URLhaus Database

You are currently viewing the URLhaus database entry for http://fasteasyupdates.com:8088/wp-content/Receipt-80228430.xls?tni=6zYO9UAyWznbeP9g7ph which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1454123
URL: http://fasteasyupdates.com:8088/wp-content/Receipt-80228430.xls?tni=6zYO9UAyWznbeP9g7ph
URL Status:Offline
Host: fasteasyupdates.com
Date added:2021-07-14 15:33:07 UTC
Last online:2021-07-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-14 15:34:04 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 21 hours, 32 minutes Poor (down since 2021-07-16 13:06:39 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/adoc 11488f6348e8f6e19d58b98e6a47c8f0b6bb8ef6a63ad381c71b7809a6e03ef7n/a 
2021-07-16n/adoc 4c2ca5d640ec8f65324f654e28b2ea5597540f1f5a998d31c1f4fe7c50fee76an/a 
2021-07-16n/adoc 63f27463089b044ea30e107b7e70a7a361cb39f7a21c76bcb492dcb18eadd993n/a Dridex
2021-07-16n/adoc 8bbb426f52bced46200f4a2b99e317722a8334f59d77cf9d44748b9d1132d395n/a Dridex
2021-07-16n/adoc fa9d01cb022b940f822006acf5d8a33677d2d148e4f380daa9ca4f57d78d8402n/a Dridex
2021-07-15n/adoc 8cfed8fef909247deabbe4a7fa4e79a9863bec1ee7bf30e05afc292a16f46fffn/a Dridex
2021-07-14n/axls 92bab194eb8d9e8189b184caef04bfc4e8b375ec095cd027d94a5fec73747e53Virustotal results 26.67%Dridex