URLhaus Database

You are currently viewing the URLhaus database entry for http://www.rupeefriend.com/cgi-bin/available_module/rjjisp_k07wo3rsa9o1pud_cZE1NM7Zk_c1qRersATZ/2Ckc9WmzF_N3wd7jpogtI/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435735
URL: http://www.rupeefriend.com/cgi-bin/available_module/rjjisp_k07wo3rsa9o1pud_cZE1NM7Zk_c1qRersATZ/2Ckc9WmzF_N3wd7jpogtI/
URL Status:Offline
Host: www.rupeefriend.com
Date added:2020-08-18 14:42:06 UTC
Last online:2020-08-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002873890 created on 2020-08-18 14:44:06 UTC)
Takedown time:6 days, 15 hours, 12 minutes Bad (down since 2020-08-25 05:56:07 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-20rep_2020_08_20_WQW6668.docdoc 31896a613dc6dc5bdede079f857dc45c591abb281b1b13e8bb411554a2bda60aVirustotal results 23.33%Heodo
2020-08-20list.docdoc 48c065c3c6c626c7fca855686845bf480a74dd0902ae005eeea171dcb5237947Virustotal results 23.33%Heodo
2020-08-20File-2020_08_20-982626.docdoc ce3ff108a607fa2314a8bcbced388fe05dd7231df86db8dbd4beb6271388f1cfVirustotal results 23.33%Heodo
2020-08-20doc_2020_08_20.docdoc a352582176c8f6ccef9286c97faec72461076b101973783284eecd6d42ea3e4eVirustotal results 25.00%Heodo
2020-08-20doc 20200820 MQA10105.docdoc f08d7bebe518919883aedf8b598a15e5961f848acc3cd068104b99c3cc5729dbVirustotal results 22.03%Heodo
2020-08-20MES_2020_08_20_X850.docdoc c770bba68818296583e90edb1401e456254a70721f9572ed9036d9a4aabd3aa5Virustotal results 22.03%Heodo
2020-08-20List 660.docdoc 2aa3ae963e12e360ed0aa0cac15bb33e19e9359e7b08e7b2f9055df72c76c34fVirustotal results 22.03%Heodo
2020-08-20INF-2020_08_20.docdoc 93d43e8efd2b7c13c0695b9ccd0026d2b289bc0a681d091d568072044de9d886Virustotal results 22.03%Heodo
2020-08-20arc_912606.docdoc 378b412d3de776d01ec9fdec9de5c4af668d37871bd5ef9d2eeb144eb21b5d01Virustotal results 21.67%Heodo
2020-08-20ARC_2020_08_20_917.docdoc 385b99deb4659a9229df342c92919b54428710364712aa73f5de71245a8e4e55Virustotal results 22.03%Heodo
2020-08-20Arc_2020_08_20_Z30838.docdoc 953b662d9aef02326fea06afebcb2c0f499bf6075210cee6bc361cbf62c74c8bVirustotal results 22.03%Heodo
2020-08-20Arc 20200820 937823.docdoc d9e54fb1e80316189d29a17cc3898bfac26ba783a23c610218c77349250d653fVirustotal results 20.00%Heodo
2020-08-20Arc 2045815.docdoc a6495ce0634ebce9b181f45914574e07b54400238c8a8eeeacd6516ccce7752dVirustotal results 43.10%Heodo
2020-08-20List_06144.docdoc ff2219bf2a6e79b513db9d0cf17c1ba49ab9b6b9b64ccc86662e2a8090a54b13Virustotal results 41.67%Heodo
2020-08-20DAT 101.docdoc 89b6ed4e8a0cf8a07e457b0f616f06fc4770fd168802ee6180994858453dc3f3Virustotal results 40.00%Heodo
2020-08-20arc-20200820-5324.docdoc e47caa21a204cff18af76ca9418e048f41e70ffea406ea5c41bbb6fc6bac357fVirustotal results 38.33%Heodo
2020-08-20file-SDA33592.docdoc 67a3761b4abfe902aeefe85f6d92576b90564d706f24a08b54b1e90e5cec0105Virustotal results 40.00%Heodo
2020-08-20Arc-CDI2108.docdoc 62ec1bd0426af880a8212346e5dd56fa705a031c9b838cba9dc012e37a661ceaVirustotal results 43.10%Heodo
2020-08-20Mes 2020_08_20 6015865.docdoc 139d96003a5964f811cfd1d2a1c28130de97b7b0a548b04e7eb8dbf7331d94e3Virustotal results 40.68%Heodo
2020-08-20Arc_2020_08_20_E581134.docdoc b520ba622b83b81208d66821aeb38a6d30a8f9a5a4043f69bcd2cec19db40e19Virustotal results 36.67%Heodo
2020-08-20DAT 20200820 7230.docdoc b10b19c1f993e77bacc7116920f5c3211701223777403cf710ef56a257238986Virustotal results 36.67%Heodo
2020-08-20Arc-2020_08_20-846704.docdoc 38910d48a5b54e7d0b4f33b6ae9ff7668cb5a8ea4b8895d894b73115cf8d3596Virustotal results 38.33%Heodo
2020-08-20DAT-T400.docdoc 744029fece917740a88f43a6f35c563dce6abb340e34652085620785547883e6Virustotal results 36.67%Heodo
2020-08-20File_20200820_MRF0361.docdoc b9dd0c46c40a59f5ee13585b936980a4e93d12bace98f342421fbb63fc15a460Virustotal results 38.98%Heodo
2020-08-20mes-20200820-160779.docdoc 14837e0fca7286d6b85e13b9a9f1d5498b6a30241cd7cdfc59b5adcb0547be15Virustotal results 38.33%Heodo
2020-08-20Mes_004384.docdoc 34df63aaf08820ef807a0992d54df52142bea2fc2135e5f4012ab9f1f89aaac9Virustotal results 38.33%Heodo
2020-08-20list_2020_08_20_DJZ178.docdoc 81bed19efa97ba8177bda3736a8ab04d1a331974d94e3ccbda0e1c85f0cde5d5Virustotal results 38.33%Heodo
2020-08-20Rep 2020_08_20.docdoc 9ea89a24c2efb06595aa09d8d9dc8ac79ad4a9df0d0d99a7fd5fe63fe9e1f7f8Virustotal results 38.33%Heodo
2020-08-20INF 20200820 HD094.docdoc a07b4b70e44a67ef59e7bffe9f8765f449f5e739d25ad9c49f88d65607e38f42Virustotal results 38.98%Heodo
2020-08-20rep_KG585.docdoc e5da2bc79938c38b6d1deb7265a10cef4adb6664addab2bc3739942b0a0d0d34Virustotal results 33.33%Heodo
2020-08-19List 2020_08_20 5240833.docdoc 2c5b0a5c645d8ca87fd7a703e770536a91e2178a14a3b50980fc71231a5c9049Virustotal results 32.20%Heodo
2020-08-19Arc-W560091.docdoc 0cd31f3fe195cfa0c025d27c1cf6ad200d8228b2fff802412181fece4bbf5155Virustotal results 28.81%Heodo
2020-08-19ARC-20200820-83277.docdoc 5c74356183992b27397f191b6b6968050d1ce8762dd082afa67b5844585280a4Virustotal results 26.67%Heodo
2020-08-19Arc-VGA6384.docdoc c940432dc1875cdb1adfbda4eb2c3a23b3a10fd0a53cf12cc32e79389120b5d8Virustotal results 26.67%Heodo
2020-08-19File 2020_08_19 2213711.docdoc 49332870601ca0a8710ad69eb2e09ff1952cd8c9d843fad20ce04ad0b8de8546Virustotal results 26.67%Heodo
2020-08-19Arc-20200819-3425684.docdoc 949d5111399eaea6135927548fb0154fd3b99217f2e5556ee5b7efb4eeb8d813Virustotal results 27.12%Heodo
2020-08-19Inf-20200819-817280.docdoc b6bc398b50e53b9134174954be2711af3ba4a2715a4407db570f3f0ab63c81bdVirustotal results 26.32%Heodo
2020-08-19dat.docdoc f7e9fa608f55e54940a272093c78974b3e2350594feb6bee7e0847ac03e975bdVirustotal results 27.12%Heodo
2020-08-19dat-20200819-I32541.docdoc 1974d9df785e9c234899f09030fb1e99b007709c6ed249e4e8b2fc080df7ff16Virustotal results 26.67%Heodo
2020-08-19LIST-2020_08_19-7856.docdoc 621f57169211edd6bfa1215035b4b15f300b7356aa6f3c40a716b29b9c2f0db6Virustotal results 27.12%Heodo
2020-08-19DAT VB55279.docdoc 5a69dbe048fbeb2da153621f4cb921772399169f8fc1b021e72ff4650f82f6a6Virustotal results 27.59%Heodo
2020-08-19Mes 2020_08_19 5888132.docdoc 60583244e23ce73f1033463f27a56403be325eef59cb3050e85c5265d2cbcb3bVirustotal results 25.00%Heodo
2020-08-19Rep 20200819 54771.docdoc 4f49566c22cd95508f39368f73be4e9b6c9c8e504c519f2383cc00fb67d28c55Virustotal results 23.73%Heodo
2020-08-19REP X795356.docdoc bcec740185af19805b96a2a510bf2e824d2c3dd65c58866cc013ce08b8648e6dVirustotal results 22.03%Heodo
2020-08-19MES-20200819-V142.docdoc 35a575d3cc73b07a44de16fc04dbd04650ba5d4a0005028abc178ad78e1d47b4Virustotal results 21.67%Heodo
2020-08-19inf-80158.docdoc c313812bbf729a2f67dbad9bccebb42106cf1625d5d9c8a3621ee88aff2fbe31Virustotal results 20.00%Heodo
2020-08-19arc 2020_08_19 1550.docdoc b4980748305d9329f376c996a7887e4cb40713c823693998d4360500c510062an/aHeodo
2020-08-19arc 20200819 0277.docdoc f04dd72e780c21c9e4b8c93008e7c679ba859a9ffbff5a9e997d387659a324c1n/aHeodo
2020-08-19arc H095071.docdoc 02efef8ede900c86814ee2bdbd43c88bda71b970e85d0320bdb50feea29dc6baVirustotal results 18.33%Heodo
2020-08-19Dat-2020_08_19-3290.docdoc 440bce9e28d9e45a9b6158c91047a6bcf28d0f4cbd2dad43f041d74beda848b4Virustotal results 20.00%Heodo
2020-08-19MES_20200819_5568308.docdoc 6113d226147ed6792b907a3ef253741209049cce5e48a0e420828ee4e9679985Virustotal results 20.69%Heodo
2020-08-19REP SB535917.docdoc 47375ee765d009fcfbc20d212b828e35b6ff6c22fd0a478f90f24800cc21ef29n/aHeodo
2020-08-19INF-2020_08_19-0660.docdoc 681b60c42182e1e44908749abbbdcf6b53a3cdb654acb4630f41348068d297ceVirustotal results 18.64%Heodo
2020-08-19INF_20200819_YS762.docdoc 963b5a5d7697620b406fa79e667784b136bd5f07ce3384a384b679bb1f046e65Virustotal results 18.33%Heodo
2020-08-19INF-2020_08_19.docdoc 4f1f186c9993f7a0816cf46d8aaafd5057718ca9b9102e98fb12fe2c2ea1bb24Virustotal results 18.33%Heodo
2020-08-19file-0303.docdoc e9da8132017bc36f1448def9ba8b2ea44184e68bf955c08ba75f2560ade79372Virustotal results 18.33%Heodo
2020-08-19ARC_08876.docdoc 17904f8a80c29c5ed3d3048aae5f62027b918b756006c67893220e03e7a0d7c8Virustotal results 18.33%Heodo
2020-08-19dat 2020_08_19 UPP650.docdoc 87a90ac40158e53a2309863a8bebfe1218f13262f87b93db76e5fc79ed1c388eVirustotal results 18.33%Heodo
2020-08-19Dat 2020_08_19 SSK8803.docdoc 44116755a469545747d98ca4dad33a22c5565d571be3001cb95cb4971c532c3cVirustotal results 18.33%Heodo
2020-08-19LIST 20200819 FL0102.docdoc 55243fe4d8aaffb5742798883e5ebb342f4cbf5eb2b4ea32c0f3603c658ddc93Virustotal results 18.64%Heodo
2020-08-19Mes 20200819.docdoc d854741ed5301c0c1c91902f29edc9e823fe1f656c5f9c1610fdc19ae1c29059Virustotal results 18.33%Heodo
2020-08-19ARC-2020_08_19.docdoc 7bf519b79d25cfda553295f5249aec90f7d5faa6374eca5930118e0bc0a59666Virustotal results 18.33%Heodo
2020-08-19REP-2020_08_19-56289.docdoc e539186195154e173115f68e790dac9a32909a8c4344a387ce25fba6fbf55d27Virustotal results 18.33%Heodo
2020-08-19Dat-20200819-2813377.docdoc ec04bee2423d5f00191bc124105d869b664321f61b553a0d1b7335989bfce7bbVirustotal results 17.54%Heodo
2020-08-19rep_20200819.docdoc 568b22f1a6fb077fd3828a09858b4bcd8401325c01f2aed85b3a39e12777cb35Virustotal results 18.64%Heodo
2020-08-19MES-A715376.docdoc 1dd9e898cf2ef400f93bb6759c7453980dc396b70c7c8748055db01b62685f2aVirustotal results 18.64%Heodo
2020-08-19REP 20200819 281090.docdoc 6409ea14c150741b3551828dcbbc20e14505bdad2f9a8eee4f450a80878f6519Virustotal results 18.33%Heodo
2020-08-19list-2020_08_19-BGU858.docdoc da820b108be2808d9d5d1909a3d8683f33f902abe5ae4e5e319d6aa766aba61dVirustotal results 47.46%Heodo
2020-08-19ARC_18726.docdoc a09fb497ce5738081489fafa343ed354128eba16cc5f8f6bfbb26ff79e19ceebVirustotal results 47.46%Heodo
2020-08-19arc 2020_08_19 6502814.docdoc 09d725bc4314f587c3132842fc1d924a1ec4952620d18e32796d3797b90e66b0n/aHeodo
2020-08-19ARC 2020_08_19.docdoc 06cad41d0787e562a96ad8958e26b1f207b90cdf231201faa801225a7a259256Virustotal results 47.46%Heodo
2020-08-19file 20200819 2923169.docdoc a0096856f8887d5cdf7d5f2e6805694ac96da153aaaa326ef25ee058e6c6a683Virustotal results 46.67%Heodo
2020-08-19file-PWZ76741.docdoc f6feee3a8137cb0cab6667842f06e07f96e54fc2f15ebe079dc30b4060d52452Virustotal results 46.67%Heodo
2020-08-19Dat-20200819.docdoc af3f70492545cd6391ad67cedb9347c9e78980d2462b1b1a6b656113d246e010Virustotal results 46.67%Heodo
2020-08-19MES_2020_08_19_YI05558.docdoc 8ecfd0e0dbd4257b0b0f97f99517f9d1d825e32d7862b1ceb1b6bfdc67b205a0Virustotal results 45.76%Heodo
2020-08-19List_20200819_VY820.docdoc 9f95680d93e52258b33600da99d066d953f0aa373f991d850e83ae0e050fdb4eVirustotal results 45.76%Heodo
2020-08-19File 671080.docdoc 7916fa0619bd4a976c48a8b068040591dd8f78f9eb5b2bd3abafc019ec1f0dadn/aHeodo
2020-08-19File 2020_08_19 80079.docdoc 5a63ce9de6a721eaabedc5a95a579a3eee404a94034db171f646e24517fed367Virustotal results 46.67%Heodo
2020-08-19REP 2020_08_19 N371198.docdoc e94bbfc806ca8e6182447d1f10e43d213e234887abec37e993057a77a51e3132Virustotal results 45.00%Heodo
2020-08-19file 2020_08_19 XD330.docdoc 40ba73d22e9dab3b78ab066b7fce42d3bc541832c4d6a8ce3c564f2290c0b308Virustotal results 45.00%Heodo
2020-08-19Doc-MLX128.docdoc 859010e3760b56ccc5e32be50378cd07f2f34509d92b112b4ec0e6e5802fda42Virustotal results 46.67%Heodo
2020-08-19rep 20200819.docdoc eb36ddd9edb9f64c1d10743135f87875826990fee2cde8abfcc653b1045c9061Virustotal results 46.67%Heodo
2020-08-19DAT-W576.docdoc b4109096624dd29f07d9e5c328637c66396a4c0ba53760b48905a4d81e829027n/aHeodo
2020-08-18ARC.docdoc 5644494f53e0f58e39e8c623b06d33e093d920e7728632366beaa74ce3ce75a2Virustotal results 43.33%Heodo
2020-08-18list_2020_08_19_3281.docdoc 85d051184c78737bf858c74a6fe5cbf9d30ed82b3ace8cad4b7555c5132cb11en/aHeodo
2020-08-18list 2020_08_19 773200.docdoc f7f2b55cdbf9f24f6e1850b32aa87b859717f840d46caff776674a973d28d51cVirustotal results 43.33%Heodo
2020-08-18LIST Z81018.docdoc 5fe3b8e6945f1fd2e0c85c1b8cf1c0969965447dcb9d72deb04c28e05c9116b4Virustotal results 44.07%Heodo
2020-08-18mes 2020_08_19 4722.docdoc 1a586ed406130c0ed7d070f24ccb79ee1b6f0b4a3f47373cfa6285ed1ee322b9Virustotal results 43.33%Heodo
2020-08-18list_V152157.docdoc 17300227be521550f2f2047dc5be4dcad326b59b87378c8a1372dbc867fb29c8n/aHeodo
2020-08-18File_2020_08_18_IC78923.docdoc 2df5b20d8f749d1edb14c16c6c1c1ce78165354f3d038a23ac8d4d99188391bfVirustotal results 44.26%Heodo
2020-08-18file 2020_08_18 96679.docdoc 1a8c5bc937330472d676469e981466649ed28cae04d2f3273b0648e96ee6609eVirustotal results 43.33%Heodo
2020-08-18LIST 20200818 888333.docdoc 81a254ffe9cc5094cfa32cac704d5273a94a9f9f8af621676853247eb6c92be3Virustotal results 44.07%Heodo
2020-08-18List 049889.docdoc 119e31c97f1254759e57ac901452c408e74c094919190ae94625b5e5a40312e3Virustotal results 43.33%Heodo
2020-08-18Rep 20200818 027963.docdoc 72d943737f8d648bf65f1f9071ab2656abc7a9095e4bb53f4be92836d49aaca5n/aHeodo
2020-08-18DAT.docdoc c2c31857eddef908bb15ebce07f54e91a068ffff5b92014fd70c1d5ce8f34cd6Virustotal results 40.00%Heodo
2020-08-18Arc_2020_08_18_250121.docdoc c674ec5f3cdf350eb7768e985c94060f26903274d10b581bab0fc71c730f0179Virustotal results 36.67%Heodo
2020-08-18MES 245.docdoc cbe9a323a3f8c6f8e119d5765df5d8c8aec0899db8729b8cc5f63e877925173aVirustotal results 37.29%Heodo
2020-08-18REP-2020_08_18-KZ6137.docdoc b8ceb76e216625929c1a81fd2260e8b3ed97b6dda3a18f3054ef2fd575f7b15fn/aHeodo
2020-08-18file 20200818 296542.docdoc c2ddfddccb101d4e986562ca370e4c29e0ec7f510f7a657f32d61ae37a173c8dVirustotal results 31.15%Heodo
2020-08-18doc_2020_08_18_WU672008.docdoc 96c73835686797a5dbc5dbd37ef4a7291b69f848d7ca403c9ab404f4f7f650e7Virustotal results 28.33%Heodo
2020-08-18ARC 9926.docdoc ab45fc94f007788e905abc86f9e9d8cdd26a6ae5dfd6af136acb05575c229ea1Virustotal results 28.33%Heodo