URLhaus Database

You are currently viewing the URLhaus database entry for http://marvelgroup.co/demo/docs/FQw82nbdgMnB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:597133
URL: http://marvelgroup.co/demo/docs/FQw82nbdgMnB/
URL Status:Offline
Host: marvelgroup.co
Date added:2020-09-22 13:37:06 UTC
Last online:2020-09-30 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-22 13:38:40 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:8 days, 4 hours, 59 minutes Bad (down since 2020-09-30 18:38:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-24593139_T760495.docdoc fe3cc0d7c9149b7117d7835e07f7c916b5cca31c1f3f2bf90d9a2b77b8d98c0fVirustotal results 32.26%Heodo
2020-09-24arc.docdoc 94d496b45447bafbd61e3db3257ff0371ff39e44f783dd6ceca721bc79151be0Virustotal results 29.31%Heodo
2020-09-24list-NP291396.docdoc ab018f08c79d8a8f4335f9fa35e22f6d573ddcf82c5a1db98a8ceb6671bae1b6Virustotal results 32.26%Heodo
2020-09-24Untitled_KMC23337.docdoc 025db95d810ab6ee5921b32025854992c1914a1aaccf0783f4a99991290e18adn/aHeodo
2020-09-24UNTITLED Y345.docdoc 0fdfd0bf5a70dcd3c4f8f8c8fca5f034d855255ee1cdd4aa4e9a477ac4329362Virustotal results 37.50%Heodo
2020-09-24List-88724.docdoc 2677eca82d20e819b49e10849f94803b189d30af9526a146a14aa65b8393a944Virustotal results 30.16%Heodo
2020-09-24Inf-2020_09_24-W69528.docdoc 4da7b86975d7a29be7c1f9dfc46eb1463388e66694d9df0ef78ee14549c145c3Virustotal results 30.65%Heodo
2020-09-24Arc-2020_09_24.docdoc 996c5f68583ed17db8c022bb5f2a0d32eea5927e2df2343b19b79b40a16486ecVirustotal results 31.15%Heodo
2020-09-24889UEM-20200924-49738.docdoc 3020db5313a9b6de1b0e7dd95d8273c9c7bd8d2a4fd052082d9de9981056dde4Virustotal results 30.65%Heodo
2020-09-24mes-20200924-KV50174.docdoc 913c4df8b23c19870eec0fc8b841877aa428638a2b4b41a081bf18f9f65dbd4cVirustotal results 20.97%Heodo
2020-09-24file 20200924 484.docdoc d8d2680a4e26f522c087421a816565e6abe39207532f6c19b5e8004c1921b129Virustotal results 18.33%Heodo
2020-09-24File_628.docdoc f2e3feb41565cc844a3bb072dbb0d54fb53d4f1cc44860f23dc3d8c4f4c470edVirustotal results 19.67%Heodo
2020-09-24Attachments-2020_09_24-648757.docdoc a857f646e850ebd405ca8405b40ead46310cc56778bf78f897edd78035941bbaVirustotal results 19.35%Heodo
2020-09-24DAT_20200924_274.docdoc 6f1bb55765e88a93bd41c9de93203aa15fa24ba0367e99d178c8b5d8bf3cda74n/aHeodo
2020-09-24list 2020_09_24.docdoc 6093c4cfb002d365f8ed7749c339b75a92ae859f23a5989378d8096481daa5caVirustotal results 43.55%Heodo
2020-09-24dat_20200924.docdoc 448c58d4e526ffd04116fb0f31bd9971ce9f51c993c4368e3ef8a54c93a2c70cVirustotal results 44.26%Heodo
2020-09-243012-2020_09_24-OZW06127.docdoc 77d05388e54ffc1cf04195a80a090cb3eaa41f8820c93c4c646f4f56cb6beffdVirustotal results 43.55%Heodo
2020-09-24FILE_Y44886.docdoc 4646dd3e53714af28ecc8c4bd54029a5cb00ec4ea6eead753353eeb8e574ff63Virustotal results 39.34%Heodo
2020-09-2482690127_2020_09_24_6926869.docdoc c0e4414d503b796df3ac298ceabf771394e65acce8d3822dffff366964dd8d7dn/aHeodo
2020-09-2456210J-20200924-SOT9254.docdoc a8c29fd851cb952d316acc958e0666ef6c6d2ce6e1d8404dc1aa1ab06c95b79cn/aHeodo
2020-09-24Rep-20200924-789.docdoc 452a5769e0ee8f5698e793518a7272414d747287e82494b62ee4db46f2101f18Virustotal results 36.07%Heodo
2020-09-24470695_2020_09_24.docdoc 031a4e9cda99df5d982b2b59480f2354ba7a4f13a3f6d6366feff317bf4820f6n/aHeodo
2020-09-2462849PFS 2020_09_24 249106.docdoc 48523dc1483cef07ef0bca44fe8f6629de0a7ab7e89899640b66568d4816c54aVirustotal results 33.87%Heodo
2020-09-24Rep-V6189.docdoc 9b6ddc314258dd07193fca458631855ec60eaf598557379f4bfb34cf178a0d41Virustotal results 32.79%Heodo
2020-09-24File 2020_09_24.docdoc 459d111095342d54bfb487028848de4425f55b76dd86c33da107f3f09edfc4a0n/aHeodo
2020-09-2404876555_2020_09_24_MV14426.docdoc d459ae5f366703f6a9c1ad00f597a966ab17bbe733d0eb970e94a9e1ed912dc7Virustotal results 32.79%Heodo
2020-09-24Attachment-20200924-SNF703.docdoc d7bc2bab7f33b749c58f25edb93fc2b032a41f112b80e69d310fb818f109d3eaVirustotal results 33.87%Heodo
2020-09-24doc_2020_09_24_OH2590.docdoc 1deb4e6a6641ebc64dead1bca39705a6df4d32fd478c574303dd3a17370cd84fVirustotal results 29.03%Heodo
2020-09-24File_20200924.docdoc 94e4fe6c73db0e80100417fe60ab8d9b1fe7fc9ece7a2923861e1e1d42717d4dVirustotal results 27.42%Heodo
2020-09-24doc-230.docdoc 723d382c65591be516dc0f62f769cd79b42fffef91a244bf773da31d1478f631Virustotal results 29.51%Heodo
2020-09-2416021QFA 2020_09_24 Y792082.docdoc a94c2c5af432da438e746e9cf551dd6b3c7645af7a509a8bd8a7b4cdfc76ad96Virustotal results 30.00%Heodo
2020-09-24FILE_2020_09_24_YC826103.docdoc 98cac1b2d3b5764f8aabb6955ae8d2f9d1078b7f4fe2ba221e4c54da5460ef08Virustotal results 29.03% Heodo
2020-09-23Rep_328871.docdoc bf610aa108a8cdb11b895e0c49cbad7b781810f1c4b95a051d0a75ad830563baVirustotal results 29.03%Heodo
2020-09-23Dat-20200924-638287.docdoc 5840a444fe973bc3d41c8334eb9da05bef991ee9bb7863e19181c3c11dde0bcbVirustotal results 29.03%Heodo
2020-09-23INF_179560.docdoc d5925a52ac9cd59de6d9a5006d99886c79175fa1b26006effce8f26ca1a6385bn/a Heodo
2020-09-23Attachment_2020_09_24_1145.docdoc 96307c5a62e457f86a55e67c624892de7b841d9f9e37545fff75861f6ff6e749Virustotal results 29.51%Heodo
2020-09-23Doc_470.docdoc 8034f804eb73d852e44f3747467758493a197f329723f30b0ab6da31d8e40acfVirustotal results 29.03%Heodo
2020-09-23dat_2020_09_24_Z7382.docdoc 77d0c8250e02def7791e35e8867734e4c830c7ffa95f8e0e701be87d596115d3n/aHeodo
2020-09-23DAT W480320.docdoc 2f4d462d1ebf2efd17320d7e0a5595ab8b55f8d8fd9e9e94d5e8721cd88c2ef9Virustotal results 28.81%Heodo
2020-09-23Inf-3817096.docdoc 565684ddbbc44e0cb4cfd978bb95b1c3f425955e0d78b2fb2d112c1405c31934n/aHeodo
2020-09-23UNTITLED_2020_09_23.docdoc 0fd85da59d6b48ce05fd95b68876bf8fb44c782709aa7f53ccd674673c628b73n/aHeodo
2020-09-23inf_2020_09_23_WO010.docdoc f55309ef8103e8a22b236ec04b6e3d4e4f358098a3cf215c9048a202e7beba6bn/aHeodo
2020-09-23859262_2020_09_23.docdoc 776094e859ef485a39874c83e60218bcbabab097a64d650b872a9c747ca9b7b0Virustotal results 23.81%Heodo
2020-09-23MES_Y667.docdoc 564cf15d75ab866d106285b7075ff84a4b2a056802d26af1bbddcfbc2e2aa176n/aHeodo
2020-09-23Doc.docdoc 4bba9a7e75c30f59092690a7c7aee69fa75e0bac9834ab0ed5cc09a6c17b0800Virustotal results 24.19%Heodo
2020-09-23doc_2020_09_23_I0372.docdoc c115496f1c00acee0ba2504206a523fc093e8c17d127a85a9fdfb88ae9625065Virustotal results 25.81%Heodo
2020-09-23List 2020_09_23.docdoc bf0c0d8405f31ddf2f8f42f73b66516e529a85f5045cd102ad36dd7dc5bca66cVirustotal results 22.95%Heodo
2020-09-23CG699 2020_09_23 732.docdoc 48088fef82ceef7a0e37949c7f49ddad25c550d493d0dfea572a30aaa41f36d5n/aHeodo
2020-09-23LIST 2020_09_23.docdoc dfae82013bca633741113a217e0121e03f6184d7c0286fee76dc0a8065fcc658n/aHeodo
2020-09-23arc 25261.docdoc 7933d8d9847728baa3c56f3d63a5539deb3a9260f1d7e03df15affdaed3a57b9Virustotal results 24.59%Heodo
2020-09-23doc 2020_09_23.docdoc c82204f05d965920dabed03f975483321d08789ad161eb2e541395bafc8b9ebaVirustotal results 20.97%Heodo
2020-09-232794_07592.docdoc 7de7c3f5e5713fac361f2b8dd2c015dfa239a2e33c7616a4872241acc8320b68Virustotal results 17.74%Heodo
2020-09-23Attachment_20200923.docdoc 5c71823fdb58d87974e42984373f86844a885139266a5998286d3a8af69a85a7n/aHeodo
2020-09-23UNTITLED 2020_09_23.docdoc 7ab1e02cd484bd8eacc14e4997843764f035abb2c7fc449a1c90b93acecaeac8n/aHeodo
2020-09-239108299 20200923 9649950.docdoc 6eb287c4415cd13a838e22611588a67b3de2af15d6ffd1f1345bf7d94fed20e3n/aHeodo
2020-09-23DAT-2020_09_23-I06306.docdoc a74bb4fe8856890718cfe6e74662170dfb7510a006f324b6b71f95bed8a0da31Virustotal results 17.74%Heodo
2020-09-23LIST 2020_09_23 JF2499.docdoc e39f691edc4ff1e1fe413e85f4ac03ceace139451e760efb67e195bdd940da7fVirustotal results 16.13%Heodo
2020-09-23DAT 2020_09_23 525.docdoc 4b44a49d851cfe708c39124110dcb95dd328ecb52b9c80a0bc91c9fffd677ef0Virustotal results 14.52%Heodo
2020-09-23REP.docdoc c92bcf1609664dfd1d2c60ba1ab0e97035401c70f259aedb7baf21ff50858908n/aHeodo
2020-09-23inf 20200923 QAC7039.docdoc da70616307607ec5010de6bc4f9d01785fee4f96a316e839ab7e76751608b734n/aHeodo
2020-09-23Inf_20200923.docdoc 5616a07174bf07899d97125e61f8bf9dfffc6c3e363c87a6fbef04d0ca2be8e1n/aHeodo
2020-09-23Untitled 20200923 016723.docdoc 0b54100fa83ac1de95e2c67b08ec5a99ea5cedb577c2673aba4001022cf1742eVirustotal results 25.81%Heodo
2020-09-2305611557-P938924.docdoc b1ba10a2cdff3f7b26aa3d4644b9ad18de9e3bcb492556dd03cb454ebec76b76Virustotal results 24.19%Heodo
2020-09-23mes-2020_09_23-57408.docdoc dfa8f288cec02386061e3fa153580ff5a6eacd75a41cb2d27f3a3fb4c731f737n/aHeodo
2020-09-23DAT_2020_09_23_CD77947.docdoc 4637b26a9ecb444cb7b4ac7227ece0a2a58c9fc83545dcfb15f8c3011458e675Virustotal results 25.81%Heodo
2020-09-23LIST 20200923 250803.docdoc eb08530e5f924639dcd82792dbdb90d6cc3b51a631675c77a66a27351382158cVirustotal results 24.59%Heodo
2020-09-23LIST_486.docdoc 453b69010023da795bba1876cd362cefe28c387fc05257ed7037b766a101779cn/aHeodo
2020-09-23UNTITLED-2020_09_23-7960679.docdoc ae33aed667d8528466525b8af553788b5eb989c106e74c17d89be4c21ee174a5Virustotal results 23.33%Heodo
2020-09-23Inf BC084.docdoc a479d904e47ac4318ff5f4b0b9e46eabd12fed4df701fb91829a08684ab7bdc4Virustotal results 24.19%Heodo
2020-09-23MMA9907_E39446.docdoc 56030b1317e1938948565d60fb5058b0a683637f2dd820947141ccab89998f43Virustotal results 19.67%Heodo
2020-09-23353FGF-13277.docdoc 48860f05fa54eb5e2a2d97f62a59f8bbc2f3df78ea0a6093fd26420a7c7c860eVirustotal results 29.03%Heodo
2020-09-23Rep_20200923_251488.docdoc bf62cdbe7b5e4207ff3acb0aba88b0180f584c4a1a7d3eb14dc3d66c27fdbe21Virustotal results 29.03%Heodo
2020-09-23Dat-2020_09_23-84866.docdoc a61f1b45b06305829478c9c58b8b8e94fff53017fc1e735bcd18e288f0efbabcn/aHeodo
2020-09-23Rep 20200923 N1259.docdoc d29db979a44af6a91074afd2c68cd3c1f353bc4f4a30a953916795ecb3813e61Virustotal results 30.00%Heodo
2020-09-23File_X1240.docdoc 7295aebd2a618cef25261555136c8dbef5344ceabfd9b5088a41276c05b48cb3n/aHeodo
2020-09-23list_20200923.docdoc 4f09397b6219cc33b6d317121c35865043663d6bead47a855a9d33820f8f49fbn/aHeodo
2020-09-23REP_2020_09_23_799.docdoc 9bd69510e3c43ec7952a8f5468ff9928523e1a435164c281bd3f6b789568e8a3n/aHeodo
2020-09-23Mes-Y998.docdoc 799375bc17349fabb727d209dce766f0f790222a89a95d7783de4428c113320en/aHeodo
2020-09-23list FT747859.docdoc 79026593013ecbf23dccb9db4eeeb812b77aa0d3749441ce05e92f1f216e38a7n/aHeodo
2020-09-23DAT TX6519.docdoc 692bbf3c78f0c8af1c57acea7c9910b8138ef4e85822096176a8bbd7603623fan/aHeodo
2020-09-23rep M23607.docdoc 4eea20ea1f7e4eb2be858aa3760fb9de41ca1e865fe12e6d3dd2ce43ed84845bn/aHeodo
2020-09-23Attachments_20200923_ZC8838.docdoc 8d9264f42739eb272f340990d05b2688263682781551a47e197cf7fd15f54695n/aHeodo
2020-09-23DAT 5033429.docdoc 64c7907e94da2ce9a18f7ad3c62a54d7e9afb9b0be47c3bf44d9e94298fa4e8bn/aHeodo
2020-09-23DAT_20200923_ZGO490584.docdoc 1e507d68388701dc8f629d1095e01d6d906909f368ced204caf92180f11b1a55Virustotal results 29.03%Heodo
2020-09-23FILE_2020_09_23_865828.docdoc 352b0eaafd07102686fb7e59059288bd6f527e4190c6700cc5dd1e6f267bda16n/aHeodo
2020-09-23UNTITLED_2020_09_23_031834.docdoc 2848cdf9e7ce3d808191531f2a46ab11df4f948725e708cd401944cbf333f7bdVirustotal results 24.14%Heodo
2020-09-23arc_2020_09_23_CMR41976.docdoc 81b456f559f2efef31515554fd43bcf8ceb61f08ec66226eaf06dbad995f64c6Virustotal results 27.42%Heodo
2020-09-23rep 20200923 606.docdoc da5ffbd8e3f1e32cde22e5e6d87f62a99816d614a29179e6c393e6ee1d1eec8bVirustotal results 27.42%Heodo
2020-09-23UNTITLED.docdoc 4936a865fa30aaf552649f3c14f7333565da60037a34a9ec243752662b79c6b0Virustotal results 27.42%Heodo
2020-09-2396174-20200923-G1542.docdoc f2de99ef933f7cf018ba9947803a5f5c5a9cb72ea0971ee3a565468c10a8783dn/aHeodo
2020-09-23Dat_2020_09_23_8998.docdoc 24902fba74d4a7285bcf27a18267f05e104acd3dbb083de1c50f854e491b2378n/aHeodo
2020-09-23FILE_9737.docdoc e213173e3eda08277bd3f8276a466a8eb67f19823c6fb95aa45a06fd29fcd646n/aHeodo
2020-09-23J01018 20200923 KC04821.docdoc e654ead5a64c1a9508e1824c6e391f25e0dedee6db74de85549d1c8527a359f2Virustotal results 27.87%Heodo
2020-09-23Attachment-2020_09_23-HDN95402.docdoc 14fb3459b2830d93d3158893cf9d19a967236429dab7740d73d83999d23d380dVirustotal results 27.42%Heodo
2020-09-22Mes.docdoc a132f8367518b36376bd03160587713674ff98805021fed3d6e3ff58c045a97dn/aHeodo
2020-09-22MES_CX2032.docdoc ddce72ee2a6c8276c490d00f3c5334dddbfef7dd01107ba9b47b8620b5f04f87Virustotal results 32.26%Heodo
2020-09-22mes 20200923.docdoc 9895cbda416306bb0fea5069cc2c9525a714f63de4260492ec34e1d5697ae24bVirustotal results 32.26%Heodo
2020-09-22Mes_939602.docdoc e3187dbe7923459b3ea645a3d68b357927471e14d70aa4e542327ad4ef540637Virustotal results 32.79%Heodo
2020-09-22File_H414848.docdoc 1d6604773dcc06efdd5664f01c0a515be47465bf1638f5b9dbed05debcca83b5Virustotal results 29.51%Heodo
2020-09-22List-20200923-7329.docdoc 8031c668f56e12d2f6e1d54f98aea8eca655f14e6dfa3ca6df9da76aaec004f4Virustotal results 29.51%Heodo
2020-09-22W2843_20200922.docdoc 0e33489760ef3718d82c94dfe4827be3bbe89593da14b7a7912b7345f3e7e56eVirustotal results 29.03%Heodo
2020-09-22mes 2020_09_22 JWK336336.docdoc 41e6b271c4d42b952c300b7772f78ccdf76279c2357380936a0a4d520e511a60Virustotal results 29.03%Heodo
2020-09-22List_4232831.docdoc 5118e3bd72677f8cda269a8e2c50571beffb5dc3f7dbfb1b05cd1e44a904a214Virustotal results 29.03%Heodo
2020-09-2271413_20200922_58788.docdoc 68489ce36e7548641be6668b08d265ead175025a1650199eb050bee7e4e8566eVirustotal results 29.03%Heodo
2020-09-22MES 20200922 9946.docdoc 5231a24a90603fcebbe4e812fb2ac981a788534259a9f3bf6343cef44d447720Virustotal results 29.03%Heodo
2020-09-22DAT_652.docdoc 3a9ad2454dcb31ab7a424d69dee0659c219202415da5f6a02f0de501701f24b7n/aHeodo
2020-09-22rep 2020_09_22.docdoc 877325fa959dd70b6e6279c0000e5b2e40a206b88c550c288b961db9740c681fVirustotal results 29.03%Heodo
2020-09-22Arc 20200922 J542924.docdoc 807f0fb8f94f16a66f2cba86e04982b3c8cce542eb80678040264f2a5f3ea051Virustotal results 29.03%Heodo
2020-09-22list_2020_09_22_328442.docdoc 1086ffb88505e44c03ff9497ac66a9df3717d361cfc1aef1cff28a1b67ae9eb1Virustotal results 47.54%Heodo
2020-09-22Arc_2020_09_22_968.docdoc 104d2e1471c7993b4d02e8043079b61edd68a9c7744f66779b40d798cc1f8da1n/aHeodo
2020-09-22ZCN7998.docdoc af06636ff1f20f41974598ecce049672f3a6b8e245f80ef60b4c36eeb4c7d5fbn/aHeodo
2020-09-22list.docdoc 4e0fc19cd148b47ee573dccbb780bc459c45275318871548b3b864d9eb0af8ecn/aHeodo
2020-09-22dat 20200922 679049.docdoc c4699bc83e2c480aa53af341f4b67b5dfb27cb5d28fb09a7619b55689b686ae3Virustotal results 45.90%Heodo
2020-09-22MES_20200922.docdoc 2c9c3cbda0aa694b7f8075132ef84de6c06632e7959d6356634acb932ef4d9b4Virustotal results 45.16%Heodo
2020-09-22inf-20200922-7482.docdoc b58e849ff15fd90ea845ccee23fb2884bf9666f6dc705ac84dc556130a1f90edVirustotal results 45.90%Heodo
2020-09-22List 20200922 934801.docdoc 8ce52163ceab79b32f012e6129070434d32ea30dfab92da2a9e62e79da693497Virustotal results 45.90%Heodo
2020-09-22inf-232210.docdoc 8becb7ca0d2d13bc1e667d22cf222c927c6b952a67daede438a39afcf555629eVirustotal results 45.16%Heodo
2020-09-22mes-20200922-IBS07246.docdoc f37f2049ceabc90d26652988361144efe6e8f6600a94ec8e61f9b461233e2fa8n/aHeodo
2020-09-22Dat-ES765.docdoc f8be92f6e72e27aee1f0edb3b42e6823fb30804713b3c34066fe75a75c4bfa5bn/aHeodo
2020-09-22J1223 20200922 99045.docdoc fe522973d24d82334e51ac782259df4894964c0d7ac3b4090ef77bb2b734377cn/aHeodo