URLhaus Database

You are currently viewing the URLhaus database entry for http://agtrade.hu/images/lkUWxxUTK1uIUxqUpAiPCB/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2123338
URL: http://agtrade.hu/images/lkUWxxUTK1uIUxqUpAiPCB/
URL Status:Offline
Host: agtrade.hu
Date added:2022-03-30 22:33:12 UTC
Last online:2022-04-06 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-30 22:34:06 UTC to 1b{at}1b[dot]hu)
Takedown time:6 days, 19 hours, 30 minutes Bad (down since 2022-04-06 18:04:14 UTC)
Tags:emotet link epoch4 heodo link xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-31ZJ-955994101.xlsmxlsm 894658b992050ab6d7ee061f083a48264ce56c1b4fbc5ac87c142765405a47f7Virustotal results 36.51% Heodo
2022-03-31ZOO-4188119.xlsmxlsm 53ef2d3a553342c46f5d3011cb07634e1f02b36dae99808e47dd459dd384e388n/a Heodo
2022-03-31PBX-409134828481.xlsmxlsm a1057f814e603d7b7ff7b711305cac0ef15e48b78499802d411424a19ee235f8Virustotal results 40.98% Heodo
2022-03-31YVS-44705079137.xlsmxlsm 5fe0d5c74d36af2db670ba08c72837740a66a82a2e8f0b206468474195578366n/a Heodo
2022-03-31UC-0600319.xlsmxlsm f88eb7101fdc0fe20190969ec3bb4651bf4f270d9a9636d6c1e1a84ae46a9cd6Virustotal results 37.10% Heodo
2022-03-31CUT-1529095520016.xlsmxlsm 30deb7a7086f74317285271a2e26e40dc43b461a1a77c77480ea742b02cbe51fVirustotal results 38.10% Heodo
2022-03-31ZPH-582054429614.xlsmxlsm a43da1637de01a06d72a9d09981de5132b8bd971844704ee9fc7c5e07450a49dn/a Heodo
2022-03-31HRR-098612558005.xlsmxlsm 61ad9b2b8c9707a14412bf30d2e17c11d75dd548e841d9b4eb6299ca1e0456d5n/aHeodo
2022-03-31QKT-53327529.xlsmxlsm 0c71f0ce426be3dfeacb36cfb08349362327fa6041d1669a1d2ef8b1110bfab3n/a Heodo
2022-03-31MZW-377796542977179.xlsmxlsm 5c682f8054f1b9bb175d9a5784b8fd5bc06364ddf2b802d9aa5fa0abe6cb3a33n/a Heodo
2022-03-30QSY-10725568651.xlsmxlsm 24499993a94d9888bcdc8a5b9c58aadb86dbd363efdfc2fe1996d98dba57bde8Virustotal results 39.68% Heodo
2022-03-30FWX-186788422764759.xlsmxlsm d736bc77cb744076e6985c5b54fe1322f0fe2407f1e3e3fabb539ec8bb8d5014Virustotal results 35.48% Heodo