URLhaus Database

You are currently viewing the URLhaus database entry for http://insiderushings.com:8088/wp-content/Invoice%2084525529%20from%20Quickbooks,%20LLC.xls which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1455478
URL: http://insiderushings.com:8088/wp-content/Invoice%2084525529%20from%20Quickbooks,%20LLC.xls
URL Status:Offline
Host: insiderushings.com
Date added:2021-07-15 01:04:09 UTC
Last online:2021-07-16 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-15 01:05:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 11 hours, 57 minutes Poor (down since 2021-07-16 13:02:56 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-16n/adoc e822dc32f94d6dde7c01994d7ca92c7ce8a1098190da6c840c66131f6e8acf5cn/a 
2021-07-16n/adoc a9584d09fbd3e6d23eac6c9f2809d1d8205ac044d282c2e2b9fa159786e06dd9n/a Dridex
2021-07-15n/adoc 848e745ab12fc249fac53c1170b5caa1e0d63d87b8af5054fef3aa53526c12aen/a Dridex
2021-07-15n/axls 2e0caea2afcefdee7a74ae56ce574bd76f44383b9b05bcb2432bae24d3adac03Virustotal results 30.65%Dridex