URLhaus Database

You are currently viewing the URLhaus database entry for https://marquitosgoa.com/wp-includes/Pages/zLqBiYJJ1zXCR/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:630041
URL: https://marquitosgoa.com/wp-includes/Pages/zLqBiYJJ1zXCR/
URL Status:Offline
Host: marquitosgoa.com
Date added:2020-09-30 13:27:03 UTC
Last online:2020-09-30 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-30 13:28:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:1 hour, 40 minutes Good (down since 2020-09-30 15:08:32 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-30Attachment 20200930.docdoc 9c64b681d05175b3e7768a424579e19e1cb064bc89e07001c94b31a19a6db8cdn/aHeodo
2020-09-30Untitled 20200930 ERW463.docdoc a19b038d491d4ca43680c6d74f88143a523afe12be6191d54393fcc1e609df17n/aHeodo
2020-09-30arc-C803.docdoc ce437cd41adb6661b0e4389bcb5f69ac300b5e9c7fafe156dec9f8df767b625bn/aHeodo
2020-09-303237245 20200930 U58286.docdoc dca2f3f5cd4fc577315e8bd9fcb344afb5cdc0726cd6349dd3698c48cc0542d4n/aHeodo
2020-09-30inf-20200930-O47001.docdoc 3457ce4d5f9318c7bd875c583e9c7be3b65c2963e1a6f597390275f7e03cef0cVirustotal results 24.19%Heodo