URLhaus Database

You are currently viewing the URLhaus database entry for http://2nf.me/dl.php?id=13 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1474142
URL: http://2nf.me/dl.php?id=13
URL Status:Offline
Host: 2nf.me
Date added:2021-07-22 18:27:06 UTC
Last online:2021-07-23 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-22 18:28:06 UTC to CloudFlare Anti-Abuse API)
Takedown time:12 hours, 31 minutes Good (down since 2021-07-23 06:59:48 UTC)
Tags:Dridex link msi

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-23n/amsi 48fb1b00b40c4855e4fc7443128fc5841bb7d7cf9b06f6832aabfc94ca12034en/a 
2021-07-23n/amsi a38477583f2c2fd9b07c6c5ba26473893bfa3ff638abf760d933902eadcdcbc6n/a Dridex
2021-07-23n/amsi 8db10be9756e820c8f36a8904599edc18f7a266f293cc1e6a4654e3ed58e0f1fn/a Dridex
2021-07-22n/amsi 87f07d9cc7969437afb06529ae8c0412b142c01965a0b394f64c6dec1cc60e62n/a Dridex
2021-07-22n/amsi 4beafaf966e9f4501b2ac554a7bfed228830f1eeec4486b04a5f0f888b1b5db7n/a Dridex
2021-07-22n/amsi 825ef88dad5d42b78658ca8587f057f8047004800e5eb7513bc408d9937549b1n/a
2021-07-22n/amsi 5e11b34ddd6ffc2504f31b653bf037522d8cf7e5ac946edbbb0799e683e32f1bVirustotal results 31.67%