URLhaus Database

You are currently viewing the URLhaus database entry for https://margaash.us/sys-cache/DOC/0u9thggdtv/1zn69dp08z987/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:694310
URL: https://margaash.us/sys-cache/DOC/0u9thggdtv/1zn69dp08z987/
URL Status:Offline
Host: margaash.us
Date added:2020-10-14 20:46:05 UTC
Last online:2020-10-15 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-14 20:48:02 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:9 hours, 47 minutes Good (down since 2020-10-15 06:36:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-15BAL_MTJ_100120_VHE_101520.docdoc f71ae94d242b3462c842f1437cae8812ed520d8707566c04c3570859cc609937Virustotal results 33.87%Heodo
2020-10-15BAL_FJM_100120_QTS_101520.docdoc 97facc45c64f326ed17ae9ea249dab0f4d6bb4a237092a7996d8e4eaf43226c0n/aHeodo
2020-10-15FILE_392157158908.docdoc 0cf59450f4af8123dc62d34cb387c1f4bcc5a3c38cd4c966acbd7552574d9fc8Virustotal results 29.03%Heodo
2020-10-15JX_6234867292368686.docdoc 100b400505d67803dd47e7093247e44637dade8df24255e8fd14b80a78f77533Virustotal results 34.43%Heodo
2020-10-15VNNGVAG.docdoc fd12780ca0e4c591da35bf3d215c22a47050b1a68e524ce4d0434ee2414cbf3aVirustotal results 32.26%Heodo
2020-10-15INV_QW1557079023KY.docdoc 2d22c090ca32c456c3d88c382392a124bf484fb67ef5737c1e9c6ed81b87e4fdVirustotal results 29.03%Heodo
2020-10-15REP_AF3350923136UK.docdoc 1790c5fab1f40df300b33f400baa6f3981447142c4368a43e01a5b76b1beed3an/aHeodo
2020-10-1594474057746785.docdoc 275d247b675319a0e083b29b0e1c88b3bae28687e80b83a5b6db109ae72d954dVirustotal results 31.15%Heodo
2020-10-1569144969.docdoc f2749bfcb47ccd5ca2d9a1a0707ed06064ceb9ad0549c3bbff8475d01668d9b5n/aHeodo
2020-10-14INV_PO_10152020EX.docdoc 7b075ad4950850227bed02d8388e00fb244191c6f5dc0af216109799e512aa5bVirustotal results 29.51%Heodo
2020-10-146I9EU2RI578G3MP.docdoc 9c89c629514bf2387f6c00a5c10903227b923f18741a52982877996be1ea5811Virustotal results 31.15%Heodo
2020-10-14CIY_62883288.docdoc 0d6731404ab523678e4e70272959a38c04c12861e5d94284b88316c3830f0b9bVirustotal results 30.65%Heodo
2020-10-14BAL_PO_10152020EX.docdoc 766cbde7ddad3ff7d55d13146e76bdfdd1699d56ad5886d619dc2e74f2889d1dVirustotal results 29.03%Heodo
2020-10-14INV_PO_10152020EX.docdoc 9670351cda3385021054e49a74fab0df1f24d4e7d1344baddab81bfc1a4ae963n/aHeodo
2020-10-14PO_10152020EX.docdoc dc41f5064696331607d50440a2dc8ad1aeb74a70cc6d1fe6ff652dc36d48a51dVirustotal results 27.87%Heodo
2020-10-14CW5615369284TK.docdoc d8e8296e8032721412eeedd5ef9a8e7c30015865ebfa1b8661f447ff4fcc676dVirustotal results 27.42%Heodo
2020-10-14BAL_7361300335553741924.docdoc 092bcc5907112bacab3f65e2a0d921eacb8f10f66e7d5ba3346b672f7dfbf165Virustotal results 31.75%Heodo
2020-10-14RCEO_2UYXS2WW.docdoc 11ee22195d00d98a48b0b0bb49583f59637f52911410fef41176fc8e466f0c88Virustotal results 27.42%Heodo
2020-10-14REP_3993338081218639640610.docdoc 47d2663f2d97a5313bd52117865a0fc284bc8b3c8ebc176fb27d2ed5d60b208fVirustotal results 27.42%Heodo
2020-10-14INV_48124750243248197.docdoc ac443ee3def6c35248d2c3e6191d6d342a8f45654bab23f50b208062be1df2efVirustotal results 27.42%Heodo
2020-10-14FILE_PO_10142020EX.docdoc b356139efe926c881eff89255d16d5e8a0364aed9b05d34c491d8515710b3e72Virustotal results 33.87%Heodo