URLhaus Database

You are currently viewing the URLhaus database entry for http://kyleriffic.com/blogs/CPiQkzre/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:427065
URL: http://kyleriffic.com/blogs/CPiQkzre/
URL Status:Offline
Host: kyleriffic.com
Date added:2020-08-07 08:57:08 UTC
Last online:2020-08-25 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-07 08:58:02 UTC to abuse{at}publicdomainregistry[dot]com)
Takedown time:18 days, 2 hours, 16 minutes Bad (down since 2020-08-25 11:14:03 UTC)
Tags:doc emotet link epoch3 heodo link Quakbot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-08INVOICE_SGGU382_84760560.docdoc 5d7f4b905c268a16b873261ceb5f2bca434dbaa45ad6c5b20a3d43091709ace2Virustotal results 39.66% QuakBot
2020-08-08INVOICE-QPJI537-6715614.docdoc f2ac567d25e6c1c3423309a6ee7158f3740d1f4b648a3d0b162b83cf1dd3b6b2Virustotal results 38.33% QuakBot
2020-08-08InvYA562065848.docdoc 934e668c7d90204ad5578903490ce28fd0e338875fabd6a82a4789afac1f3062Virustotal results 38.71% Heodo
2020-08-08Inv EE717 477775239.docdoc eb283960353efbf54aa5fea1afd72a13e16ffb3e86b9230aeac43d3e2c346e17Virustotal results 40.00% Heodo
2020-08-08InvRAQ590435114.docdoc 4f1231f567a608f26676f43646cc522317020d2d2d9da3a8aae64495ee840814Virustotal results 37.10% Heodo
2020-08-08Inv-FK5-123420.docdoc d9117ec342f11a6f9cfe66f8c223ad054a26dc3cde8c442a7a72d537701fbff8Virustotal results 38.71% QuakBot
2020-08-08Invoice-QPU93-9374444.docdoc c620f32017dc5a093d19d6362b34657906e156082ffac1c93df403171a2fcc32Virustotal results 38.33% QuakBot
2020-08-08Invoice-772-94359174.docdoc 9f177a054edb33a1e6ae00ceed458756c377f47fb18719abe82e506ed38e954dn/a Heodo
2020-08-08invoice-VQXH9126-435205801.docdoc 3861a52ad582544a7eed808c49f41588b9620ffc729cc2c9de6a83aca5762fd2Virustotal results 39.34% QuakBot
2020-08-08INVOICEGC058685017.docdoc 65ae828750c71374225c39bcfba19a641631b695eafa9df608266f83e63a8c61Virustotal results 38.33% Heodo
2020-08-08Inv_FX5_5933531.docdoc b67b32bfd579e0f9ab07e5c28fbffa92e3b061190d7b010a0ac40655aecabbdeVirustotal results 37.10% Heodo
2020-08-08Invoice-KJU7-191441029.docdoc 2659421c624afcfc6ad404b436a664c9faae922b703e516ccdcfe79f2cbffb27Virustotal results 37.70% QuakBot
2020-08-08INVOICEZR1711709.docdoc acbb87afd6b22d463b27aa56b1b49e40a2c049097102b0c901678e2ba771e59aVirustotal results 37.70% QuakBot
2020-08-07invoice UQY1 889543603.docdoc d91731a4dfcfb45b578cde0a57e35273bdc0eecf426e738a1f52a32e989c9fb9Virustotal results 37.29% Heodo
2020-08-07InvJGXO2272393963.docdoc a4b97280b1cceda62816b36b8b40327eea965a74334cd171eeca03b3158d3177Virustotal results 37.29% QuakBot
2020-08-07InvoiceA6424096369.docdoc 522dfd2bd5983277254467284eb5cb1ae79a0957444adbd473462cfee3599c4dVirustotal results 37.70% Heodo
2020-08-07Invoice_ZH9869_07355056.docdoc dd693242b7c4ea00e3edc941a1b92d17d7effee6af390cd0abda5da40e5f4367n/a QuakBot
2020-08-07Invoice VGEJ551 43979118.docdoc 3d2f7bb83fc1e0ff00062b026e00645a1f25b5538f799fc47cb8f1878d8d9c39Virustotal results 35.48% QuakBot
2020-08-07Invoice-A111-423536417.docdoc d8ed4fd8240d522ca6a6f60b17cc639ad6dfdb93ef50a62987c6091b7c80c56dn/a Heodo
2020-08-07INVOICE-QN443-492543539.docdoc ebdda6969778acca315a17e1505c60c3ebbf9c13ca2b43a5092c7a32341f06acVirustotal results 29.51% Heodo
2020-08-07Invoice-VDWH0078-532247.docdoc 737d96d343a18d4739a12d2b949eb31e758fb5e24c17b0c706997154731ac07fVirustotal results 30.65% Heodo
2020-08-07Invoice-STS399-436115.docdoc d5bff5a6b9e1f13e2206aadbb6ff705b7eb29882299b70d8f97205264cb1c04eVirustotal results 27.42% QuakBot
2020-08-07INVOICESOMU273056196.docdoc ce9c9aa5b7aeaf8280a14d4bdca59c62624e14eeae978170acdb80a98ed185deVirustotal results 27.42% Heodo
2020-08-07invoice-MOIW633-5062124.docdoc c2ecd3419f71d51acb56c7f02e685cdd46ec96514b459545a931768e2141ae58Virustotal results 27.42% Heodo
2020-08-07INVOICE_BX5485_2069849.docdoc ab1f576293cc70428b0adcadcbb453c1525ff8bf2fa71d650e52b83ff4092f81Virustotal results 26.67% Heodo
2020-08-07invoice-S5-10777226.docdoc cd0a8f71f9191062a85d74dcd5321d7882e38ba58e3f04468a7e5b2c1aa32209Virustotal results 25.81% Heodo
2020-08-07invoice-Q81-4587594.docdoc 67067a83cf054c8deccf1e31d09a2d8ed82469b2e27884e87aefef248019b89aVirustotal results 26.67% Heodo
2020-08-07INVOICE-84-64729709.docdoc 0a4b53e2bf7608fe93c60618cf50a657598aa4fc95b947cc7fa7b8fb0331d561Virustotal results 25.81% Heodo
2020-08-07Invoice HC9276 499654.docdoc d3c7b17eb10b73fa3e2c519f2e78fbf3d2fc0ceca12fa1eb7b6d2f2b550ee3ecVirustotal results 25.81% Heodo
2020-08-07Inv VLBQ99 59124018.docdoc 969a99e247a7799ab5d43893d9ba53bc202dea27b3246da220b250308ea060d4Virustotal results 24.59% Heodo
2020-08-07Invoice-WCK2746-983128.docdoc f3d9f7cc7e604de1c96321d3ceb0e2d2099aa4bdf9e36bdc861bda08c76601b1Virustotal results 26.23%Heodo
2020-08-07INVOICE-IS019-4283862.docdoc ad8fc14787b10f1dd4473d7b7ec98565f64ee0493926368426c7ed261339666fVirustotal results 26.23% Heodo
2020-08-07INVOICE-T023-32777494.docdoc 4b2a3123f9c35cd05baa562f88b99a767710e4576ab2f5da552c910fecc5b76cVirustotal results 26.67% Heodo
2020-08-07InvOPX329224222588.docdoc 422d547c0615bade5795e3a8cd678030b51987591a28559af66ea99317e345cen/a Heodo