URLhaus Database

You are currently viewing the URLhaus database entry for http://nitroswap.com/author/EJ/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1990517
URL: http://nitroswap.com/author/EJ/?i=1
URL Status:Offline
Host: nitroswap.com
Date added:2022-01-19 22:06:06 UTC
Last online:2022-01-19 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-01-19 22:07:15 UTC to abuse{at}cloudflare[dot]com)
Takedown time:8 days, 4 hours, 59 minutes Bad (down since 2022-01-28 03:06:51 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-20436426101479.xlsxls a1d4e9c497ec94e9c1182741b7096c47396c0057014747c17e618e82538eae72Virustotal results 17.31%Heodo
2022-01-2056479078479.xlsxls ceafd90b9d8a1fa4ba9b8f81f1c3b138570c8768b75ac1ef0d3bb126cc6d497cn/aHeodo
2022-01-20716871605317.xlsxls 0e985904fc4e727bcdcb2cb67a0a1c9cdb6e659de8ceef36f331f05ccf81e5fen/a Heodo
2022-01-201240706806651.xlsxls 6802d962671c5de15753c1ed53a75e0993691d66b44426226d8c24ad5b667664n/a Heodo
2022-01-2041560688455483.xlsxls aec8e11077b3155936201e3011ee82bc5f9736383849d3070901ffc60cd62ca6n/a Heodo
2022-01-2039821654833.xlsxls 5a1489af62963b07c39a536bcd6d0912b6e83fe7c5f14f9335660d0ec8e655ccn/a Heodo
2022-01-20671066293694697.xlsxls ef8562b363253996a0a2f5902bafc7d8f345d05e3bef28c3791c48e10d14c78bn/a Heodo
2022-01-20539384354193.xlsxls 042d4b59153d75848595e19536f77437dcb1a52e851dfa507596159c99c74adcn/a Heodo
2022-01-2091376178531747336428.xlsxls 3a62645fb0fa509d7ef475480849b1ae216c24ae4868b71e0a9b4cb2e9deaac6n/a Heodo
2022-01-2068952802650315.xlsxls 93e3c367bda53786b1288bbbcf96770a8865d3b8a3132a90a33d10bc91a31009n/a Heodo
2022-01-20907548495133189523.xlsxls 1bf2fd1660e48510cf19cfb1f9211d2af3aa71753d2e3d7dd047de4296a7f678n/a Heodo
2022-01-2074397205192.xlsxls f43c7941272a2ffa5252dd03a62fcf67ebcedb4eeefb62b83e282df408cbd899n/a Heodo
2022-01-2074255405226791467739.xlsxls 89ac9846e80ef313bb3b47ec5d39721a42df0322689ec11f3fddf2ade55504ccn/a Heodo
2022-01-2006210321065491170230.xlsxls e5cbcea06c596c35b817e23de0dd39377dd88d951c16e0ff97d2aea7aa748e38n/a Heodo
2022-01-206644296238814536.xlsxls 2543badd28fc1740c4784e313fc2627c75b8ffa4ab59f5e79dd74e37973a72ccVirustotal results 20.69% Heodo
2022-01-200099787898.xlsxls f0e3c55ec4382d23917bb1166f8ee92b8bf2e9f8f07081506b47de8c14fd36b3n/a Heodo
2022-01-2088649200613160349.xlsxls e10cc43ac64c0bb9759a41c29d470c2c4a8a4b1c7c680d1785c14e635ca01aa5n/a Heodo
2022-01-20426809640207803.xlsxls b73bd971894582e6cceddac7aa53c67b0266db1737bb1cadc0564f2d35fd84dbn/a Heodo
2022-01-207506397753132488807.xlsxls 5b9df9cf37e1922cc729345ae55312a8abcc8ca8911323da2a49aa7c7a8f2ae5n/a Heodo
2022-01-20655973249714165835.xlsxls 655c64e52eaf67ca0c8fbab1fc2f1a5b2b0ed7a9fcb24d4b72af657167319bc6n/a Heodo
2022-01-20783396812948458029.xlsxls ffa7963791fe7d82893083a2d6d56830adadc54f6e5ab8996f30fd3ca472afe9n/a Heodo
2022-01-20785479871519584823.xlsxls aa68c6fe9d1119990397dbc46556a017468ff65d4e017efc019f94aa1a03e4efn/a SilentBuilder
2022-01-204536945553757859.xlsxls e671c9b26b2b246cc5789ad0668750051048ef78c28d162f0af953a4f52e6aa2n/a Heodo
2022-01-20209969812474899.xlsxls b1ee7aa00b7884ed02a3f5ddc07419b6e8dd6e7382269d8cc5511f06431d5eafn/aHeodo
2022-01-2045507454538155242.xlsxls 7c70964c132fcec35a067531e95526ab0826f3e77ee4ed6ef1eb2a3b2420c68cn/a Heodo
2022-01-1934785477637593632294.xlsxls 88c52c4d1940f16219506b7c10ded1fa314e5f05e0aa03cf441a7dee30f41aa6n/aHeodo
2022-01-197494687858821.xlsxls 0a00bdf339b8c80c70ccce5af6bd26246d2775bebcd7347412ca5761479b7952Virustotal results 28.07%SilentBuilder
2022-01-193926744406.xlsxls c5ca000d7bfcf3b1a413dc211b2f207404f4a82351d1f3d07ca048fa9b98d063n/a Heodo
2022-01-1992349355134.xlsxls c48a780e4664704fea5ddb053288a405a134644cd21cf1b2a21050df56d28d94Virustotal results 17.86% Heodo
2022-01-196719408545.xlsxls 4f48ef3036b8e2b724cbf9ec618f35baf7cb5e2017dc5fae4825659a28b58e68Virustotal results 18.64%SilentBuilder
2022-01-193391411048.xlsxls 9395907b748740960ac38d3ba4faeb6248b7953da69f834daff192bb2ff1fff6Virustotal results 16.95%Heodo
2022-01-193187132275022.xlsxls 48645d321856636203f209613f50ae87684d0e12bae3421baf88c25657717abbn/aHeodo
2022-01-191246519502693255745.xlsxls d507a6a85d0f208c8662e6cde4d1bd419daefd9b5644146e4a51546fa37131abn/a Heodo