URLhaus Database

You are currently viewing the URLhaus database entry for https://middlemagazine.com/sys-cache/eTrac/M6TTrQ1BwWz/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:545170
URL: https://middlemagazine.com/sys-cache/eTrac/M6TTrQ1BwWz/
URL Status:Offline
Host: middlemagazine.com
Date added:2020-09-17 12:35:07 UTC
Last online:2020-09-17 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-17 12:36:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 49 minutes Good (down since 2020-09-17 14:26:01 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-17arc 2020_09_17 4615.docdoc 2dc66566b82af7322a37d69bcd0052bfc5e454abce37b101c7b6f3d715abdfacn/aHeodo
2020-09-17ARC 141.docdoc cc96320d4b261455f9e38490eaeaa1f04d7eaf3c322dc6771225ad50a0f4a29en/aHeodo
2020-09-17Arc 20200917 ZP670.docdoc 05ce719d6bbe09bf2fd00e9ce8c5d8a14c173ba82dd5a361d3a34c95586fe45dn/aHeodo
2020-09-17Arc H234.docdoc 42f8349a51f2a89dc0e94db8a5437d9a51a817b6a12f77178b9beed274730b5dn/aHeodo
2020-09-1772035 2020_09_17 010820.docdoc d67efc77364801dd225a827ec8b2717b46ed9a3d0cfc421a8f52d88840b17bf3Virustotal results 28.33%Heodo