URLhaus Database

You are currently viewing the URLhaus database entry for https://instagridkit.com/wp-content/Scan/OK9JGcnujS2DcIdjUFZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:718645
URL: https://instagridkit.com/wp-content/Scan/OK9JGcnujS2DcIdjUFZ/
URL Status:Offline
Host: instagridkit.com
Date added:2020-10-19 16:13:04 UTC
Last online:2020-10-21 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-19 16:14:05 UTC to abuse{at}contabo[dot]de)
Takedown time:1 day, 12 hours, 29 minutes Poor (down since 2020-10-21 04:43:16 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-19Arc-SB42996.docdoc 3207073cb0a36893fd66ce7369e682435effd0a709e6af1dababb08e29185e2eVirustotal results 37.10%Heodo
2020-10-19inf 2020_10_20 52186.docdoc c130edaae88b1e0fd286f27921028a747da2ed741fcd5974dd30e15bb3457519n/a Heodo
2020-10-19EPK2387 2020_10_20 2520.docdoc 979236f4d2d99e9272c6abef5b246723ac02e7bba9dc2aee883c4c907fe4b362Virustotal results 37.70%Heodo
2020-10-19Mes_20201020_XIE8218.docdoc 71e4ec3e11f734f0ce73a46fcbe3079f4418154382d6389da01859b9ad74bd99n/a Heodo
2020-10-19ARC-2020_10_20-L4169.docdoc 2d5db19f14ba5acd1290b35efceb0d2a5fb4b948cc627ccfd3fffa7e41136fb1Virustotal results 37.10%Heodo
2020-10-19File-20201019-9050.docdoc d6fc8acb0c1a4b38f100335349e71cfca14003134259cd7798a9d50fe45735eeVirustotal results 37.10% Heodo
2020-10-19Arc_SIK809012.docdoc 31c64f6a21d4a14319fdcafa6eb86d6668b5968e832b79b5dead97973eb7b006n/aHeodo
2020-10-19Mes-2020_10_19-NQ44478.docdoc eafa3440b1b3cc0b658086ee26210d96b6da49caa2d6ed3ba7b1ff285c60350bn/a Heodo
2020-10-19INF_20201019_EQO083.docdoc 4a1656e05641ecf363b724ae37a92d0ca73aed83f75f0a1b62ef1c90fa1560c1n/aHeodo
2020-10-19inf.docdoc 2704ee507c3054f747c58c1ef0ed29424a2e5eab1a0920d60e3421155bdb2195n/aHeodo
2020-10-19Attachment 2020_10_19 C87094.docdoc f579a6044d9f764bd59abd53771cb8846744e24997e2d83e41a17a445578826dn/aHeodo
2020-10-19Attachments 20201019 UC3331.docdoc 67be51a6de7a956a41d7e574bdf617701645afcdb8f0b1c43ed96f5013d60c0cVirustotal results 35.48%Heodo
2020-10-19inf 20201019 ML174.docdoc ee4d9edb2370e384fb5f36330a42d049a086408f2c0d7b59818c8f7cafebbbc4n/aHeodo
2020-10-19Arc 35732.docdoc 92353815ff999cb487b2007b517962fdb9b8c87ac78f64c95f68f6985ef1039an/aHeodo
2020-10-190675PA_2020_10_19_829479.docdoc f589f6fecd0bf2407976afcc8a58f22f29f89aa5648defa661b595d0e0cc39c9Virustotal results 34.43%Heodo