URLhaus Database

You are currently viewing the URLhaus database entry for http://www.agretto.com/Template/ziasuz5w8pS08Gm2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2087706
URL: http://www.agretto.com/Template/ziasuz5w8pS08Gm2/
URL Status:Offline
Host: www.agretto.com
Date added:2022-03-10 09:24:13 UTC
Last online:2022-04-07 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-10 09:25:17 UTC to noc{at}vt[dot]com[dot]tr)
Takedown time:27 days, 22 hours, 5 minutes Bad (down since 2022-04-07 07:30:31 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-02qudLRRbxLCnMPUmk.dlldll 6413a4bef83ece42dd5e1dd942d9e71801012962a5664863ede18c5b86e9615dVirustotal results 68.18% Heodo
2022-03-10Y5uxufuBgrHXsF.dlldll 3b10a2468a995e3aff1f16cf672dbe83d5da155d7f6c673f0026c73cac7dbedbn/a Heodo
2022-03-104iAds.dlldll c07abcdb5b600d16899a64a5af008157527cf9f26af743502bd6a64342ad510fVirustotal results 25.37% Heodo
2022-03-10wzhyxr5sGff3VGUmvt.dlldll eea0d3c04b489c311d095e37793e53d6dff9d61c5181e7874a546dbd3b3d61cen/a Heodo
2022-03-108gDY95Uec5jhcM0Hqf.dlldll 72c2c8dde61b7f9fe92f0611537d99e87e5599f94cb97eaae4015a243331e2ffn/a Heodo
2022-03-10OBeB.dlldll 468fcb9c783a64c11720203d26e109f112389f6b883493dd9c02b65dc2f0d38eVirustotal results 25.76% Heodo
2022-03-10W1gfwTg9m0.dlldll a982a60aeb5e4a752e796c6fbff42c277bb2a39c6a0d660cc4ecc4e497b3c4f5n/a Heodo
2022-03-10Drqg5E73enaHPJ.dlldll cd1c423739006905915067705522c1ddf8f5486a841b30a6ebf732783115342aVirustotal results 22.73% Heodo
2022-03-105Kcpbx4bPr2S19UpH.dlldll a1581258aaa7098bc2fd08c2f6d127fdef48c07750492eedc077c817b1942b71Virustotal results 21.88% Heodo
2022-03-10u2jM.dlldll 24ba0ebcaf1d0e27b7956429c634cd8606818f403f4113ebc14abbf350249833n/a Heodo
2022-03-10mLl2LqeRTnyaJQb.dlldll 38c058b408741e7158ae633fe690c98998bc95536f2f08c1081e11adf3d67da5n/a Heodo
2022-03-104RdySINT.dlldll f8e6e7ec666aa5174a4cbc465eb5aa77370ae7887e19a790cbc82ca0c1667eb2Virustotal results 22.73% Heodo
2022-03-10HAV63922PIp8EsJTB.dlldll 7bbef188d310cf28ef408016da5213a01482b1f5ebd497b12dbb33b275e6ed92Virustotal results 22.73% Heodo
2022-03-10x3uO32q.dlldll f11f01eb0c4cc226adbb3e27cd9e017891f98ba50e46fd8a465924a4ea042764Virustotal results 22.73% Heodo
2022-03-10000javSrICl0.dlldll 3e2636ae227c2e1fcf9d711548bcded0b416ea51ce840c31b04b08028abd3be2n/a Heodo