URLhaus Database

You are currently viewing the URLhaus database entry for http://agiletecnologia.net/site/jhtq-7rrmv-2764/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:290667
URL: http://agiletecnologia.net/site/jhtq-7rrmv-2764/
URL Status:Offline
Host: agiletecnologia.net
Date added:2020-01-17 05:59:15 UTC
Last online:2020-02-26 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-17 06:00:03 UTC to abuse{at}redehost[dot]com[dot]br,flavio{at}redehost[dot]com[dot]br)
Takedown time:1 month, 10 days, 13 hours, 42 minutes Bad (down since 2020-02-26 19:42:14 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-18invoice-IEQ449_512651.docdoc 2f90590da13be020cab94f6054224224af5d674bb07964796cbb051cef5dde3aVirustotal results 27.87% Heodo
2020-01-18Invoice_CMA94_87715753.docdoc d4d29c6cfffdf351ad541d65a634554e0a99a4486477bb307f318499af87904bVirustotal results 24.59% Heodo
2020-01-18Invoice-BQ82_34501590.docdoc c18f5e41c03d90485d087d382d3953e3ae125d732a5c8bb1684de08cd58d79bdn/a Heodo
2020-01-17Inv_IB24_773836.docdoc fa9e97722fc94cc65979bf0bac795c3e5c860e2b72dc977262c2b7641ab53acbVirustotal results 20.00% Heodo
2020-01-17Inv_2917_2746193.docdoc 92c85540c7e919439415aa82c133d50f19540ccf3d76526199af09ed1b2a69beVirustotal results 17.24% Heodo
2020-01-17Invoice_CD5_0124580.docdoc c1773292833e3d31b42687618328bfc2e893bc2262b9d3ddeda0dd585eb5446aVirustotal results 19.67% Heodo
2020-01-17Inv_W1701_533420.docdoc 3f227c11e8835a6cb877438bf4628c9b105553fa1fc681389fcf5bd5574dcfa0Virustotal results 19.35% 
2020-01-17invoice_TJAD5_67094416.docdoc 44a7800af970884939e0d1e420aa3f140610c62a0a1e7d207cc020b9971c6c2aVirustotal results 21.31% 
2020-01-17INVOICE GZ268_70578990.docdoc 8135652b106f2b85795db8ea0696bc8b19b68a1fc008345df6b797e19b88084dVirustotal results 20.97% Heodo
2020-01-17INVOICE_OOJ084_111047786.docdoc 127fbb144e09a37a3fb74478730d2c431fc0876897035497e7dce1c49d3d539fVirustotal results 20.00% 
2020-01-17Invoice_956_348049240.docdoc 50682122531706e8b035ce5b24ace8f3b0e7e50526937b524c4523e7da0adcdeVirustotal results 19.67% Heodo
2020-01-17Inv-QYP4467_64145481.docdoc 52a35085b05a7fac898644b7e69c83730e819e568480c29301e09e9a19dc2578Virustotal results 21.31% Heodo
2020-01-17Invoice_POBA36_7248715.docdoc 559a07cd9e86fcb6787310e586b5f97ad4ecd0cbfad46d213673d6f8c9618999Virustotal results 20.97% Heodo
2020-01-17Invoice OJP773_31280872.docdoc e09d6c6471feb40345f420439b9c6a3a12ad485be6d8be5a8568b50fcee2b422Virustotal results 18.03% Heodo
2020-01-17Invoice-D90_096343.docdoc c682de9b99812ab7c470a026d17e1060364b9bf4e1890d733b05ef312452f8d8Virustotal results 19.67% Heodo
2020-01-17Invoice_Y6157_15224031.docdoc 705c0fe4297531835d50b0458ac82dd33ecc2372332fa70d25d6f723ee898671n/a Heodo
2020-01-17Inv-YKT0_08243599.docdoc 7a51d9e976d8778788950f5c677c677cdea8a828a49b9306cee884e85d66c448n/a Heodo
2020-01-17INVOICE-20_753571763.docdoc e54979318c06a7cc3d8fb5f00d32d0fa2a169f8447a224ec8822749071c550f6Virustotal results 37.10% Heodo