URLhaus Database

You are currently viewing the URLhaus database entry for http://waunake.com:8088/wp-content/Invoice_440258.xls which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1471659
URL: http://waunake.com:8088/wp-content/Invoice_440258.xls
URL Status:Offline
Host: waunake.com
Date added:2021-07-21 18:40:08 UTC
Last online:2021-07-23 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-21 18:41:03 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 15 hours, 53 minutes Poor (down since 2021-07-23 10:34:14 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-22n/adoc 291d40eed116355a5e29449aa39cc5f42cf4f3b6be9bcc83c3b4fb3d5fcad20bn/a Dridex
2021-07-22n/adoc 017362d7c56c96021dc7de1994d17bf96c162cd02e6aea4e14209024c30db5e7n/a Dridex
2021-07-22n/adoc d94c5e90133b57606e322af1e20725fb114cf3f046798e4c79f57cff09a0cba0n/a Dridex
2021-07-22n/adoc a21c8de851e81e5d726c624f1c620007ff67a7a42b3c71f106ba49db15b39e25n/a Dridex
2021-07-22n/adoc 6d1b7168c670199565c3493426ad1f1e1998a6fe5e76029a8555d5cc8f19b788n/a Dridex
2021-07-21n/axls bb54dc0cfa4ac775461547a04c989435a95653d288ff7f4bf6cd50100d8a0d49Virustotal results 26.67%Dridex