URLhaus Database

You are currently viewing the URLhaus database entry for http://agentsdirect.com/Services/Documentation/hpQDVH/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:438458
URL: http://agentsdirect.com/Services/Documentation/hpQDVH/
URL Status:Offline
Host: agentsdirect.com
Date added:2020-08-21 18:58:06 UTC
Last online:2020-09-24 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-21 19:00:03 UTC to admin{at}internetnamesforbusiness[dot]com)
Takedown time:1 month, 3 days, 18 hours, 57 minutes Bad (down since 2020-09-24 13:57:54 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-22invoice #04417.docdoc d264878eae29d3da022f38e67a38560346ba42cbb6dbebbf0e6c852c666fb1acVirustotal results 55.17%Heodo
2020-08-22INV_294106.docdoc 90f17bd24601e8b3707503a6768ee606d3133da51a9d9e539bf906a83fcdda4bVirustotal results 37.29%Heodo
2020-08-22Inv. 0035945632.docdoc b199113c89d1f14f205054c9a7cce7b661199224054e035b6f5044205dc27cf8n/aHeodo
2020-08-21Invoice #1130.docdoc 69faa30392d54cd8e6aa41e01b7e54516a7fe0be5745fe59594331d5c40d976bVirustotal results 33.33%Heodo
2020-08-210887732.docdoc 5e76cf07b30861c92504b7c0a38932ecb933cf087f2a2e5b4918b5b543177983Virustotal results 32.20%Heodo
2020-08-21Invoice.docdoc 30e001bf18864a20c17eb16970d0cee0f97d61b5a3d616267765ab51974e5492n/aHeodo