dad7915609292c8666fe0e02c0438d997827753Virustotal results 46.67% Heodo
2020-07-31File_20200731_449374.docdoc 3807ea27c87ef220916b55deb372a2eab386ffd18028cfee853a34521e6fd377n/a Heodo
2020-07-31list.docdoc 4c6a9e9d068aaa2a313b10f83cb3f03ba7afdca5c5cf699fb7da411be652526aVirustotal results 46.77% Heodo
2020-07-31list-HEY29916.docdoc 6dca66df42bd8494a68b0844baf9a74e4bbd8da25633bca4914817f18657e009n/a Heodo
2020-07-31Mes-2020_07_31-V863.docdoc f9daf58283bfa44af378dcad38562399d3e8a6ed3117f97a4019941b8f6164baVirustotal results 46.67% Heodo
2020-07-31DAT-442.docdoc 4ded51da1c85dc6bb80665a8d1090d7df4948bccdc294956015e9e69a6156e70Virustotal results 42.37% Heodo
2020-07-31LIST_2020_07_31_BPP538.docdoc c5e1be1f3b4b0978b9a8d32d545c5d775db521592c4b0c41ee29dd6353cb0190n/a Heodo
2020-07-31Rep-20200731-BU5743.docdoc cd29071298cbab67d898b5cbcf4b56f1b7d725f85267037659bdd2da3083f57eVirustotal results 44.64% Heodo
2020-07-31rep_20200731.docdoc 72038c4d742717c91add32782d8128e5c7753b4cd7ef566bcc1d39aa0df0677eVirustotal results 42.37%Heodo
2020-07-31Inf_2020_07_31_7712.docdoc 596669e4ee62dd88d2ad8cd5b9f66d21a243874280e56566b6530cab61ed15b2Virustotal results 41.67% Heodo
2020-07-31DAT_20200731_NA2105.docdoc 56acb99a4ce942c9970dd5e96a8bdbd3e446b89c9c66e8876a9894c569afc259Virustotal results 45.00% Heodo
2020-07-31rep HUE1375.docdoc 4acec2a5ef0b6f549b39db572081188d4e2d9cc039f95a709c105b7aa3bddf7bVirustotal results 41.67% Heodo
2020-07-31Rep_196.docdoc cb6ac957d36fc72b75e45e7c90202b929041dd3d870a095ddae756a7f50180a5n/a Heodo
2020-07-31rep-2020_07_31-8947141.docdoc 5335d6881bf6a2b0776a89724043b6693dec8ffb4848b0c66954f6373c38cb20Virustotal results 40.68% Heodo
2020-07-31MES_8939.docdoc eedaaf67ad14a0213229367966ad1333e3f8085e1e6b83683d7fac0e3e16ae28Virustotal results 40.98% Heodo
2020-07-31Rep 2020_07_31 TA751.docdoc 925fb8974d3622ddd5df080f3bee888c2ce91a92d43cd6b685ee82c8108deab1Virustotal results 41.67% Heodo
2020-07-31INF.docdoc ce56b6b893ac522621d455933d57153c9ab60208780ab20bf1abfc87ca79d4cbVirustotal results 40.68% Heodo
2020-07-31Dat 20200731 717274.docdoc 1f026d0c6af0581b3cb6ccf98632e978d6267d06bdcd83563307eabe38620165Virustotal results 49.15%Heodo
2020-07-31list-20200731-I49964.docdoc fa3e81294239894ab6d187ff561319cd3f23649f9888593ae2c7bd734af6ecfdVirustotal results 49.15% Heodo
2020-07-31ARC 20200731 9263948.docdoc b24383b94d024d7b70eedeb7a46866953f07275f1a7ac00fad41f149696db391Virustotal results 48.28% Heodo
2020-07-30List XKB013.docdoc 37a735cf6c77b657f5daef878aca4b61d7edaf9a7612575cbf361a4286156caan/a Heodo