URLhaus Database

You are currently viewing the URLhaus database entry for http://fasteasyupdates.com:8088/img/Invoice%20471471%20from%20Quickbooks,%20LLC.xls which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1454922
URL: http://fasteasyupdates.com:8088/img/Invoice%20471471%20from%20Quickbooks,%20LLC.xls
URL Status:Offline
Host: fasteasyupdates.com
Date added:2021-07-14 20:57:44 UTC
Last online:2021-07-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-14 20:58:05 UTC to abuse{at}clearrate[dot]com,noc{at}clearrate[dot]com)
Takedown time:1 day, 16 hours, 5 minutes Poor (down since 2021-07-16 13:03:16 UTC)
Tags:CobaltStrike link Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/adoc 6a75360acc88e5678f378d0708e9c3c7c56b7a81e02fcc63e55c2f2dc3609800n/a 
2021-07-16n/adoc 5d2b30fd2fc74349fdee7aca2503d32a9a1d44a7feea492734dea4bb4bcb7e39n/a Dridex
2021-07-16n/adoc 26ff3d21dce75aac7bf63b982af8f7713ccefd4346a101447b1cfba4403bda28n/a Dridex
2021-07-15n/adoc c036bd955bd3c979d7fb47b55e19c47ecede0a287392c7ba46c61c152f6a1ee1n/a CobaltStrike
2021-07-15n/adoc ac4e06616ff6aad33b85c418c5771eecf08a36715ff42d3d914cec7963674569n/a 
2021-07-15n/adoc c5d98827cf57c27760bc5cb019ccb1ac1a84868deedc7d0c651246c3099f6676n/a Dridex
2021-07-14n/axls 049c1872e0355d768fab2bdbb1759527ff8074e0be5652f6fbada81d23f705feVirustotal results 30.65%CobaltStrike