URLhaus Database

You are currently viewing the URLhaus database entry for https://aglomol.com.mx/cgi-bin/T9C8JGTK/8uf56c1707/9tb5553584nswsnz5yandch9/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:422995
URL: https://aglomol.com.mx/cgi-bin/T9C8JGTK/8uf56c1707/9tb5553584nswsnz5yandch9/
URL Status:Offline
Host: aglomol.com.mx
Date added:2020-07-31 20:30:06 UTC
Last online:2020-07-31 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-07-31 20:32:07 UTC to arin{at}ntso[dot]com)
Takedown time:2 hours, 17 minutes Good (down since 2020-07-31 22:49:07 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-31INV_8994068648.docdoc 94740399d4f82347d284463c29d6bd05a288b65a122efd5f8d8b379ab5979a80Virustotal results 49.15%Heodo
2020-07-31FILE_62280318.docdoc 4834d43a503e5a10693dcc514692016c26b9084f17b258a3505a4e44ac893db7Virustotal results 47.54% Heodo
2020-07-31Z_JC6702821671SF.docdoc ad5d63edee98350ce19edb0c144dd79079865cf72f2e092b91678a77835f10c8n/a Heodo
2020-07-31SK3195058975DY.docdoc 1e4b706d611f935dd5aaac2b97e921c9c1df152d9dcf98127840b7c0e60348eeVirustotal results 47.54% Heodo
2020-07-313504203768686331.docdoc a3667171b7c4b632d7241b65287398007d28c018697677f2bac729d91af17b06n/a Heodo
2020-07-31RX_404561402750074.docdoc 7ba9d770d237bd49b68182d551c5f73e2f7c00bbcaa22bf9c1107ca4dfd2038bVirustotal results 48.33% Heodo
2020-07-31PXDYRU74WM.docdoc ef664c354f361e0467d36c08c3bb3563f1408bd30c865fc1efd73237b7a26e6cn/a Heodo
2020-07-31BAL_CX9RGPFRJVJN4.docdoc b8b1360e448aff874ebb4f439250be3f18319ab9445186d361fa1afc109a639an/a Heodo