URLhaus Database

You are currently viewing the URLhaus database entry for http://maremarius.pt/swift/92vrxua829145413790520tksq5iu79jje1h/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:441074
URL: http://maremarius.pt/swift/92vrxua829145413790520tksq5iu79jje1h/
URL Status:Offline
Host: maremarius.pt
Date added:2020-08-25 16:17:09 UTC
Last online:2020-08-26 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-25 16:18:02 UTC to network-abuse{at}dominios[dot]pt)
Takedown time:21 hours, 11 minutes Good (down since 2020-08-26 13:29:15 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-26EE_TPL_080120_BDC_082620.docdoc 690b7078636392724c3d0facd5199e05ec56585148bbcda6aa7f2c64f597635eVirustotal results 28.33%Heodo
2020-08-26INV_IZ5789931133SW.docdoc 676c878bed2e541c7e1adcbb0f141462e8f98125e82ff705dcda881165585452n/aHeodo
2020-08-26INV_P6AHWPU7MT.docdoc 16ba108b19b54a215fdffb4ada0bf198814e65190ae73a686c300bdfb5eb2ab6n/aHeodo
2020-08-2652016609.docdoc 0fb8cdd6e033deca3e95931c9f20ddab1df2d839911cb271774ae42cf5460094Virustotal results 28.81%Heodo
2020-08-26FPU_080120_TTQ_082620.docdoc 673dfbd1e8a6cae6500c6bc52686bc69101e89a34d4f579b1f3b5a45174ef250n/aHeodo
2020-08-26BAL_LM1299524827DZ.docdoc fc8d4d45930f6975b843b9efc608897012e01b772d88025fc4d2762e24802adbVirustotal results 27.12%Heodo
2020-08-26YC2828368065WA.docdoc dc167ca9c82110cbd8c275bde50770d2cda4d232986e4018107994b92009862cVirustotal results 27.59%Heodo
2020-08-26V_PO_08262020EX.docdoc e14c5eae5d7ce85445fc7463becfb3896307625e246e3b97df5def0501570eedVirustotal results 28.07%Heodo
2020-08-26IZT_080120_XOJ_082620.docdoc 66d9e9f340163d1c3be2cc282e4b2871834a870392f970f4a1121da1c578b7d0Virustotal results 25.42%Heodo
2020-08-26CW_JFL_080120_ZSI_082620.docdoc a1b37527202d95f794add7eefe6cdd747cb51e22ffe2d301dce761e7f27be7a4Virustotal results 25.42%Heodo
2020-08-26JST_4749666658390.docdoc e2f93f504fd4eaf83abee9ba616dd2ff6264f7805737a5556899e37883c7cdc0Virustotal results 28.81%Heodo
2020-08-25609006366864960.docdoc 4a5ed6745fd5984335099810dddf416d8d709155611992c8d2f5af52a465fe32n/aHeodo
2020-08-25BAL_87440806355759909634414.docdoc 696268abaa7fca009d2d755c96a4aab42d5aa9d20f5e586480896798e975b44eVirustotal results 29.31%Heodo
2020-08-25ZG9425888121DX.docdoc 2eeec2892926e686de8fcc29fc57c57b10a4f37e49cee06ec4b5c864dcf5cfben/aHeodo
2020-08-25INV_GU8939941844GF.docdoc 450e8dc78bc1e07fb859e5b2aa358a8df25b20cb9e7aee45c0489e1718d10f1dn/a Heodo
2020-08-25OKRZ_17657917.docdoc b7d31d0d2e6624c23fdf8a2c989875d78052e661f92c0839d379c4197a188415n/a Heodo
2020-08-25YE6858992890YF.docdoc f83ff86a7b80e435264d444c0bec91a81e09cbc5df01e1f2f155d3782e456eean/aHeodo
2020-08-25REP_7381499745624409823015.docdoc 96eef74c59d9b8b47979fbaf2552a9735dcddef28df0b5b87655a4c849f9d853n/a Heodo
2020-08-25DOC_8RBLUKJCYL1Z5.docdoc c83c6353d36706d9ede8b73d387db5ea74ea2977900f849d802d7cf17669c266n/aHeodo
2020-08-25BAL_PO_08252020EX.docdoc dbe154340b5e5f2e020d7e33eeaadfe4a518f3dc72a2d83c43e48d16c453e9fen/aHeodo
2020-08-25FX9740716959LW.docdoc 263db302489a8ee87cd55bc7cdcd6853b02d39b711ec9a671afef6737154e2a3n/aHeodo
2020-08-25DOC_98612600708848602.docdoc 0afcf7a35acb62edb01ee3f2827626deac6bcb7f7cfc799a2f56132d916b571fn/aHeodo
2020-08-25TP_YN0406518449AP.docdoc 7cac6f200ebca1722e73de9a75c49af7370e59a87960f9ce3e36a52975a7b1bdVirustotal results 40.68%Heodo
2020-08-25REP_PO_08252020EX.docdoc c52d43a72bc36aa33659558cfb0788b7c919cf70f6d6c98be550891ce51556abVirustotal results 43.10%Heodo
2020-08-25FILE_PO_08252020EX.docdoc f0842ff3c4163d604958e593b4b63b2519467663122da0e9cb70fbc0f4494e91n/aHeodo
2020-08-25QKI_080120_ORL_082520.docdoc 23b985aeba6423e4a9a4b3c2c30d057fbf0dd29f65d0700581a45b8276eae366Virustotal results 40.35%Heodo
2020-08-25JXY_UJ0539187354CM.docdoc 883741e495892bc438de513bc9c4003bee8b8c25de3bca5266b7f5d03896eaa3n/aHeodo
2020-08-25FILE_PO_08252020EX.docdoc 24d0808f9cc4ef5a1587e54dd135bf7e3d4ac84ce1dbd7cfcced11649bdf0157n/aHeodo
2020-08-25FILE_PO_08252020EX.docdoc 31b667c4a36243119386974054815bcd6f58ac21d868084ff020986f1b28cb30n/aHeodo
2020-08-25TSO_PO_08252020EX.docdoc a1187d0a8168efbc1d9886ed333f9bf24f7fc79c55ef5f4dec04909961c4c800Virustotal results 32.76%Heodo