URLhaus Database

You are currently viewing the URLhaus database entry for https://npaperjoy.com/new/c.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2947473
URL: https://npaperjoy.com/new/c.exe
URL Status:Offline
Host: npaperjoy.com
Date added:2024-07-10 01:52:09 UTC
Last online:2024-07-16 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-07-10 01:53:14 UTC to abuse{at}namecheaphosting[dot]com)
Takedown time:6 days, 7 hours, 40 minutes Bad (down since 2024-07-16 09:33:22 UTC)
Tags:32 exe NanoCore link PureLogStealer

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-07-16n/aexe d3f7e200327d65a5f4304f30f5795b37bef0d5f0ab3cc7ae9a29785382277c64n/aPureLogStealer
2024-07-15n/aexe d018983432f75f7768fa0f60416f3f3ddac67eb14cbd10ab0d46ac6abe619fa6Virustotal results 33.78% PureLogStealer
2024-07-12n/aexe 8051c628e55f885bf79ebd90bc8af52eb3451f1d4ce362f810459a91f45d40b4Virustotal results 32.43% 
2024-07-11n/aexe 319bff6d833601a7f1db75dc79c6cd3f0df55c67c52fd989d5c1bf1b5ef5bc69Virustotal results 23.64% 
2024-07-11n/aexe ff02ce95ce92934b9bd5ab657c70a93909e35194c4efcd6105add3dc2fe74f5eVirustotal results 31.08%NanoCore
2024-07-10n/aexe ac5e61786802fec0c00c05fa0af6310a8968939dd0fd73eb105562bd72b04d1eVirustotal results 25.00%PureLogStealer
2024-07-10n/aexe 39acd505663ef230a0871108eb33536dd87367ef886c1f209784e7434a930346Virustotal results 35.14%PureLogStealer