URLhaus Database

You are currently viewing the URLhaus database entry for https://martinstec.be/wp-snapshots/browse/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:436700
URL: https://martinstec.be/wp-snapshots/browse/
URL Status:Offline
Host: martinstec.be
Date added:2020-08-19 15:39:34 UTC
Last online:2020-08-19 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-19 15:40:04 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 17 minutes Good (down since 2020-08-19 17:57:11 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-19BAP_080120_IYY_081920.docdoc ca9d8a7d89d70189c5aa64520344cab49186a9085d0607897b31f836b090f7b2n/aHeodo
2020-08-19DOC_07259073.docdoc 77834d629af8b45f85ec232e03fab3cf97e78e448b23fe48bc93ad6a391f3c90n/aHeodo
2020-08-19M_RKOVKTMOIZL.docdoc a47b7f6d9af6602b2dac196cb0faf5414e8a3d7f94604f937e2e66f19fd17b61n/aHeodo
2020-08-19FILE_0ZAFN0DF19L8F.docdoc 40430817aac77bdfe251ec9275bd54f3f38e091508e5381af53292469132db78n/aHeodo
2020-08-19WFWY_55350462.docdoc 3ae29b3f7f29f20ad0073a44572a88b7aafe19da62e0a8d8d8a04213945f0e80Virustotal results 16.39%Heodo
2020-08-19XBA_080120_RVH_081920.docdoc dffce4f3af033dddc15747bb720fb0bd4358e29dffa6c674242ce4350b44af48n/aHeodo
2020-08-19UY7424213378NU.docdoc d054c0a4a703726e52aaa5f6db946aefbc777af3e84c0bef5d5cfa5f7dbfe034n/aHeodo