URLhaus Database

You are currently viewing the URLhaus database entry for http://uagritech.com/cgi-bin/a5G/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:973776
URL: http://uagritech.com/cgi-bin/a5G/
URL Status:Offline
Host: uagritech.com
Date added:2021-01-22 08:42:05 UTC
Last online:2021-01-22 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-01-22 08:44:05 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:14 hours, 5 minutes Good (down since 2021-01-22 22:49:43 UTC)
Tags:emotet link epoch1 exe heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-22OflNBE5gUr0axuEu.dlldll 58732dac726ef318569cb9cbe21371de46bee4c87090a61cf1bdaa591b9e0db7Virustotal results 36.23% Heodo
2021-01-22ohmkRsa3FX.dlldll 0b4715beac854bbb23f2bcaa358df2e75546fdb965f7bf43dee03676dfffe930n/a Heodo
2021-01-22eVmnV4y8.dlldll 44fd5351894837ee85cf8250b9339a413d867bc2df3ac8662a4df6f7c1ad8f74n/a Heodo
2021-01-22Fsasvet7QFwCcQS.dlldll 0bcdc7db8504ad79bbc4e79ae00e5af6a859048875c6eb283e282d9d49e40c12n/a Heodo
2021-01-22GSdswuuHIuHNloge9mh3f.dlldll 3a5c550ee81be161b93f7a52c46cd0bc1363f285d5aacb4f73c394814aa32c68n/a Heodo
2021-01-22trXx8OW.dlldll 7e8c0752e1f39c51f18171fbebdbfdb47404aa47cc7cd3f806ceac856d6ab33cVirustotal results 34.78% Heodo
2021-01-22fBsbdO1ghgQWoTboPyX.dlldll 5e4fdfc42c70de81eae02b59887eeac2c6049852ed37081521f97b6d6d31d667Virustotal results 34.78% Heodo
2021-01-22rOqMNaxIev99.dlldll 3c537931abb34616a500f34311a280540e505d2031d42378456adb7aafd79b41n/a Heodo
2021-01-22NORUDHSLuVlGej8h2WSOZBx.dlldll 13fe2cbc4d844dccf0d1268879d7d157464ed8d8a4917adbb882451f7626779cVirustotal results 35.29% Heodo
2021-01-22oWlnIS0RQXGFZXfqljUj.dlldll 3048a9b2947439ef76185217b531277e2b24e5c9f5895abb1a67fc752b206906Virustotal results 35.29% Heodo
2021-01-22cOIImcdtGuLSnre.dlldll cf8db4c7857eaa6df75fe3ea3a41a08180fe9474a8d8d21e75ceb23ec6850e24n/a Heodo
2021-01-22lCoE2awwoJy43I0uMK3.dlldll 9151ca3bb95144cd2add57158c45b6c089f7019ba18701ad09aaaf0a90ee1b42Virustotal results 33.82% Heodo
2021-01-221GuWBhQagznNdqIm.dlldll 87986258d7fbd32ddf23ddd9e15319b6171deb12ce4e32a821a81b535715a89an/a Heodo
2021-01-22tLqVkIYbhiNnxunVAR8iTH.dlldll c6a64fb40908e1b60189f0ce2fb861a4251a1b39265787b195a55e597a33158cn/a Heodo
2021-01-2224.dlldll eda1a91065b700ab348e700e107b1c12aa453e0f5f117541d8a5df575812133bn/a Heodo
2021-01-22hKlUvi8birq9v3Cg3rf.dlldll b5cfff17583096c814ffecf96d837387db12e73d1b7b7ff8fb191514116fa47aVirustotal results 33.82% Heodo
2021-01-22jk5.dlldll dc97a110fa270a336720d0c06ef0d66674117f4ec02655a7827ec91976377e04n/a Heodo
2021-01-22yHp0l.dlldll 28ce10850f5a13943cd6905748b2653156f90c1b02aecd1d1a4981f66a51ffabn/a Heodo
2021-01-22CUuipU0BX0Z144KGq.dlldll 8ed6d766d2460acdf4e864cb7d7b3b143be98b839493dec136214eaa6c39b734Virustotal results 35.71% Heodo
2021-01-22YxoknLcfsqHqk.dlldll 59f04909e11a71c2762d54311a74242cf0256d81970a44cf99709fb032b34a92n/a Heodo
2021-01-22a76daV8wJOAUCgN.dlldll a10a8fd41816982d99a367d3a4fedfe4cdd29bbb1d8dde18733f5295c27d3a53n/a Heodo
2021-01-22CyzwKUG7w8jxM6uxUUy.dlldll 107d1c4a449c90d70176ce55bf90539164bd9458fa74b5876df73d97426fd75bn/a Heodo
2021-01-22Fgw9xSOOZd.dlldll 6efdf8b75115e8c43c65a8f4dda951c9a76f1b7501101aa2b39aac1b811809c0Virustotal results 32.84% Heodo
2021-01-2282wONEDOtZMTR.dlldll 4aee3f0b3ba7afc3f21da9dc0e0e848358954bbee41cbea2e53017a4c23e6997n/a Heodo
2021-01-22sGeMh.dlldll 7af14ef91a6c9dd048273daec9c95822a765dba1a92f327d2004565352152d96n/a Heodo
2021-01-22lMK.dlldll f5a2ec7716664ae860577125e6e304b393e655a69cdd48c93387c0ec08cc98d5Virustotal results 31.34%Heodo
2021-01-22Ci8CqGoCYmpg718Vlt.dlldll 4f0aebbe2bd0308a5f20f96491a8c87875b2373da050bb36f8b9fc3200dc8215Virustotal results 30.43%Heodo