URLhaus Database

You are currently viewing the URLhaus database entry for http://markantes.com/jason/public/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:437864
URL: http://markantes.com/jason/public/
URL Status:Offline
Host: markantes.com
Date added:2020-08-21 03:18:34 UTC
Last online:2020-08-21 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-21 03:20:04 UTC to abuse{at}networkredux[dot]com)
Takedown time:2 hours, 16 minutes Good (down since 2020-08-21 05:36:43 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-21E0WDD1B.docdoc 29489d8ec25a46a76a0bb977cba3d4260eef3e2520e1b060a323df2c5f8cd8fbn/aHeodo
2020-08-21I_NSS_080120_UTO_082120.docdoc 346bffecd143569cdd0fb796380eb297dbf4b03fbb9c68edf994501847763d20Virustotal results 31.03%Heodo
2020-08-21V_3569924306810644628239.docdoc b067f851af29843c48232b84fd2062937192d864d7f69979bc590786f4f4d4d7n/aHeodo
2020-08-21F_6757767578016513.docdoc 7112a5a9264a099d9056f3d980c95fead062c56ea04362528c505bcc6ddd2b1dn/aHeodo
2020-08-21DOC_PO_08212020EX.docdoc 913271f10fdbf26cf67c0c6b3b0f0f501848bf25f539c04feb5553f95307bd95n/aHeodo
2020-08-213B2GBZ51NUYP9IR1.docdoc c87f02029dfc7cc838cdbd76fe5640ab9778826bebdd965fd772f7b853d4178cn/aHeodo
2020-08-2122036332.docdoc 35ed303201d25d7d1788fda68276104204904cacc9d5ab695589c1b68ee96020Virustotal results 28.81%Heodo