URLhaus Database

You are currently viewing the URLhaus database entry for http://insiderushings.com:8088/styles/Invoice%20865978%20from%20Quickbooks,%20LLC.xls which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1455470
URL: http://insiderushings.com:8088/styles/Invoice%20865978%20from%20Quickbooks,%20LLC.xls
URL Status:Offline
Host: insiderushings.com
Date added:2021-07-15 00:56:40 UTC
Last online:2021-07-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-15 01:01:02 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 12 hours, 4 minutes Poor (down since 2021-07-16 13:05:59 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/adoc 0f9904c4d6624974988691957365a409b05e31ac7e11785555bc482afc0a14e5n/a 
2021-07-16n/adoc d442ab2b74829a0bb2e5a60f940766702b7899d986f547085f0b1b72abb16832n/a Dridex
2021-07-16n/adoc 734bf917afbe9e9bba16d263c840855f5bb3d60ec0c1085ef98e2a80b50f1c95n/a Dridex
2021-07-16n/adoc 5d130b1f2de3db632c9a2a6dce9dd2518f8a4b137368e59e46d1d99dc205cbc5n/a Dridex
2021-07-15n/adoc c0e617fe0793df016b0855c6f7b2d07ff01443564434ac01118087a0bca3da23n/a Dridex
2021-07-15n/adoc 7a4809fed1b31b56e69e9ecf232f239993ebdccd9b3af40c1b9e9d2494eff437n/a Dridex
2021-07-15n/axls f1406094b5aaea926ba2700a23f6c7924c1735b1c69cd5dd30fccae1cea72595Virustotal results 33.87%Dridex