URLhaus Database

You are currently viewing the URLhaus database entry for https://agaazclasses.com/mail.agaazclasses.com/Documentation/mex0qcc5ao/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:494140
URL: https://agaazclasses.com/mail.agaazclasses.com/Documentation/mex0qcc5ao/
URL Status:Offline
Host: agaazclasses.com
Date added:2020-09-14 10:49:07 UTC
Last online:2020-09-14 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-09-14 10:50:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:2 hours, 30 minutes Good (down since 2020-09-14 13:21:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-14REP_VMO_090120_ULD_091420.docdoc 506bd0bf18d33b2e92b6638ec09ed0af6dcedffe870c41063f7845695e19fbc4Virustotal results 22.03%Heodo
2020-09-14BAL_01790376872569.docdoc fbb786eb4a0f0a9ecf9da92977d330921554d0c4cbdc1218de3641c9a9a16933Virustotal results 26.67%Heodo
2020-09-14686487590825564.docdoc 44dd298e5761ecfbf28b770c3adc34854679aca9c88565aef9e0f7d426749cf9Virustotal results 24.56%Heodo
2020-09-14B_80478081.docdoc bed57dded8f474e1685273acb47e279b76b699d0e2c44ac0f299ee924329f3a1Virustotal results 23.21%Heodo
2020-09-143D2UIX4SMI3A1DKB.docdoc 0cc20101093fe0717a459f14250ba02273813050342e588fed50e77c5b9e52c7Virustotal results 23.33%Heodo
2020-09-1447055851.docdoc fa69858e237719a046347129a4fa0d2bad1890e1843c54a8e5d71568337ee2cbVirustotal results 23.33%Heodo
2020-09-14WVPJ_55641878.docdoc 024ff9ff62ba78ea622ddcaaa68aacf0cb62fc53c52caa27db4e4cbe4e413a89Virustotal results 23.33%Heodo
2020-09-14DOC_UR9806539318GH.docdoc 80d8e37e856ada6bc31bdd15d3ef46e47cf2163c6394c78aba7ee026b55a6b2bVirustotal results 22.95%Heodo
2020-09-14E_NA96DZ86IXJT7.docdoc 3b211810dcd8176df286ff6d29407b15b8977014c8a22899ef51874995c40462Virustotal results 23.73%Heodo