URLhaus Database

You are currently viewing the URLhaus database entry for http://margarete.it/wp-admin/Oi/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422506
URL: http://margarete.it/wp-admin/Oi/
URL Status:Offline
Host: margarete.it
Date added:2020-07-31 00:40:05 UTC
Last online:2020-07-31 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-07-31 00:42:02 UTC to abuse{at}ovh[dot]net)
Takedown time:7 hours, 2 minutes Good (down since 2020-07-31 07:44:07 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31INVOICEAV1761_78653650.docdoc 3d8ef147ca84e9943fdc850171e2de9c05b0db3472cd05901e4f109e7fbe07f1Virustotal results 50.85%Heodo
2020-07-31INVOICE_JD75{:REGEX:.docdoc 24faef0a3c46f8fdf60a5fff6f323ebd01a0365dde63a55a242ecfa0455183baVirustotal results 50.82% Heodo
2020-07-31Inv-4_41903823.docdoc 31cc2ce5d46e87076266a3202b8fcf83047af212b47c84458caa5fa94d48e86cVirustotal results 51.67% Heodo
2020-07-31Invoice-ENC062-4878624.docdoc 5399417505ae67bdc2253943f273fe2b69fcdb71294530cbfe0cbe731a251b48Virustotal results 50.00% Heodo
2020-07-31invoice Y228 645993453.docdoc c8586306addfc533e0c3ee2c72a3a19e28d38b0e41207d72632708e52ee965abn/a Heodo
2020-07-31INVOICE-7914-180072.docdoc 36edfa2da0e0eae3557b74c315c7dd66eb25f209f7e207682647a475984eb47cVirustotal results 50.85% Heodo
2020-07-31Invoice GKRX801-127969.docdoc b6ffa6767e3b7c53645dc329280108bc5145c28514aad30f28d9b628bb3bed9dn/a Heodo
2020-07-31Invoice-R28-758298785.docdoc 8e95611645644103d2ab67a6ecba315228abcad85d986852783b1af75477a63dn/a Heodo
2020-07-31Invoice_ICYU2164-104000597.docdoc dcfb38249b589a264dd4ce2c25853335f1399685fcd68d68c337f308d110a793Virustotal results 50.00% Heodo
2020-07-31INVOICE-G53-811684.docdoc 105f7c3a68f898a8605a251f25363f508285b8d32b8d6fd1f1e00565dcb4e3fcVirustotal results 50.82% Heodo
2020-07-31INVOICEZW24_77321065.docdoc e98facde0dc82a3d26e7ceb7588d41b8a6246e4c74bc9fa68679aa9820ce91b4Virustotal results 50.00% Heodo
2020-07-31INVOICEVGB8039-489139187.docdoc 2239e9dfea333b691ad7931b2f663ce27192aa0bfe9b4c7112e98eeddc00ae38Virustotal results 51.67% Heodo
2020-07-31INVOICE ULBD0954 362944.docdoc 5a6467226e68ef101e447b20fd8f64d3e84e344d4dfa8fb2759fbd303b7a6d64Virustotal results 50.85% Heodo