URLhaus Database

You are currently viewing the URLhaus database entry for http://payreminament.com:8088/javascript/Invoice_7028090.xls which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1471835
URL: http://payreminament.com:8088/javascript/Invoice_7028090.xls
URL Status:Offline
Host: payreminament.com
Date added:2021-07-21 20:31:08 UTC
Last online:2021-07-23 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-21 20:32:06 UTC to abuse{at}digitalocean[dot]com)
Takedown time:1 day, 14 hours, 9 minutes Poor (down since 2021-07-23 10:41:29 UTC)
Tags:Dridex link excel

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-23n/adoc f5ce4cf03945ec4fba2094369972b98aaf2d4860706868dca994a7c9a4982c76n/a Dridex
2021-07-22n/adoc c378f32b4b507bfdb30ac8f544046da38f7ec6cb31fa223b7f088431769de606n/a Dridex
2021-07-22n/adoc 7cfd5712bef75338bb1e6dbfb7b531b827f9b7868197d9a687486659f37112e3n/a Dridex
2021-07-22n/adoc d38d17f4d61390662fad4b945676c669438b2f466bb6d1051654dfd9c0eff12cn/a Dridex
2021-07-21n/axls af931881445f375b740f42f182c797e8267c576e36f3093b10a935744154df60Virustotal results 30.65%