URLhaus Database

You are currently viewing the URLhaus database entry for http://agentsdirect.com/Services/attachments/hqobn8ylwy91/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:426076
URL: http://agentsdirect.com/Services/attachments/hqobn8ylwy91/
URL Status:Offline
Host: agentsdirect.com
Date added:2020-08-06 07:08:11 UTC
Last online:2020-09-24 12:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-08-06 07:10:03 UTC to admin{at}internetnamesforbusiness[dot]com)
Takedown time:1 month, 19 days, 5 hours, 13 minutes Bad (down since 2020-09-24 12:23:13 UTC)
Tags:doc emotet link epoch2 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08FMD_080120_EDE_080820.docdoc 00f4cf37659112079af518ca20cdf2cd80bd41a63c0bcf4cde328cd476fcd952Virustotal results 40.00% Heodo
2020-08-08FILE_MZM_080120_FSS_080820.docdoc 5d405365644b1fe72cf334ce68fed86b295cff563010c02d0035a001fea71ce6Virustotal results 37.70% Heodo
2020-08-08KDJO_3130159640679.docdoc 99c91d2f1ecbee44baa8f5c9f3bfc0e2d7d11b63cac8d777f6dc1dd3b1c2aaa8Virustotal results 37.70% QuakBot
2020-08-0765181618672107216.docdoc 41ef6b4c13a98f92f61c7a14e9619f68f166ea699a7ea6eee9a1bf0165512f81Virustotal results 36.67% Heodo
2020-08-07FILE_TQ5U19UM.docdoc 7b833e4d843c70240e38d8a42213d19df971ac00c2265be02c724b9bf44493efVirustotal results 35.48% QuakBot
2020-08-07KWCG_0623412011787932.docdoc f3118ed881772d4b5b9ca95eb3c2335bfa2f0dc423dde055f9c2361dd35a58a8Virustotal results 33.87% QuakBot
2020-08-07REP_VF6767484024HM.docdoc ceddfbaca020f738159a9f23ff626356400ce8a3dcccb86e056e207a1580543aVirustotal results 30.65% Heodo
2020-08-07DOC_36775990.docdoc 75818bb582259a28ca9b133e8917b0361a46fb555fc72e8989ee164373833246Virustotal results 29.51% Heodo
2020-08-0758729496.docdoc c1b804534f3c90cc15a7a9be7a259edd9d4de813a627e84db243e8b462b236c6Virustotal results 24.59% Heodo
2020-08-0774013660.docdoc 83acfc01aed8937375c8bc98733684caaa595766301ca229d41af7b2c3966921n/a Heodo
2020-08-07FILE_PO_08072020EX.docdoc aba867cfd146ec0ffdc261441e6e1f83162f29f2740beb837322498fbca0b691Virustotal results 24.59% Heodo
2020-08-07FILE_04100994.docdoc aa1cebda0a54ea6ea94341f378ef9c0a40c16b9ed1906b2c51e22b3ff3780383Virustotal results 24.59% Heodo
2020-08-0752260967.docdoc 1b35831b48e2ee75787762399f5dd5f79f6bc437bebf24319d85d740c8a693beVirustotal results 24.19%Heodo
2020-08-07BAL_FR7663115167LV.docdoc a7dfc7a90aff0ded33424138ee9d5069525c5f635e7fed5a860036ebf5a9401aVirustotal results 35.00%Heodo
2020-08-06IZV_080120_KES_080720.docdoc 2ee0a294d681306e15289470a69d09210966baba4b985463131eaec15ea3cbcaVirustotal results 26.23% Heodo
2020-08-06INV_ZJY3N1E605RQ69.docdoc 1bc51c6d408fca55b1fe9c16eda0c5c56fadaab475a80035f595474c189494f9Virustotal results 26.67% Heodo
2020-08-06U_382705017.docdoc 6404a5a49751db7e1c82b5bdffadd5171eea2b5a4b43f9b77afb50b2095df09dVirustotal results 24.59% Heodo
2020-08-06FILE_21968273.docdoc 93c870008317b819f86d45c0c3e0075eae202d632a8c5a15afafda0e60ba9551n/a Heodo
2020-08-06DOC_59312440.docdoc 05c72e97f5d458c6490496c4ac646b9555bc470d63b6bbea42875e5adb1a1549Virustotal results 20.97% Heodo
2020-08-06BAL_VNKOISR0PGBG45.docdoc dcf13e777cc81ba6dbf2ebaf5747e5de599a4de2aefffe544b7f52c9e0188827Virustotal results 21.31% Heodo
2020-08-06LB_HT4528520921YS.docdoc 9dbbea4ddfca73dcd4ca58f1d91ab60f14bdf65a70097fa3e5ac5ca1f6b291e3Virustotal results 19.67% Heodo
2020-08-06766739538301060297194417.docdoc dec3471e2cdcb7c10cecb9ac4f4ad90866f0725191065c12f80d585331601005Virustotal results 16.95% Heodo
2020-08-06BAL_3833191153706715870.docdoc 304614d4a80ddcf70ed20283f9b4837eb8a9b65f318b47acf092be17ed214933n/aHeodo
2020-08-06ML_07031937.docdoc 760332e0cc50301ec3479486479a525dab98e541c7400d07d8158dbf76135b4cVirustotal results 19.67% Heodo
2020-08-0693607194.docdoc 1b3d99ea038b8ab01934e0ca64e6025bc2ce176db72e2cabda3537ca09991469Virustotal results 18.03% Heodo
2020-08-06INV_99565390.docdoc b05b7a5b7251a3088a61d778b36b9806d3c57425a15891696e1f447a258f08ffVirustotal results 31.15% Heodo