URLhaus Database

You are currently viewing the URLhaus database entry for https://nsd4kt.co.za/swift/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:295003
URL: https://nsd4kt.co.za/swift/
URL Status:Offline
Host: nsd4kt.co.za
Date added:2020-01-22 16:42:07 UTC
Last online:2020-02-06 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: spamhaus
Abuse complaint sent (?): Yes (2020-01-22 16:44:03 UTC to abusepoc{at}afrinic[dot]net)
Takedown time:14 days, 12 hours, 4 minutes Bad (down since 2020-02-06 04:48:22 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-24PAY_NSW_010120_OVI_012420.docdoc 9cf4a06c5e8facb8fea0a5a2fc8b17c6fbcc11eafc143e9081e6170f0224a79aVirustotal results 28.33% Heodo
2020-01-24BAL_060U5NQNALVF6FW.docdoc cba73ededc4676a3fd5ea386a62854670752212eedaeea52fb505d3fb96068faVirustotal results 26.98% Heodo
2020-01-24L_0311344691005017624796.docdoc e091702f3ff978403bace9f3dbc7dc332467f18f409117d56d857f4eb1f8b4a9Virustotal results 27.42% Heodo
2020-01-24INV_PO_01242020EX.docdoc e848ede38876ef2dedf485fe2818f53dcfc4a4cdd21062ce8ff7a53d2f8e32b1Virustotal results 26.56% Heodo
2020-01-24DOC_92721608.docdoc 789f39cce8f34ef92a1114d703e66a8894c7d3025572c148161fa467d1b6fe81Virustotal results 26.98% Heodo
2020-01-24FILE_XA5871431562YO.docdoc 6b70256ec87f79fca124f33a26e5f745547c178cdb9ddd66e63f073948449bb7Virustotal results 26.67% Heodo
2020-01-24WWKD2V0KE.docdoc f460126fea6eb56b1bce157ed383d7f459d0552fd60ff370d479a13ea5f1894eVirustotal results 25.00% Heodo
2020-01-24FILE_PO_01242020EX.docdoc 1e1233341f3cabaec36e9a7aedf295488edea6d4cb7f27423040c37bd4d22905Virustotal results 25.00% 
2020-01-24REP_PO_01242020EX.docdoc 29b29c20b500917ff965ae4f5112e0307109c243e724f0af4f6dd6634a31f07bVirustotal results 25.40% Heodo
2020-01-24BAL_GA74IJ1YZ3RJJ.docdoc 6a538f5d087e49e06be537ade4bb480a0729b86fb9d35e34df163e81e7b10c6aVirustotal results 46.03% Heodo
2020-01-24BAL_RW6225651125TX.docdoc bedffe567bdec300da442d0c24e30f94beca6e30401410ac906a60946b63fe9bVirustotal results 46.03% Heodo
2020-01-24RP_PO_01242020EX.docdoc a8c8f2dfea2c31f160cb6b05c9dbe6033df6bb6119ce43c2a4c71783d49a061dVirustotal results 46.77% Heodo
2020-01-24HSW_010120_LYZ_012420.docdoc 423b7b9ea002165c61b8db1259dd9bbad8a0dae6fc5401a591d206e01c4cbe05Virustotal results 43.75% Heodo
2020-01-24EM_78323164.docdoc a5a83502716a69849058507848fe4dd4f3282eafae03e6fffb7628d453f2966eVirustotal results 44.44% Heodo
2020-01-24R_PO_01242020EX.docdoc 1ebada079a4f6cf5839b6889fb6348b438ed1ff5663a7f5228855c7527699161Virustotal results 42.62% Heodo
2020-01-23FILE_PO_01242020EX.docdoc b4b863bb79c7f22ebbc9bd5183fd67c6b9e020e15eb75d24fbb6179a57e16125Virustotal results 38.33% Heodo
2020-01-23ST_37246575.docdoc 826405ab23ee390f30113412530dd8fa36957b7fd600826efea19868f3f20b3dVirustotal results 38.71% 
2020-01-23EKTD_SVS_010120_KKG_012320.docdoc a89c16c64bda3267164f8e815f3d72ea9468eecfcf968f4144f2c53435bd787cVirustotal results 31.75% Heodo
2020-01-23RP_555R5WA89LUJLJ2L.docdoc a48692ac69029e43c34f02d17df8103b91037aabd7db83fd7ac40cf461ebe95aVirustotal results 31.75% Heodo
2020-01-23ST_BN0418785353CT.docdoc ac9dd4e543ca8121fc28dcb180e615d6e19fa44715e30f4af82315d38a7bb0fdVirustotal results 30.65% Heodo
2020-01-23INV_44655466.docdoc f66076ecc005f5bba5bf8dbe3c7f85fee5b3cb20a0b19f18f316d94ce160888eVirustotal results 32.79% Heodo
2020-01-23DOC_GC9232378673DM.docdoc 9e3306d0c2972e30cd0f123f9f41865e99a4eb40075361e1eb85bb783e722e38Virustotal results 30.65% Heodo
2020-01-23WDU_010120_ECR_012320.docdoc e1380fa81c9ecf98aea7ac2b25a691e612910e8b07ce4adf982136d30d00907fVirustotal results 29.03% Heodo
2020-01-23GXZ_010120_RJN_012320.docdoc 1fd3b81ca3d30c9017a44eef7861ac902255560376ba3a1524e22f8bee5fcaa7n/a Heodo
2020-01-23PAY_PO_01232020EX.docdoc e81dc8d25679f4fea9a21338bd9612d079418003d3304029950f146696624ff7Virustotal results 28.33% Heodo
2020-01-23SW_XW3522530660JA.docdoc 667a70d5b2b7840b6e7668f011e10182bbd2103b7885111ed07392813d2af6d4Virustotal results 31.75% 
2020-01-23ST_4PNKQAZLBRJ06N49.docdoc 73ec09ba4b743dd18b184e5c7b2f4bd79bcefdc5df159653c75ffb5e05d7559fVirustotal results 32.81% 
2020-01-23FILE_58KG13Z3PWP.docdoc d744c1d20947939b65a0dfa826e7b011a996521e9aea99c7a6be5531639e82eaVirustotal results 26.98% 
2020-01-23FILE_71578567.docdoc 3dddeb95fb091ba145a2b0705117b8ecefdcf833024674c193dbe2ccbc4c6bd4Virustotal results 20.63% Heodo
2020-01-23INV_FY6064156133HG.docdoc 79950a40bf62dac08fd1adbb9c8aba2b8db0e05de9829d485ac3a51302d546a8Virustotal results 20.97% Heodo
2020-01-2316162764.docdoc 260b5a47eceb11eaeaddda02644c85294da44e3eaca951d45152e1db6b9f1c79n/a Heodo
2020-01-23H_6156302532960281.docdoc 627970068806ee557b861c46c5f66f04f0985ad9caddd21dc3c8e4682108042dVirustotal results 22.22% Heodo
2020-01-23ST_42884048.docdoc e50ca42cece8459c5ed1bf0713f580775a5bea5fd9384b1e5f284e52f2db08b1Virustotal results 20.97% Heodo
2020-01-23N_MU8354896906NY.docdoc 425dc31b9652f83260c405be0755dcc694bee850e115c19c8aab134a108c8ef3Virustotal results 32.26% Heodo
2020-01-23J_VU5657772227GP.docdoc 9af2280771f435166b53ce4682f2cedf9072877a0fd338920e1a7ae4434c47caVirustotal results 30.16% Heodo
2020-01-23DEW1UKL9WQ.docdoc e63aa1c3401d847d86e7d7a0183b1b09932060991feb79d6e2b775a27f30c36bVirustotal results 30.65% 
2020-01-23DOC_0827126958732678421929593.docdoc c902819826aded735fa4ea8025d726e7b868dbee374343fde8e6b5a3fe6733e0Virustotal results 28.57% Heodo
2020-01-23BEJ_010120_GEG_012320.docdoc 57f80688fb69b44c38dc1526796d523074e95761263f1c762f83cbb491b369a6Virustotal results 28.57% Heodo
2020-01-22SW_DDE_010120_FDQ_012320.docdoc 62fb677b5e795566ed8b06713d070488a08cffaccd527993f327cb931929ea2eVirustotal results 29.03% Heodo
2020-01-22REP_SS7146504736PZ.docdoc 669eefc104d806bd76c96aea4774af65b2fdc557d7bb93f72910014b7093d9c3Virustotal results 26.56% Heodo
2020-01-22FILE_GU0264806211EY.docdoc c551f97351c13e0f158f87d3c11bbdb5b9f2b2b10576509755d225e3f3bf46c7n/a Heodo
2020-01-22PO_01222020EX.docdoc b745d82dc51876677c63b0f9599371242bf49ec12008015adbeed348b27d5307n/a Heodo
2020-01-22ST_PO_01222020EX.docdoc 1acea02225c6650692c85051717ea09e03791a57fe39ab10730263373f7fbde5Virustotal results 28.57% Heodo
2020-01-22YQ_WAV_010120_JFT_012220.docdoc 3f76bffed904f6d76aa34ff1cbade88f10318f165b79082e3f3b9101bdca3ae6n/a Heodo