URLhaus Database

You are currently viewing the URLhaus database entry for http://agdm.ml/wp-admin/EEY708951/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1984578
URL: http://agdm.ml/wp-admin/EEY708951/?i=1
URL Status:Offline
Host: agdm.ml
Date added:2022-01-17 21:18:04 UTC
Last online:2022-01-19 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-17 21:19:09 UTC to abuse{at}cloudflare[dot]com)
Takedown time:7 months, 15 days, 16 hours, 34 minutes Bad (down since 2022-08-31 13:53:10 UTC)
Tags:emotet link epoch5 exe heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-1874705537848748447.xlsxls b5abaa61ee5a2795808e2dc90c87c149ea7927be1431f1595fb1061e045b8657n/a SilentBuilder
2022-01-1714758979841496335935.xlsxls b9cf7499338b7ce6d879b0093cddd093f329e54f080335bc602f3b30f055978an/a SilentBuilder
2022-01-1797075821748391841.xlsxls 5edfa18d54052256d62cd14523eee828be94dbd74b83296ece55b13122e94c56Virustotal results 13.56%SilentBuilder
2022-01-175829945559610.xlsxls 5feb30d01fb35d5fde34eb531e533bbfe6870e26612f2b397214636aed65988dn/aHeodo
2022-01-172762670821405044071.xlsxls 5ae8846c8c7b641f282ee57e2c7e43ecbb26ef440b76a0fc3d4134df1c6e4867n/aSilentBuilder
2022-01-17376286076229.xlsxls 29709d03acee721410a55e3e7456f31bba930f697066acc6c5649882231cf288n/a SilentBuilder
2022-01-1726681445187.xlsxls b57b7792f2d74379892499f9a23972aed0b7206a9041b5e3b0720b2a683c0d53n/aHeodo
2022-01-1780245722142.xlsxls f3cd52a5a1168f54d3a94892a338e010ef91071d57091b9503805d3e880f83efn/a Heodo
2022-01-17JMFQ97742381.xlsxls 89693c1d61a868e13f8341fd6cb0251a7fbdce9ac109560361a86008f548c868n/a SilentBuilder
2022-01-17340718-73402.xlsxls 7ab8fdb32c73c5d578dfa7eb5fb86a309ba5aa7d830e43f7f3acbadc23eec71an/aHeodo
2022-01-17BX-85671.xlsxls 8976395bbc9ade87e7ecaf509860c9a460299dba5418b0c536818a7d14d5941fn/a SilentBuilder
2022-01-17918912561_7696.xlsxls dc1149a410dfa7ff3c58eb61f57fd39169b774f8ac21a9554e9227fbb1528816Virustotal results 20.34% SilentBuilder