URLhaus Database

You are currently viewing the URLhaus database entry for https://nfcstream.com/ybzq/ZuIdkLtAGeoDPIDQKdCkvV7QHM19/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1912373
URL: https://nfcstream.com/ybzq/ZuIdkLtAGeoDPIDQKdCkvV7QHM19/
URL Status:Offline
Host: nfcstream.com
Date added:2021-12-23 01:15:06 UTC
Last online:2021-12-23 03:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: waga_tw
Abuse complaint sent (?): Yes (2021-12-23 02:11:47 UTC to abuse{at}ovh[dot]net)
Takedown time:2 hours, 7 minutes Good (down since 2021-12-23 03:25:00 UTC)
Tags:emotet link epoch4 heodo link SilentBuilder xls

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-233931888581261628.xlsxls 22f3dd823009e3b1c3547eaf2ae78c54fcb499e4a0055c5db099ea28bdea93acn/a SilentBuilder
2021-12-23411482395322718.xlsxls 9d4d4f0a7f353f0ed7ce7138c8e954d51e5f08f5862d5ad570fb427d0c57ae52n/a SilentBuilder
2021-12-23333625607.xlsxls 58b6f1c79906e917ccd06eb3c83917af37d249284b707e1bfe6220d245c057adn/a SilentBuilder
2021-12-23101191933.xlsxls fc427adb111a2cdd28c3799b619887f125d8c79900419fdd0918cb4f09084ab9n/a SilentBuilder
2021-12-230383474.xlsxls 46549909e329faf4ef851f602d8c1091c253897e0292ae05d83b73da7914077en/aSilentBuilder
2021-12-2345577380.xlsxls 46d6a384fe1773327c74c5e6daf03b4e1346cfef7e79d6e16045eccea064acden/a Heodo
2021-12-233572682788965104.xlsxls 5eb66d76f40bfc2a8b27ae16d451f2f8c3eddb77bf14e8fa7006f0d7ed9925c2n/a SilentBuilder
2021-12-237471029705.xlsxls 7bf4ea88fd12ab28b16f6d7817d87f8b81b837d0c6e6640c4044ca3fbcbe7f2dn/a SilentBuilder