URLhaus Database

You are currently viewing the URLhaus database entry for https://mardeibiza.net/wp-content/aHaYWvcBjxkC7LvnGBhalSVHPom1Uafa32cjeoYDh8sJdN6uIT8rbee9iE5/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:944526
URL: https://mardeibiza.net/wp-content/aHaYWvcBjxkC7LvnGBhalSVHPom1Uafa32cjeoYDh8sJdN6uIT8rbee9iE5/
URL Status:Offline
Host: mardeibiza.net
Date added:2020-12-29 12:26:04 UTC
Last online:2020-12-29 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-12-29 12:28:02 UTC to abuse{at}ovh[dot]net)
Takedown time:3 hours, 33 minutes Good (down since 2020-12-29 16:01:31 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-292TE1RK0.docdoc 66dee1c531293e20e26da0ffd7b7d4825876218dc4a90d537af904966fbb7db5Virustotal results 39.68%Heodo
2020-12-29TYV14NI85GGA40.docdoc c7991171d6070c5dbd364aac10be197a02acc9582d85ae29ecd5fd45ddc7da23Virustotal results 38.10%Heodo
2020-12-29KYPUGY.docdoc 3220a607cad214a83f7491a28fab782cba46277dad8762d709daf628333b2b4eVirustotal results 36.67%Heodo
2020-12-298RWCYCXBMK9L.docdoc 45d8bc6c35fbbb07e2a164434082d5659b1a53769f01d35cbae03741ddf981can/aHeodo
2020-12-29XY8NZX84V1R7NCN9.docdoc a2716d55c3b2823a856e3308aefdd3883d63ce417c4e6013858bf14c80f48b29n/aHeodo
2020-12-29VIRE0C5BX.docdoc 534741cd011d3d7a34c5c3c0dee6f721faec6a7e6f81720011c3f0d54556b0e8Virustotal results 29.03%Heodo
2020-12-29QLQDQAYNFH0OL.docdoc b8d8aad4c79c9b57697bac1666963c81e045f30d4a200e1be8458ed96f03871fVirustotal results 30.16%Heodo
2020-12-29SLEQPK3WGA.docdoc 2e5599c71028de6a5c1202946484ff5020f38bb282b78e69aade9c840c3e2f24Virustotal results 26.98%Heodo
2020-12-294XF5GNC.docdoc 768cac32a7e61598368fa17fcb6792ca6d504cfab9cdcd29cb406ced3a9675c2Virustotal results 26.23%Heodo
2020-12-297ZKRV5IG991676EQ.docdoc 66f81b626c6aa30847496544362040dc372b403ef6f0f66b0adc343843ec4a6bVirustotal results 25.86%Heodo
2020-12-297HDWWQ299OE9.docdoc 64391214b0c653eee052ee6002b08285719f04d563e2000dc6f82579923c3867Virustotal results 24.19%Heodo
2020-12-299ES7Q4Z40.docdoc d9b4e756834c3249baaa01674f9d0542b3cbe53dd174ca24beaab15054426928n/aHeodo
2020-12-29HFKYLPD9A.docdoc 93b5810b60939fdc63bc152dabb0723fd8505ca85acea04f6891fbed64a8e6d4Virustotal results 20.97%Heodo
2020-12-29OXSMIO7K.docdoc 4977173aed4452a0e0439de276d7912c6b6b2dca887504b0f251ab83c38aaa9cVirustotal results 24.19%Heodo