URLhaus Database

You are currently viewing the URLhaus database entry for http://www.rigavagroup.com/rigavabackup/parts_service/ye5g7nl1/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:435773
URL: http://www.rigavagroup.com/rigavabackup/parts_service/ye5g7nl1/
URL Status:Offline
Host: www.rigavagroup.com
Date added:2020-08-18 15:54:34 UTC
Last online:2020-08-25 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: spamhaus
Abuse complaint sent (?):mail Yes (Ticket DCU002874013 created on 2020-08-18 15:56:05 UTC)
Takedown time:7 days, 5 hours, 26 minutes Bad (down since 2020-08-25 21:23:00 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-08-2038806687.docdoc b56b6b80ec50e23b72d315864d8aa23d32af918161941d9b448a7126dc5ff3afVirustotal results 24.56%Heodo
2020-08-20RRDI_LGB_080120_KCG_082020.docdoc d8bbdfb8719a0dc349630f75bd9631472316e3a42d943b541ae46da6e4b127dcVirustotal results 25.00%Heodo
2020-08-20BAL_79889406.docdoc c57a4ab4e5c80b5cd6551c5927e4a052aca796d0dc0e9ee1f0e18308fca78605Virustotal results 23.33%Heodo
2020-08-20B77ELDQDWOW6G7.docdoc 18898d58822870334064b88a2224dc8d236210978f732a70cf80f3617e5a6445Virustotal results 23.73%Heodo
2020-08-20BAL_MYW_080120_GWV_082020.docdoc 370f13258c923be12a4ce1b761f231bb3cb640389f75c77b5a50180cf21b221aVirustotal results 23.33%Heodo
2020-08-20FILE_BZ3969706637UL.docdoc 2d76fe1bacf66d80f4a8dfd102f00c77dcf12834e0adad890869fe7a75d45c2aVirustotal results 23.73%Heodo
2020-08-20BAL_YDY_080120_SVT_082020.docdoc dc62b29f01e0debdb807f4adaaa4c22ca3f21e5fd5a48e7b2cb6b994d76cb36aVirustotal results 23.33%Heodo
2020-08-20INV_RN8499449047JS.docdoc 62aaaf61f90d1c3f0c657fb7c0698dc7e72492a3e762c2161612a93b9ffe2aa1Virustotal results 23.73%Heodo
2020-08-20PO_08202020EX.docdoc 601fd5470b6ef0aa11898d2c1d96a77bf1382dafeb3f1b7c2a3107dc61d426a2Virustotal results 23.33%Heodo
2020-08-20WZ0027252650FK.docdoc 863fd1e52d219bbbf28aad47413c3fe73d56a35ebd143e0373795a33204741c4Virustotal results 24.14%Heodo
2020-08-2068230058418.docdoc 66adaecff904f859044c0d2aacc5bf77afc7928a3827c0e75dda7e79c0c29601Virustotal results 22.03%Heodo
2020-08-20BAL_67889301211.docdoc 73bfcb9214b001594d3b0d3cc9c11c8ae9b0c2f57e4b75b8772cdad41a7e3c28Virustotal results 22.03%Heodo
2020-08-20DOC_69080483.docdoc 004df4af1179c95b943b776e868fe3f553dc136e2586a75fcbb13bf6c000f569Virustotal results 20.00%Heodo
2020-08-2007867555.docdoc 1ec4fbe7672e49a2c4d311f2abb491d07517aa98db9ade8f346fefdc6cad7469Virustotal results 20.00%Heodo
2020-08-20BAL_856527428178640389940.docdoc 9f32a654f894dafb884f98c4e30ab391b1fe3f15478273bedd8397903990c781Virustotal results 20.69%Heodo
2020-08-20BAL_YQU_080120_TJE_082020.docdoc b3cf4a0833d4e2f90e6c3e9d199128272cc2d62f3ec2a3c4516e9f5b7fcfeaaaVirustotal results 20.34%Heodo
2020-08-20FILE_PO_08202020EX.docdoc 6a1d4f7d099b5838523267a6171d718e09385c8ad15f2cebc47a4fdde9b1d6edVirustotal results 20.34%Heodo
2020-08-20REP_GGC_080120_HVT_082020.docdoc 0efd74cc9a3e2043ccf2d1aed8696b82a65a9c96293fe1ca3c6958f41c818543n/aHeodo
2020-08-20DIO_PO_08202020EX.docdoc 6e647b837da2262825372b4fb5ccf78f780e467cdcc593c348153bd1619dbf86Virustotal results 44.26%Heodo
2020-08-20BAL_SRU_080120_NYW_082020.docdoc 66a403efd8393bccf77c5569e565832eff2be778707554b35b78be859b2af41eVirustotal results 42.37%Heodo
2020-08-20DOC_789365336737595979.docdoc b1a3a3654d76f8eeaf84cff925c62e4f349407617da64a11c91b03851f5cf209Virustotal results 40.68%Heodo
2020-08-20DOC_NB4625941757HP.docdoc 77dc94d7a2eb1a8f1f2875ee18a8115333a3c2ab0f0455d8cd46b952f93809b8Virustotal results 40.68%Heodo
2020-08-20FILE_80170509.docdoc be4d090fe53cdad0fd9dcb56ac3cde1af3c9ad19d5e1a8976a02b154d2d9940eVirustotal results 40.68%Heodo
2020-08-20BAL_VVNQEKFW.docdoc 6caf84cf6a6cadcdf4aa5f45a9f87b63c16cdf6486f53279c0ce48676edfc142Virustotal results 41.67%Heodo
2020-08-20DOC_EGE_080120_PVQ_082020.docdoc f4bdec707792203de37f57aaa05aee2ce49012f69866816d8275ceed21df1daen/aHeodo
2020-08-20FILE_EX3300871018EL.docdoc b26d580deb9ff666c0dc35f4cc7c9d88038fe0f3c8bf48c4aacd56dfc05c4cabVirustotal results 40.68%Heodo
2020-08-20DOC_UF7105380827LT.docdoc 29524d934f54a27deecaedd3e58de8a4490eddc04ac913bcb37c3ca1354c5b06Virustotal results 38.33%Heodo
2020-08-20JFW_1SNIO01GST9XP52T.docdoc fd5697cbe13a39316aa3bb5a556294913f66b029ece0dfa4c3dcfb9f8fee28e5Virustotal results 38.33%Heodo
2020-08-20PO_08202020EX.docdoc eeb0a1417b5106cfb471ec4c6404b1acaeee3e4acfd04ae2748adee4ed69812dVirustotal results 37.29%Heodo
2020-08-20CMJ_080120_EEY_082020.docdoc 275e276c98e61d33c2852f27d543c9cda4212aa16383e36b2e3651a28070a8fcn/aHeodo
2020-08-20EP_297453878583478.docdoc 60bb16533f938460519528657d8b785485622e3471330a87fa5894fed506eed8Virustotal results 38.98%Heodo
2020-08-20INV_EE1136877129LP.docdoc d302615d23c61c639ad53db79f2e5e6e3aedb53e0404821c5c02064f7913910fVirustotal results 38.33%Heodo
2020-08-20DOC_YY7902960831NY.docdoc b32f302c129728edd895136f299f0e68031f9554b42be4fd2dd35f80a9b2a750Virustotal results 38.98%Heodo
2020-08-20QBJ2MM1A77WESDP8.docdoc 258ce6696ac78fb8d21424c2e471d638e03aaa8c2aab1dc7a78e2125e77dc9b9Virustotal results 38.33%Heodo
2020-08-20T_PO_08202020EX.docdoc 96f7d13cfc1edad4f9381ae98cab2336d39557b2230d88583c92284d6616b4e5Virustotal results 38.33%Heodo
2020-08-20FILE_ZO4YO2P9Q3XL.docdoc f49f483de9c2f5fc441b529eaa889631aa5a272206dfdca519993427403f65e9n/aHeodo
2020-08-19DOC_20322043.docdoc 5bbab5eced851e6bd35aa4ddd992a84f707bbd76ce0850920c5a5bd21378b61dVirustotal results 37.29%Heodo
2020-08-19WFP_080120_WYC_082020.docdoc 36a290d9df91c6881e6f23de7e03e02206ef7ca2d8aac9d585308806b6e2b965n/aHeodo
2020-08-19REP_UGC_080120_QEZ_082020.docdoc ee0c184cdb3791d36a47a1d945aab42379266c4cc4ea6cd88c316ace9deb8826Virustotal results 28.33%Heodo
2020-08-19DOZ_080120_UWG_082020.docdoc 038f9798da3df2c253620a2fd844e48c6d1a331e314d44196df45b0f9bedffdeVirustotal results 27.12%Heodo
2020-08-19REP_PO_08202020EX.docdoc d3cea7588b6e664da8ef52bfb856e6fdc6e0df460f961066491aed88f4e29a03Virustotal results 16.95%Heodo
2020-08-19ILJ_080120_UJV_082020.docdoc 10087ace9c6e5ec4fb09fa039f6ce0c9029cfd40b4f8203f16898992b3f01a63Virustotal results 16.67%Heodo
2020-08-19FILE_87443989.docdoc 249d09495f8a48b2afa8c8ee4d0d0dd82905f53396e8026eb04a6db756d73593Virustotal results 16.39%Heodo
2020-08-19DOC_VGL_080120_BFN_081920.docdoc 080538677c76d09277a58f1dc9be3e5df254a92d12fddc11326c1f896cd93a98Virustotal results 17.24%Heodo
2020-08-19INV_97786734160077546865363.docdoc c3f0d0d594a74f097907231612a0cd0da8c75160a2ae1064a3744ecdea407986Virustotal results 15.00%Heodo
2020-08-19PO_08192020EX.docdoc 7feab4f1f35adcc7433afdbf4448e5b79996fbe150dfe6e0f708a6c13ce86f7bVirustotal results 23.33%Heodo
2020-08-19E_96012442.docdoc 8be59997575735dc3845990047094781b5e69f074f5b6569e6e1dcea50f08693Virustotal results 23.33%Heodo
2020-08-19INV_83312610.docdoc 86480c7538f4288ee85b3d2de9e26e9d24cf22c6a2902bf81013a5826ff2afeeVirustotal results 23.33%Heodo
2020-08-19INV_GT0960900060MJ.docdoc 39f8850f02b807a843447f461d3436d67191f0f08709c03d32958988964b5e9fVirustotal results 23.33%Heodo
2020-08-19100X8UGL6WUA.docdoc dd78931e61aef620ed1e6125100a60d7dd95ca7865ffb9599bf1cdf27937f597Virustotal results 25.00%Heodo
2020-08-19O00FZ32UCT3S5SM.docdoc 4e56ff16c77956f3ade450d4f9597ac98de493849f2a44b35f6b916f8aea099dVirustotal results 23.33%Heodo
2020-08-19INV_87814880.docdoc 0d9522e1c5d18866b466aa9d28546adc56ea56f6d821fdda5ab77b1285b9e0d8Virustotal results 23.33%Heodo
2020-08-19INV_58260816.docdoc ed6f742fc6e103f092e9fd9301bf4ec786e88abca3ec1593661c4083f398616dn/aHeodo
2020-08-19S_10242405.docdoc 76b5b8d527359fb1183fc7e4e4eb0dc5369aa0126843b1ec8d04f73c658e0b15n/aHeodo
2020-08-19N_QQ1026228965NE.docdoc d9d8ec245eab78761795bfab0930cb5dd903e1157eec18a517b867e004191413Virustotal results 18.33%Heodo
2020-08-19BAL_51653555.docdoc 77834d629af8b45f85ec232e03fab3cf97e78e448b23fe48bc93ad6a391f3c90n/aHeodo
2020-08-19PO_08192020EX.docdoc 2065474363cd9df4a104d020800f2f1523e4cdbb0602b68434bb6cf61b62398dVirustotal results 16.67%Heodo
2020-08-19DOC_OHK_080120_ZIK_081920.docdoc 8cec3b93eff7809fb7cd1ac496b3c62702625511c0f52ac2aa79894af7801ad0n/aHeodo
2020-08-1975167785.docdoc 3ae29b3f7f29f20ad0073a44572a88b7aafe19da62e0a8d8d8a04213945f0e80Virustotal results 16.39%Heodo
2020-08-19DOC_PO_08192020EX.docdoc 0497b08002a87140203cebba96112f295125ba3e002ada7880e6937d484d72a2Virustotal results 16.67%Heodo
2020-08-19REP_27287984.docdoc bc5f7faf4b9266301e7e8bd3f6ad494c0b34e984278b3a484c6c46d845d9a28fVirustotal results 16.67%Heodo
2020-08-19QM_DDQ_080120_RXL_081920.docdoc ee7fba4103591bdb24625094a6325f7d1bc7371f7e5a4c119cdcfe56a88ec967n/aHeodo
2020-08-19INV_FTP_080120_JZG_081920.docdoc 28c14d0d9ba56ed508a4312e9098de46caaa153eb89958b6a8e027476ee3e6e5Virustotal results 16.67%Heodo
2020-08-19DOC_BY9060967344KY.docdoc 031a67c034a76b31c3fa139f4bbe570bc3a74c61c3b901164fb60733db2db9a1n/aHeodo
2020-08-19UII_UBMQBRWK6QP.docdoc 6ca7b784b7754fff5b22f3944f8be3abfa721a3da2e8944d3576eb3bb078f046Virustotal results 18.33%Heodo
2020-08-19941583701581449877276764.docdoc 66998f1cd1f1a729d50a2c747f4005519af186667f7d7e9b84a3e7567508976bn/aHeodo
2020-08-19INV_PO_08192020EX.docdoc fe9a97b801776daa701c134a2fc01864fd5a960dc27fa19ba13332f959362ff3n/aHeodo
2020-08-19DOC_05953716.docdoc 2b7a49352e724f27cd732cdceeb85765bee1e1b37a8f0e554eadb1d7388e6831n/aHeodo
2020-08-19PUWS_MEP4J2Q2.docdoc 25155c0bdbb328c6e4d68df35320b627b978d287c658085bc03617601fff804bVirustotal results 16.67%Heodo
2020-08-19BAL_251093499.docdoc c84cc34fabe449b4d98254989e104711653a48f902a35184e496f2f61508fc55Virustotal results 18.64%Heodo
2020-08-19INV_817024813798651.docdoc 6c565f07002b82c287ed1f4c316b8ed204766e4fbd223250f1c2cc1f110b7bdbn/aHeodo
2020-08-19MBA_080120_NKE_081920.docdoc e7801b2180c3386d049135af6b5e4ad14c56a7a6eda2cf87dcf474e3ce9c4e39Virustotal results 18.87%Heodo
2020-08-19VR_AUI_080120_LBZ_081920.docdoc 0099a00ee33efc8e25e68b3bd2862656ac4819416a7ce5252da75b326480ece2n/aHeodo
2020-08-191CVMN8HWL7K.docdoc 9214a210e7bb43bd59a4e2bc93a6e020db78e48665cabba44b5128d186f40b4fVirustotal results 18.33%Heodo
2020-08-19CF0657518601AF.docdoc bb8f4400df61e199e8f1c8bf7bc8f4409d7ad9eae9af6cc6ce8ae32bcb99be8bVirustotal results 18.64%Heodo
2020-08-19INV_PE6027304554DS.docdoc a3cdf0d9417faf332e124ab24792ff79fdd1dcd6f24bfb381b70d9b735e6cf18n/aHeodo
2020-08-19Q_KAC_080120_LTG_081920.docdoc 2d30f7b645573ac0ead27cfbf698563ba1fb14854a2ea4cdf5c30c5d750153fbVirustotal results 18.33%Heodo
2020-08-19REP_0361986796728441473457.docdoc cbcffeaf57dc69c22c4c1f6eaa6b2102c764aa8b0080b466aa95969f3c0283e1Virustotal results 18.64%Heodo
2020-08-19QYQ_20410246460853167729.docdoc dac9381a81d9d239f2a341b839cdcd469921f650f74da24535abe92d78951118Virustotal results 43.86%Heodo
2020-08-19BAL_PO_08192020EX.docdoc a1b39bb8e04288328a8785f48219abb0b12a2a6330e2192973405a2bf6682644Virustotal results 46.67%Heodo
2020-08-19REP_SUNWTZ21E9J8D6.docdoc 6b59c1ac41886b7b520cb46b401444b04190a20523acdfa15e3c77701c51660dVirustotal results 48.28%Heodo
2020-08-19KSD_080120_KCH_081920.docdoc 9300711f5a35bc33dab0314d010f858ea9385b9b41b60e8db605a367ee901d57Virustotal results 48.21%Heodo
2020-08-19REP_WU4700056533YG.docdoc 882600fee7e0ea4b30699f07b2c5237c9cb80b2ed0bdd471d055f7b450565272Virustotal results 46.67%Heodo
2020-08-19FILE_504769747682787998.docdoc a7fff8bf3bbff829f3388723e5da242e32d59f0b648925cb3ad55dc7db5697eaVirustotal results 46.67%Heodo
2020-08-19IKS_080120_HGQ_081920.docdoc 6756567ceeda5670054c44e707aeb67389b6bcf82b1bd7406461c520fc185bc9Virustotal results 47.46%Heodo
2020-08-19NR2059070867AD.docdoc 2efc148d28ccc7f78e2f598072e171cb43bd6703a0be1abc612c36f1420ec1d0Virustotal results 47.46%Heodo
2020-08-1921142923.docdoc ade0c61c5a90ff1c6aa1b54b0f5d9e29382b98feb206f3b170724aa6e34cb389Virustotal results 46.67%Heodo
2020-08-19L_98334450.docdoc 0e79daf2a9f00edeae140c5e513dfe381e03f54ae3fec2dae7b2bd9f005b4f6fVirustotal results 46.67%Heodo
2020-08-19PO_08192020EX.docdoc 5b39d05fd1a75574a20fce09addb52c62b766bb08f8812b8d692936918ba780dVirustotal results 46.67%Heodo
2020-08-19R_40522051.docdoc 13ecb0280410d83e2d67d9f049fe85af186a0c9959c316c90f3ec327a9ab244dVirustotal results 46.67%Heodo
2020-08-19BAL_4UB6VBWJ5PO.docdoc 28e4449bf2803e0d685599cbfbd23a03ac3f9a69b25f6a2669de4ce252de4073Virustotal results 48.21%Heodo
2020-08-19BAL_OAZHKEO.docdoc 546326b982f8d4e1c2af1b80d268127974403aae48e453ff6d8f1820120a8d0fVirustotal results 45.76%Heodo
2020-08-19AW6AYN7Y.docdoc 94fe6d0cc1723a60d8965c606027ad0283a60c1f4677cf33c8cb85fd202bbc60Virustotal results 46.67%Heodo
2020-08-19IJGM_PO_08192020EX.docdoc fededa8f56c791fe22493104398edd8f25c5b47a5668857fbbe72e6ee16ede93Virustotal results 45.00%Heodo
2020-08-18REP_TJP_080120_ZVB_081920.docdoc 6e7bc5b464486368fc64b81be80628536390d77832adc42ae658a9ec6642f2b4Virustotal results 45.90%Heodo
2020-08-18MLY_080120_RDP_081920.docdoc 6c9d3d58e28a1e8bbf0d1c77a0bbb7f6c71a55ac204041c9f1f8e372b19df91eVirustotal results 45.76%Heodo
2020-08-18BAL_KIC_080120_NNS_081920.docdoc 805f00873a643dff1edc0ebb808bcc771a6641780897a3d7732b01444b2ec3d8Virustotal results 40.00%Heodo
2020-08-18A_GE6259492378QO.docdoc 7f32822db30d0d6ab9d5ef5dd261b4629d251e40b69b860a30fa476c0e7b8d0fVirustotal results 40.00%Heodo
2020-08-1876637319.docdoc 6cbbdaa0e24876ae422d284449759d09a5bba350158e7e489ae806620bebb00bVirustotal results 38.98%Heodo
2020-08-18INV_VD2039593939BF.docdoc 7457d0d48a6875b4b70d817d7542bdd94e000e4293907a48b014189b5e7bada5n/aHeodo
2020-08-18BJZC_PO_08182020EX.docdoc 1ab945db51701046ee561291c84c12844c96cad17d38c044915bc3657803b75en/aHeodo
2020-08-18DOC_9840357617.docdoc cab6349ac0df4084c7ff95a5e68f961048537236c2602cd3aff11482fb0d0af0Virustotal results 40.00%Heodo
2020-08-18PO_08182020EX.docdoc 62794a5ebcf750a653cae525d04e012ab0edbf36a92f7b4e5c956afaf84db63dn/aHeodo
2020-08-18JY5627915488WZ.docdoc 455f2ce2d5b18bbce7c1ff8a8eec0e143f98fe0c1e0a4d289aee56f5f8e33e4bn/aHeodo
2020-08-18JUAD_EQL_080120_WEZ_081820.docdoc f13b6d284eb7046fcbacbc7d199359ef96282da973fb4baee25c10fe1f96d9b9n/aHeodo
2020-08-18BAL_PO_08182020EX.docdoc 2afd7cea805a330a133af9bf275a0d23de175b15c5cb194c042da07bc59f2cfdVirustotal results 40.00%Heodo
2020-08-18T_GXP5D68TKL4DMKJS.docdoc de5408a8f5bdfe07fc7968fb74f88eb396f296bb04e46861cee727b23e040ec2Virustotal results 38.33%Heodo
2020-08-18DOC_WB3322334590YK.docdoc a7e09fdce8bb372722c2e23e9a17db2d7ebbd56845a8a4d640485b9597b271f5Virustotal results 37.70%Heodo
2020-08-18DOC_B7QRPM308R.docdoc 010999a8438ea40d8012240b03d2ced196d695c0e6ddcdb43bca7d28693c16dfVirustotal results 35.59%Heodo
2020-08-18F_PO_08182020EX.docdoc c455c9ceadc985baff4abfb5ffc8f7df42352258be49101b1d45639abf3bad97n/aHeodo