URLhaus Database

You are currently viewing the URLhaus database entry for http://agenciaml.com.br/cgi-bin/dgAqqwwIeejxNozI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2166347
URL: http://agenciaml.com.br/cgi-bin/dgAqqwwIeejxNozI/
URL Status:Offline
Host: agenciaml.com.br
Date added:2022-04-26 19:24:07 UTC
Last online:2022-07-06 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-04-26 19:25:12 UTC to abuse{at}hostgator[dot]com)
Takedown time:2 months, 10 days, 22 hours, 21 minutes Bad (down since 2022-07-06 17:46:17 UTC)
Tags:dll emotet link epoch5 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-06-10n/aunknown c3e53275d6db5ed25d031b494d17efe230343b2652c4d7056767302a1c993ae6n/a 
2022-05-20DAZ30p.dlldll 72e221aa0346052ff7b2342c223829fd42305800d8a78913b12ee31879f636d2n/a Heodo
2022-04-27wsHybFcG3psM.dlldll 34ba8d9a2fc9779c2261e2c93856d5b24aa6c46048b3520bea0595258f0b9f7aVirustotal results 12.12%Heodo
2022-04-27SR4N.dlldll 382276028fb34e598d6326ca6bb6630e6aa7a94ad50e467436e26108b92327f4n/a Heodo
2022-04-277nGXENN.dlldll c80b64934514b0c8eb528bdfac8cc9df4ab9ba59dfa6a5b29e05414c5579972fn/a Heodo
2022-04-27gwAYvHCuXb5GQ.dlldll 50f5b7265032bb0b4ee1b40edba82a023140951fddaf93688642b831e3902007n/a Heodo
2022-04-27fD9uU06Oiq.dlldll 1d34a88eb39781bc579d6513021e890377ab938cb231d479e3ed9c493324afaen/a Heodo
2022-04-27G9cLrJXSVTOq.dlldll 994295ccfff691b6a66e326cf8ef8cb8ad7c092c9521b286da0a877c9abc630bn/a Heodo
2022-04-271tIBpYNZLuX0tD.dlldll 14d137048c524ffc2a16da7aac6b9c3ab2c22b61a05afac0a349703d0fca6190Virustotal results 17.65% Heodo
2022-04-27EcHly8ECUlc.dlldll ad775bad1e7f92a8b682b226f43229de5d410c4280df3212e6a689d128235618n/a Heodo
2022-04-27Zzvv6f79IxIB7.dlldll ed570d28fbea7613d288f668314dbf7ec94c004c918e3ce2e54b41fd734488a1n/a Heodo
2022-04-27Ot9yaX3.dlldll dbababb091a04258dbf1f9aed3f228f0af0e00284187cd288dd07e584f1f5024n/a Heodo
2022-04-27V2OHHHl7B8W.dlldll 4492e5795b535292c30e5ad2383b459332fe88127e39d733b1c17ddf5cf3754cn/a Heodo
2022-04-27EENyGClJVjVUoNUU.dlldll 559b195ca14207a2ee41ecfd3697c96a33b772229e59dc4e799660086d6c735dn/a Heodo
2022-04-27pe5O89PdG.dlldll db9b57d59022d7e0226c41e2f2c81c1cc76c5a36b9d51e3592e1932abd9da11fn/a Heodo
2022-04-27HyPEfkwtoaRlA8oj.dlldll 0e3d1eaf6f800896fecdd7cc8258a65767680c90a4c713ea1a5d79297ab91726n/a Heodo
2022-04-27vJraPpi1GfLgiYhE2.dlldll e50db6016abb6573f61c7ad3ce61c7068fb898ede09113f97538f4127a9da76bn/a Heodo
2022-04-27avSxZMgDSmJGxcf3A.dlldll 3bb36b43442d385dcb54527dd631dd14fd341efeb81b6a46949fb9ea750a6b75n/a Heodo
2022-04-27kIc.dlldll feee62c1cd968a4fe8e675f0aa13d718fe5e4919f7d1b8a0def98da3b181395en/a Heodo
2022-04-27ltOuJleAtzMauMPzN.dlldll 676e93ba8ce2d68ee493d75aa5ddd56f2a262ff47f71ff84f250e3883708276bVirustotal results 11.76% Heodo
2022-04-27u7KJTmmf.dlldll 50a641b9baa3ca95ef4e15154b7bc9cfdd5f29678e1594f0df9516c9ab411480Virustotal results 12.12%Heodo
2022-04-266ASYAaT9.dlldll 9291a46de2ad9db46ed52b2ea732cfb339932d2a1834e3e7d9d0668261292478Virustotal results 11.94% Heodo
2022-04-26lFgOAnetK41qI.dlldll 2477bfcbab9d91cacb1aad63555c5b7900bc8dc8b414ca90e14ac3ec6c3bfb41Virustotal results 8.96% Heodo
2022-04-26dONACCp4y9I77V16.dlldll 48f0224e35fa57129bc1706a108f97353d9f82bf452010604fbd4040c35dd667n/a Heodo
2022-04-26az0ULqacp3PcZwNr0z5.dlldll 19a1e949bb1a77ca3efb3a6529a796f99f7e175b684ad041cd0e0341cd348405Virustotal results 8.96% Heodo
2022-04-26ZDDq2m4b.dlldll 111d3dc61781fa95f18f679bca22701f3833e79f05ad5c6f21cd9164bfc64842n/a Heodo
2022-04-26cMfNAXvJElM76bhKB.dlldll 38c3c1b45253f1b26108c5b70bdb9a6dccff52866969004db8aaa533c0025f01Virustotal results 9.09% Heodo
2022-04-26nUb5fRxx6ZfZ.dlldll 42e7bbabe9a1d565d272a9b02ce110eef9552365cde4eecb516252d2a9fd2cd2n/a Heodo
2022-04-268k6nlEMHp1H6Ajd.dlldll 3d5f520e4c5958e673f1e17b27d4d0fdc9d42e2e41a1f1f07c57bbe20a70e029Virustotal results 8.96% Heodo
2022-04-2603BR9Cxwm7E.dlldll 40224682f9974acf9f0ad8b0895919cee90cf3a4ee1f4ceae4c4b841e5584266Virustotal results 8.96% Heodo
2022-04-26o7uQz.dlldll 25c2a36d3df3cdb05be707612f569c839091eccdf64948153f67aeb0110f937bn/a Heodo
2022-04-26av7shGg2nnfHKg.dlldll 84c72e8a68703645affea75a62ea29479598898abbdd5201f26f43739fb46ae5n/a Heodo