URLhaus Database

You are currently viewing the URLhaus database entry for https://www.kriskate.com/upload/nfBPTDeVj/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:430526
URL: https://www.kriskate.com/upload/nfBPTDeVj/
URL Status:Offline
Host: www.kriskate.com
Date added:2020-08-12 15:08:25 UTC
Last online:2020-10-07 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-08-12 15:10:17 UTC to eig-abuse{at}endurance[dot]com)
Takedown time:1 month, 26 days, 2 hours, 9 minutes Bad (down since 2020-10-07 17:19:45 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-13INVOICE-J4-914997834.docdoc f9d386ef77ac7b75fa5d24fedcf07b054c6e35682826e1a38a6e908dc8c77e10Virustotal results 38.33%Heodo
2020-08-13INVOICE YB9917 75233028.docdoc 2741a0a45d8bb8b7e1fa15f9f05492ec1235fcf882792971e1668640ae40fbb9Virustotal results 36.67%Heodo
2020-08-13InvoiceKGG9232655.docdoc 02002790f4d5801feba9f00836aa82e8762db15f9dbe6f7aa8b7ab84b661c284Virustotal results 35.59%Heodo
2020-08-13Invoice OK4527 303856224.docdoc ff68f4adbb2d5f421b94ec8c2ca343c8dc807544237928a2617bb4c1dd32b7b8Virustotal results 36.67%Heodo
2020-08-13INVOICEOFH467910902.docdoc 653065e50db8318e4c980f45418849681df513e216b29c07cc7036442b0f9cfeVirustotal results 36.07%Heodo
2020-08-13Invoice MGDM5313 194774.docdoc 5afd28f4c27929a5271720ade77b26422b7596600473f76d9aca778869203bacVirustotal results 36.21%Heodo
2020-08-13invoice-JRG334-3586409.docdoc 5068ac1fc3ea1af3eb637bed169df3a72f14ab7db56ff2996f718fbe8c05642eVirustotal results 36.67%Heodo
2020-08-13Invoice-MDIQ591-9324696.docdoc 576c0497e26b93869620e9bd122a6836001c6ab4128462dccaceed7c2eb22dedVirustotal results 36.67%Heodo
2020-08-13invoice_RLEB87_167519893.docdoc bb480394e0201866ae43a5b60c1ec371e3dd37a01e922a8dd5ff68d8cb325f3eVirustotal results 40.00%Heodo
2020-08-13invoice-NOM44-747145248.docdoc d50993fa8e4d9ec3510e0980dd77bb417ce8cd1455e5b3b789b4bf66e4f7b29fVirustotal results 35.59%Heodo
2020-08-13INVOICE 777 8127193.docdoc 5912b8e3ef4983ff2a2edb2097d0149b2828a6d735e579fc964a0a938c0afac7Virustotal results 34.48%Heodo
2020-08-13invoice-X3518-199924387.docdoc da66414b758cec9e59a4d246d1a01e3339644d5be305c6447ddaf0f65900db71Virustotal results 30.51%Heodo
2020-08-13Invoice-Y114-2633119.docdoc 7e058242f7a064bad48c7b7a1e45ebabdb59903cabf069d79e145c9edd2408fcVirustotal results 31.67%Heodo
2020-08-13invoice 7301 825597027.docdoc 196a89c54cda70af31877740ead0a738ead3533d3ef89e87e31b193044fb42f7Virustotal results 31.67%Heodo
2020-08-13INVOICE-W051-138188.docdoc fca1b080bd37f31310426e23e3d06dff66c14e54fdc049af8896fd4970ea29c5Virustotal results 31.67%Heodo
2020-08-13invoice_OT67_74228853.docdoc 7d4ee38f224a7af8f2988087cb32ba596f3e914f876a03f7b51b3d68c0832e43Virustotal results 30.00%Heodo
2020-08-13invoice-B9649-079623139.docdoc 440955936e72def67b0e6c0b2ff841aa2161c705b46cce961107a37535323337Virustotal results 28.81%Heodo
2020-08-13invoice-XNN66-45364039.docdoc f392265c903b4cad60edb998054c18fcb2cfdfe7e9e068ad6119545be62062e6Virustotal results 28.33%Heodo
2020-08-13invoice_RP12_014064.docdoc 52c981dcee0a9c0bc80ec192b453e8af6b01ced6cb3187645687ad0fd1b13221Virustotal results 27.87%Heodo
2020-08-13Inv_JWR6_026153558.docdoc e9bc4332a3fd2de13d8f4d58aaf749131a93e652fd663f83005b1437936a715eVirustotal results 28.33%Heodo
2020-08-13Invoice-RRL176-10195786.docdoc bf2332d7bb2fe3a48644b9436beaccf7cc4015b5954d8d012f2b095e21023629Virustotal results 26.67%Heodo
2020-08-13InvoiceASA58644722.docdoc 3a957d2e54e658d116c346dcaf0dab5ecaec5e60bf7125b32087746f27cbe35fVirustotal results 26.67%Heodo
2020-08-13Invoice G744 8003995.docdoc b58536809fa841324f6ebd181e66c4e897843b4689a45987ba00691b7c99f35cVirustotal results 25.00%Heodo
2020-08-13INVOICEIE935484536132.docdoc 776396c0aa0fac10eb849a713ca7927a00cd7aa654be032e870fa7cbe3076078Virustotal results 26.67%Heodo
2020-08-13INVOICE_37_524158.docdoc d9d595a78d3bf3bab0e65cd5eb3a71ba4bb95ed7850e84862d01930ceefd1c35Virustotal results 26.67%Heodo
2020-08-13INVOICE-ABG779-53067134.docdoc 6470a38736f61fd9858f811fe8ec7e2ea6d075e3d4bacc287ed9b0a746ddb5dcVirustotal results 26.67%Heodo
2020-08-13INVOICE-ABG779-53067134.docdoc 6470a38736f61fd9858f811fe8ec7e2ea6d075e3d4bacc287ed9b0a746ddb5dcVirustotal results 26.67%Heodo
2020-08-13INVOICEYHWD8940153475.docdoc 147ff91d2f978f8abd623f6a25e0599903cb53c9a890255e3fcede1cb0fbc8daVirustotal results 25.42%Heodo
2020-08-13invoiceETCX3451138578.docdoc 620d84fae4b584f528eb0044177ac950380d8c41d764dc1615871a80ecdc4ae7Virustotal results 25.00%Heodo
2020-08-13INVOICE-9-864500.docdoc 43b13b874d7ccbe6821d27e5a403e6415ece6d1972ad7409f6f294d1bce52112Virustotal results 26.67%Heodo
2020-08-13Invoice-MWC7138-229985.docdoc cc8c1667a1b992293217c0bb3a7bd8be2cb3d4f83bdaa7746fdb6b36992bfa5bVirustotal results 25.00%Heodo
2020-08-13Invoice 047 6571192.docdoc e1b7a11726c385bcad71dfe791b165802cc625ceaf2f1550a5a10f5f222ea90dVirustotal results 51.67%Heodo
2020-08-13INVOICE-PPRR14-6698917.docdoc 04f398e872a21555e613068343a42ae713930a96f16f079aba07a4434b800180Virustotal results 54.24%Heodo
2020-08-13Inv-Y2135-621401.docdoc de63eeb9f1015ea52b0e1a4d4698d706634a985366000085cfc06c5295b0d165n/aHeodo
2020-08-13INVOICE_OI5_190294086.docdoc 17b6049e45eaf5263f576de1799a8b8ccd0164f7e1241cf72738d56e8793458aVirustotal results 53.33%Heodo
2020-08-13INVOICE TVI2661 6056794.docdoc 015990746f332cc1ad898d46ef3de53f4ffc95d723ccd19bea5fc12b95f86b47Virustotal results 54.24%Heodo
2020-08-13Inv_QE4_994563.docdoc 90452e3bfaf3cae36b9bfcc2e98684fbabbc11074887533175a04b41b2a8734bVirustotal results 54.24%Heodo
2020-08-13Invoice PISN757 599542.docdoc 97e52709f1f9169fb2a3d0cfc7852f811d067999ed1bdc700c6b66bc7dc23765Virustotal results 52.54%Heodo
2020-08-13INVOICE-N25-6824012.docdoc e26bbe184e43c8251aee307aa6d392971f7facdda4ce50f9733a966dc7905ff2n/aHeodo
2020-08-12Inv001687446279.docdoc b858572fbe695215c2aa6ade7ada24c980392ad2f5c9e3564d4e6446ef424383Virustotal results 51.67%Heodo
2020-08-12Inv-L4988-949238271.docdoc e412c6a1097b6fdf1492ad40805d0bbb1df005f870085f3fcb57d30552974cdbVirustotal results 48.33%Heodo
2020-08-12Inv-620-084780391.docdoc fb474008a44d536948b71f933bfc0289e7779352c43c4d62f0b3dff8f0ae478dVirustotal results 49.15%Heodo
2020-08-12Inv-Q4-2148918.docdoc d60d130c4369c7d41edf041927897b2ceb6b845a66b97bfeb0cf7d60575fe399n/aHeodo
2020-08-12invoice-RY03-05879206.docdoc da25968d18d6c8ddfd6ffa940b4e0bc6809a5b1a224602f196ce7eb107578f88n/aHeodo
2020-08-12invoice-26-5580306.docdoc 0c7d085dc88b57e56819a0a9319e1aa089ad9851a0ea21137aab6309395ed039Virustotal results 49.15%Heodo
2020-08-12invoice-D196-48555280.docdoc dcaa5f28e69731be4dd507c5b31f0594b585d516edbaef3db061890462c383d5Virustotal results 48.33%Heodo
2020-08-12invoice TG0498 089699.docdoc 87a59fdf7ab0abb1c6263fc0c53650659aa5c3d50d09d38c6696819017787e38Virustotal results 48.33%Heodo
2020-08-12Invoice-66-89212109.docdoc bbf084bcd83d08a6693798f851e3af34cc7c303afb235c8c25fe237ec00315cbVirustotal results 48.33%Heodo
2020-08-12INVOICES874754060835.docdoc 45a8de935419a54875afce7f3862e01a00c5bdce06bf494ccb53a16a022f6bc1Virustotal results 46.67%Heodo
2020-08-12INVOICEEXI556547249.docdoc 79ada6c652264a8bf701b99a922fae42a4965fa95c5117d73c9d6942028cf07aVirustotal results 43.10%Heodo
2020-08-12invoice 7 959542953.docdoc 37a1c85950d3e91662ed4137488030ffcec13adad6f9b2f3eea1de01a756b260Virustotal results 41.67%Heodo
2020-08-12InvoiceCNY8666687168304.docdoc ae4e6ac684f5b88e2165adea2e0df977852b853b20d129fae3d53600eebeca8cVirustotal results 39.34%Heodo
2020-08-12Inv_E68_784351829.docdoc b2699f3cd54b6953a3eb9e1812890cf40563699a96776cfacd8f81288e962e11Virustotal results 31.67%Heodo
2020-08-12INVOICE_RKAR45_307256442.docdoc 4543b232ecad0b35f81bf1487ba8ee8d2bb9a4cf738d86e547b61f5a7c811169n/aHeodo