URLhaus Database

You are currently viewing the URLhaus database entry for http://paymentadvisry.com:8088/scripts/Receipt-427172.xls which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1455477
URL: http://paymentadvisry.com:8088/scripts/Receipt-427172.xls
URL Status:Offline
Host: paymentadvisry.com
Date added:2021-07-15 01:04:07 UTC
Last online:2021-07-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-15 01:05:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 12 hours, 9 minutes Poor (down since 2021-07-16 13:14:52 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/adoc e8b3cc9db466fd9d58cd85d6830585f466d1fdddeef1668008b3a140a55ad4dan/a 
2021-07-16n/adoc 19670f9153974c5ca0f866b19d356b9be253ff54812ada0a5d733240e6dc3031Virustotal results 1.69% 
2021-07-16n/adoc 150aba4a04a2d724cc710a1d7ca9d673e7c6f3c5f935766dfd47f32670394c04n/a Dridex
2021-07-16n/adoc d682ebd1c7364fba3154124cac44d5c9e5fc15b4eb7e30a6709a627854b3cc26n/a Dridex
2021-07-15n/axls cdcc50360daab3bda1f658df5d13f1c205c64cc628a06d4e887fecd84d7c7fcdVirustotal results 29.03%Dridex