URLhaus Database

You are currently viewing the URLhaus database entry for https://fortsa.nl/nsf-mailing/SDly9v/?i=1 which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2118886
URL: https://fortsa.nl/nsf-mailing/SDly9v/?i=1
URL Status:Offline
Host: fortsa.nl
Date added:2022-03-29 12:05:05 UTC
Last online:2022-03-29 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2022-03-29 12:06:05 UTC to abuse{at}yourhosting[dot]nl)
Takedown time:5 hours, 30 minutes Good (down since 2022-03-29 17:36:46 UTC)
Tags:doc emotet link epoch4 heodo link SilentBuilder

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-2959386459406344602409.xlsxls 3ae70ca231fc68caf9b069513aeeed261edae36013ed6fe2f2e5d3ced1e80adbn/aSilentBuilder
2022-03-298184626777078091.xlsxls 723395fe95e3d656d422955edae3e78b38c2665cac6e68947fcbd18817801e4dVirustotal results 23.33%SilentBuilder
2022-03-296570962780430049726.xlsxls 65c22cb7a34b3440d28675d2b3b926b55004765609e52e3c099ab823e6f4ac69Virustotal results 27.59%SilentBuilder
2022-03-2926969576850.xlsxls 81113b572a380caf1d7469e353abb8ea79ec0dfa9c19a9e4add89e0e1cb8fd50n/a SilentBuilder
2022-03-294811030701072.xlsxls f826114223c99e0d29401b4f95bd67ff825dba627a87a19e2c69a76a93d6773eVirustotal results 26.67%Heodo
2022-03-296402163759088032492.xlsxls af9bb5756300ab9d303c59eb0df174e3d1072f7c8d7e0104d84a11aa66a3dc7bVirustotal results 27.12% SilentBuilder
2022-03-2930792136800404.xlsxls f0b04952c2684b719598d0129456554b89af4cc8ec37578bf1e3a3be4540b404n/a SilentBuilder
2022-03-29862711258992.xlsxls bdaaebf955900e2242983fc61d9db8fccdec969587e15dbd3b002247db315fbeVirustotal results 20.00% SilentBuilder