URLhaus Database

You are currently viewing the URLhaus database entry for http://sofiariggen.com/js/lm/6rVkATBaXx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:729983
URL: http://sofiariggen.com/js/lm/6rVkATBaXx/
URL Status:Offline
Host: sofiariggen.com
Date added:2020-10-21 15:50:15 UTC
Last online:2020-10-21 20:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-21 15:52:57 UTC to abuse{at}mediatemple[dot]net)
Takedown time:4 hours, 27 minutes Good (down since 2020-10-21 20:20:05 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-21Attachment 20201021 32152.docdoc 8537810517cd5dd09f54c8b9b8ae8800be7178a6bd57e6b35effba2f254dc891n/aHeodo
2020-10-21File_20201021.docdoc 4495e02eb9c67c54be349e4212281f1c652234240082f96a9071ced88e8c6f9cn/aHeodo
2020-10-21Mes_20201021_KUQ2056.docdoc fadd46cf2d24d37774a0476e63f3deab1b22a0be761fcf7e250a25dbbec858d7n/aHeodo
2020-10-21rep 20201021 WSV3699.docdoc 7d812b3579d4c3f9b7d05487763dd9253ce70bebca34b9d46735f76435e3fdd0n/aHeodo
2020-10-21ECA8545_403027.docdoc 00ed59c9df48338ff3a5a699c8e8f21b57b36396088820dd0e3b51382a6e3016n/a Heodo
2020-10-21List.docdoc f6cca707c3dba7f0fb0a216c7910dd5b8da4d5601fc47156afc04c9e516d8284Virustotal results 33.87%Heodo
2020-10-21INF 603251.docdoc 1c9f16cb8efe6d27052e6e20471366e7516176926ff0f7c04038156016be4b0dn/aHeodo
2020-10-21List_234.docdoc 9108ca23d908dda4dec8fb03dc119e054b45ac8bef157933a4034f5992ca7ce7n/aHeodo