URLhaus Database

You are currently viewing the URLhaus database entry for http://rigatechnologies.com/wp-includes/8idgTx/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:974664
URL: http://rigatechnologies.com/wp-includes/8idgTx/
URL Status:Offline
Host: rigatechnologies.com
Date added:2021-01-23 00:18:12 UTC
Last online:2021-01-23 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2021-01-23 00:20:03 UTC to CloudFlare Anti-Abuse API)
Takedown time:13 hours, 47 minutes Good (down since 2021-01-23 14:07:25 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-23CPFCS7UM1FT9.docdoc 526866190c8081698169b4be19a6b987d494604343fe874475126527841c83a7Virustotal results 52.38%Heodo
2021-01-23T0Z21OYCLELT.docdoc dc1657890758c8563c82d9c1bdb8aa05bc4c965868247d1ac28334925e1fe12cVirustotal results 52.38%Heodo
2021-01-23JWHNEIMOB0QZ.docdoc d8ce6bc970178e61cab2dc65747d72cc90c005e63a058466f561d1348a1fa140Virustotal results 49.21%Heodo
2021-01-23U29988CU1P.docdoc b5503af31ba54c8572f00098487768ecb885e8b321974aca44c71333d9db1a6bVirustotal results 44.44%Heodo
2021-01-231H6EB1DYG.docdoc 843ac5a5070a8f77eeb150cf7963ea5a66dd5763b0e3ac3d775333219fa5b773Virustotal results 49.21%Heodo
2021-01-23PUYFM0.docdoc 3b8c1a7288a8940c4785141389d323f7949b9639ca7821ebad1fc2182a2acf58Virustotal results 48.39%Heodo
2021-01-23DV4GQDPJ2OBA4OIN.docdoc d24e032bf95e95b0c1325688cb50b3eab851e90b9350f1a031668dd2bbfac3b6n/aHeodo
2021-01-23Q3HOY6516R.docdoc 56e78f5aeb76d3b2002f79b51c0344a1bc95e0c171a56f5e7bae43028543e1cfVirustotal results 48.39%Heodo
2021-01-23DDNZ06D6QWSXIX.docdoc 20b1f1c932f9ac88685c65ca2ed2d57ba42e6cc5d643c567fbff933e64e09797Virustotal results 46.77%Heodo
2021-01-23W3OM80PF37.docdoc 1e6cf8d2575be1847bd2c4e53b2686b8346c940c315c68f3dcabe5fc53802dd8Virustotal results 46.77%Heodo
2021-01-23GFHFR6P1.docdoc 8114e0c0eefcbd0cabff86c033ee3649a76d53c8b9418626c49146a13bfe4deeVirustotal results 46.03%Heodo
2021-01-23E6GN04G0NK40HZ1.docdoc d02c5f5315f50e3865102448adebb8353c06fe90d4c08ed09cbac7572a83076fVirustotal results 46.77%Heodo
2021-01-233TIOLUFOV7EJ8.docdoc 06706618f6fb465f559d7359295a2757c1cfd4311ae5ad13d1b3ed2acac1a2b9Virustotal results 45.16%Heodo
2021-01-23XDP2G7NZ.docdoc 025820a98eaa8e45cf4293aa84d11c17f9894efdbdd7f3e2296fec778a5e0f91Virustotal results 46.03%Heodo
2021-01-23PFD51Z3E95F.docdoc d5da4dc5a6a3fc416aca8ffbfaa3b6cb18a1efd11b94eb7f40a584fd96813f8eVirustotal results 46.77%Heodo