URLhaus Database

You are currently viewing the URLhaus database entry for http://vol.agency/wp-content/report/380524ge/j6uw21q813909-85543-9o481vocacmavgc2/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:303057
URL: http://vol.agency/wp-content/report/380524ge/j6uw21q813909-85543-9o481vocacmavgc2/
URL Status:Offline
Host: vol.agency
Date added:2020-01-30 16:23:49 UTC
Last online:2020-02-18 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 16:24:03 UTC to abuse{at}kryptservers[dot]com,abuse{at}vpls[dot]com,abuse{at}krypt[dot]com)
Takedown time:18 days, 15 hours, 21 minutes Bad (down since 2020-02-18 07:45:56 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-01PAY_17064937889008566811706.rtfdocx 8ef3a86989c9654cd7b0914ab743459ad98702ea960612c66e331f858a791eb0Virustotal results 45.31%
2020-02-01DNU6Q1K7X.docmdocx da2dfdde77d319fa7d1a1326ca2ce99142a8d194e609eba08264875f442e240bVirustotal results 45.31% 
2020-02-01FILE_1XGVWUM.docmdocx 12bc283594bd2540d46f51658970e354cadec045dd90a541cdfd238fdc096a52Virustotal results 41.38% 
2020-02-01DOC_98873379.docdoc 33a89c876ed4c1f54ac3ebf60cd427562e652b39263734b693beb3be9e6c67ebVirustotal results 40.62% 
2020-02-01DOC_38P8WKL.rtfdocx ac59c732daa8085badba3321495b6415cec136aaceaf03e509380f2d2742866bVirustotal results 38.71% 
2020-02-01JED_020120_FNE_020120.docdoc c117593f754a9dafdfb9c3bcaf46d70eda6bedf7ee811038f00aad85aa541355Virustotal results 37.50% Heodo
2020-02-01VN1460731204LA.docmdocx d6ac1c0ee85cd1a5225863f4efa078bae13e3b4555885fc96d9fd47213a479f1Virustotal results 36.51% Heodo
2020-02-01UJ5646157184WC.docdoc bac8c7f92ba1d7ad83ad8ae1a8ef275549f05101769985e529e24ce364f052f4Virustotal results 36.51% Heodo
2020-02-01T_9816520511.rtfdocx 67014fca7bec38816b162f8568680c49b61d221b6f635322480b97f920b30e20Virustotal results 37.10% Heodo
2020-01-31J_HHG_020120_RBD_020120.rtfdocx 2ff7a8002b4398fe3ca4905a4abef5b229f8d8f3faa9aa284bf542bc9ad56188Virustotal results 37.50% 
2020-01-31FILE_CLV_020120_NFC_020120.docmdocx 1ddc62f513295211b5b3534a41fa4db90c57654edb852bbc2a3bea0051f1e22fVirustotal results 32.26% Heodo
2020-01-31J_CRILD16H.docmdocx 3f8f8f620cf256fc8c738bf6eb7cca17c556c295db6adbd62ce74649e37f555eVirustotal results 30.65% Heodo
2020-01-31DOC_61383810809984617201733.rtfdocx 14dd97e3653541ca32bb1cec005278756058eb08b4edd36fee7f407fbdbf709aVirustotal results 31.25% Heodo
2020-01-31HC4OW81PAINRIBR3.docmdocx 6712abf457713a6bf6d104218d20d5813ead4b4bdf9a0b13bf1e067467fbb1c4Virustotal results 34.43% 
2020-01-31PO_01312020EX.rtfdocx 017ff16f81777561b141163868aba16fc832f855ec617743feaca1d98b2e5f16Virustotal results 33.87% 
2020-01-31KMGE_PO_01312020EX.docmdocx b5907f242c6c308b4ddd0b60508bd5c4e923d0005d650a1790d25482120f8bc3Virustotal results 29.51% 
2020-01-31INV_OW2848760546WQ.rtfdocx 542ec6c1bd107f007a478590abc8e6c5e0419d13377d1fbabe68a4f685e6aa39Virustotal results 25.81% Heodo
2020-01-31REP_PO_01312020EX.rtfdocx fde981959b6b1118d50bf879509945fcdd62384654c0c29ebc296529e153210bVirustotal results 20.31% Heodo
2020-01-31494094979197.docmdocx 08644452115c41a0a6f8b3e3478c7c38b7545f7bfe05188bd958baab5c50fe93Virustotal results 20.31% Heodo
2020-01-31L_NA7327813087JT.docmdocx 64a731672001bc1e454a64d2eb8b19c05e5870e116e6addadfbc33a48423ccd8Virustotal results 20.63% Heodo
2020-01-31XD7I7OA2M4WNVRW.rtfdocx 12f17aa88c41cd66c648d4f19289192958e721c494829eb67962060967d804beVirustotal results 42.86%
2020-01-31ST_FC9741564552GG.docdoc 214d5a002c69788401e88128b4532c65e84c31018aadda1fdd7badc5bd1b16adVirustotal results 41.27% 
2020-01-31INV_U9PKSPLXDO1MXZ.docmdocx da7ddb46ecec831a2c5293164ee90fcaee314e6c070f201245cc15c1589e171aVirustotal results 40.32% 
2020-01-31Y_DNA_010120_RIO_013120.docdoc b2b0dc6852bea40e3dd6253292876a67f820441f13e9da1c5e2f415654694f89Virustotal results 41.27% 
2020-01-31INV_78967549.docmdocx 9c5de271d65d0f60677c42eca0d3ef7644017fbeb235ebf84a1bf90f0759e3d8Virustotal results 38.10% 
2020-01-31INV_DFZ_010120_BHV_013120.rtfdocx 6971378f1c7eccd93a6ab7cf3dd5ea551a5ca14cf564e121f883c2f364e46876Virustotal results 33.87% 
2020-01-31DOC_37728117.docdoc 3e3a86c471963a66202d7fb20b5db766f422c1576d1c0db97d3055e7760a56d3Virustotal results 35.48% Heodo
2020-01-31REP_PO_01312020EX.docdoc 1b75dd0fa245e88d26cb1ca67bcc5a5c0e515a1a61e11ecf77f962989f3072d4Virustotal results 34.38% Heodo
2020-01-30DOC_205209969812474.docdoc 54e129e6834af97b4ad21f3e8157eec8f08d3c46c4c49680d1b9a539429f58f5Virustotal results 35.48% 
2020-01-307508075859.docdoc 76483b424ad76c877f0c7f4e62405edc7e07a17978fcfb4c2b9087196d568a1cVirustotal results 37.10% Heodo
2020-01-30YLRE2L9S7VW1.docmdocx 9d7903dcb84d56c7bb6712b573683c2ef0302a29123305fedbf29279c6e9815cVirustotal results 36.07% Heodo
2020-01-30053289221945041.rtfdocx 1989a1ba92b07553f5089bd063e76edafddfcd4c53774fc697c8835d7f10adb5Virustotal results 34.92% Heodo
2020-01-30FILE_DIS_010120_KIF_013020.rtfdocx a791d9f0b3f74aa0c72a41cdb4e3b2fd1e50a7fe4724e7f11a2bdb11a2274768Virustotal results 37.10% Heodo
2020-01-30ST_XE9364727511UC.rtfdocx 3476381f8a76d5131391144afc9072ad6ffb33c7cdd6aeeb721600c5743992e0Virustotal results 34.92% 
2020-01-30PO_01302020EX.docmdocx 40520f763acb971389175978656d2f9c5d0b79e32f996b497f7748a0891ce742Virustotal results 37.50% 
2020-01-30SW_PO_01302020EX.rtfdocx 4dd8ce5c1032dd07f35ee5343020d8473444a5072593bb347d60255116b0a915n/a