URLhaus Database

You are currently viewing the URLhaus database entry for https://agernatura.com/cgi-bin/invoice/gn7m7n5b3p/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:529804
URL: https://agernatura.com/cgi-bin/invoice/gn7m7n5b3p/
URL Status:Offline
Host: agernatura.com
Date added:2020-09-16 10:08:08 UTC
Last online:2020-09-16 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-16 10:10:40 UTC to abuse{at}comvive[dot]com)
Takedown time:13 hours, 41 minutes Good (down since 2020-09-16 23:52:26 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-16ZBW_090120_CDR_091620.docdoc c95b5dca5208b5d4dea488991b6cae5bc1d6e7686af278285ea7e77a3b71cd03Virustotal results 23.73%Heodo
2020-09-167734805537383.docdoc e247f4f69c1be4c95bdf6687e2ae1adbd1635c126ace3b544ad989024da5fb3cn/aHeodo
2020-09-16FILE_PGK_090120_IBV_091620.docdoc d1df096853342d0030f71b7be3c608ee35fd1c81bce971a45e00b001a7d85d3bVirustotal results 25.42%Heodo
2020-09-16REP_25809731.docdoc d7f12b14c351620ca64769a126560507c4746cc966510d04d0fa882e521128c4Virustotal results 41.67% Heodo
2020-09-16DOC_BKI_090120_EBI_091620.docdoc 37af168ebcdcec12d2835ecc3a569839ed4660717927ae3ab0cc6a4b8a733012Virustotal results 38.98% Heodo
2020-09-1699664131.docdoc 1e5ed60832baaf0e362870373615cff90279bbbc4e544c76224f7528687276eeVirustotal results 37.29% Heodo
2020-09-1628933896.docdoc 278fc88598a0bfe49be55465fdb975272c6315e3845d604caba7631cc5f32595Virustotal results 38.98% Heodo
2020-09-16REP_94792396.docdoc 9c5ec196eabe90d83815fe7015b5334c7fd6bbd350de085a69e022a0fc32ad8cn/a Heodo
2020-09-1630980127905042794814197.docdoc 89e280d00eba5184867b52270ea583f8bda9161dcb52921411e456747741e571Virustotal results 38.98% Heodo
2020-09-16PO_09162020EX.docdoc c88d8beb44c5609d538cae9b2bba76ebe5b09aefbb561fd2801356e147f179ebn/a Heodo
2020-09-16BAL_IB3XBF4MY00JGXKU.docdoc 32eec3ec66c12e442e79982e74f902432abb353ca97501ad43d92c300a1fbc4eVirustotal results 39.66%Heodo
2020-09-16X_WAH44TNAI.docdoc 3cddfe22684c82c3eeeb0d3c0c8745719dcd417db42c4ea6774c9a10d1a88f3bVirustotal results 38.98%Heodo
2020-09-1654299552.docdoc 962d453203d41ae26badcb1083a24aada6ccb51ae5ef7a416d850a0b8cee6c90Virustotal results 36.21% Heodo
2020-09-16O_SF3349779882SV.docdoc 6820256b4c1c4c5b50146126f828d2317ef12e023043a390611fe9b036cfe638n/aHeodo
2020-09-16REP_FPN_090120_PPI_091620.docdoc 54f3ff0a6c12843bdb1b448362320aac7421e7a1c1a210779dbb9c57ede15a75Virustotal results 32.20%Heodo
2020-09-16INV_NG7DT67QB.docdoc 0c982fd7e6da85d772a410a46a6569667df380d6fd19d4c597ca1a0f30c140acVirustotal results 32.20%Heodo
2020-09-16DOC_PO_09162020EX.docdoc e5c37ebebf58e59d2a4855aa35821a501f6412b3960604cb50fd0d14009888e9n/aHeodo
2020-09-16PO_09162020EX.docdoc 5aa5a3b76812b8b3edc3768f494fd3550f5088d44872ac9f4bbabb99137427f1Virustotal results 25.42%Heodo
2020-09-16INV_PO_09162020EX.docdoc 39031955d734e86e67664eee812819b699a9bc4f869cfb4d28db7f4c99cbdceeVirustotal results 30.51%Heodo
2020-09-16REP_89922350713921067364195.docdoc 0e0913f7c913e70406fdc7b5e47f2455d7152c4e461770cc1b9bee581491fab9Virustotal results 25.42%Heodo
2020-09-16P1V4W5C2QNDJOT8.docdoc ff707add1c74a6d7884de1fdbca86c891861883fccab90f4ef5f97130f95d825n/aHeodo
2020-09-16NNCCDB02KBJZQ17L.docdoc ba11cc626e1527c8dec4bf3fe20af2a338030cdb646252a4e170d19512d19d89Virustotal results 27.59%Heodo
2020-09-160IAHWOBP.docdoc b3f649438cba7dc8f34dbdea69bb67a356906ead944752b8abcc4fcc23b737e6Virustotal results 27.12%Heodo
2020-09-16HKC_MW4030085062OD.docdoc c24eaf2c7e9192b22bdb558cdcb458e6de607d17f373c4d46d92561b2312f1d0n/aHeodo
2020-09-16INV_PO_09162020EX.docdoc b8d558c1ac20808b0809fcfa0c5a017da7e300736b6dbfee52ed1930c7b19a08Virustotal results 20.34%Heodo
2020-09-16BAL_LFZ_090120_XSU_091620.docdoc 4127d459a04c32375faea92c1b93077f9a79c1c7ffff36dd050303fe2c295bccVirustotal results 20.00%Heodo
2020-09-16REP_PO_09162020EX.docdoc 1d74eaf6b6fc4ebf83fa4325a27d62ee8f999df2c277d2357b777471f1b35bd4n/aHeodo
2020-09-16DOC_NMJ1E5O6.docdoc feb760d598f3b0a810214edcedd3e0ccefa48d12ba8c1dfb200aea8d382b4070Virustotal results 18.64%Heodo