URLhaus Database

You are currently viewing the URLhaus database entry for http://nsl.netsmartz.net/zp58e/Rl/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:302280
URL: http://nsl.netsmartz.net/zp58e/Rl/
URL Status:Offline
Host: nsl.netsmartz.net
Date added:2020-01-30 07:46:06 UTC
Last online:2020-02-11 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-01-30 07:48:02 UTC to IPtech{at}centrilogic[dot]com)
Takedown time:12 days, 8 hours, 8 minutes Bad (down since 2020-02-11 15:56:32 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-02-11Invoice ZG911_911425.docdoc 7554532bbf10222b955dec84aa74f3fc9a2bf3813426c406afda0ea17088b1e4n/a 
2020-02-10Invoice ZG911_911425.docdoc 3afde3a90d1dbe1be1f45d2e0eef254444983ecc8f2d378b43c92204ee0929c2Virustotal results 40.32% 
2020-01-31Invoice-CG2_994605.docdoc 1092c9cc1b0dbf643c81898c30d3034b4db59f49a86de85ced39a5315ce4549eVirustotal results 35.94% 
2020-01-30Invoice-RBT17_860974436.docdoc 528605cd4609d0d5cf1b221aa46efc0d8d75cbee20e5a26390b9adabe412138dVirustotal results 34.38% Heodo
2020-01-30invoice-D45_9979825.docdoc 9755ef1672fe2fea84ded8999cf71bd62d9a3873bd4fa6ddafab57f59f0527f4Virustotal results 33.33% Heodo
2020-01-30INVOICE_0370_239914823.docdoc 18679279d06463ba2ca553b32ba509a6cb62381bda5381ab82d862beb91da074n/a 
2020-01-30invoice_AA7419_10733547.docdoc 68ddd33bfa87185496120195d7e4007b09c04f658553fb64e558b89269d70492n/a 
2020-01-30INVOICE-SYGX383_281121860.docdoc 2e05dae96f07956982b9edba6d64d8668b4ff90f56d548ce2ef2feee40a6e6d5Virustotal results 39.06% Heodo
2020-01-30invoice-HO5_552108714.docdoc d2244062de47de476fa918383b259967e562f4a1587d57d6761f031de2d1d876n/a Heodo
2020-01-30Inv_F46_90727415.docdoc 70029b2efe245977665727cabe746a92f951297bf034a85f96c12a828c18a682Virustotal results 38.10% Heodo
2020-01-30Inv_AFF83_444965.docdoc 35b7d39e8f33f3118f3d205355b739038483d471119ac6d7712d92ad982c756fn/a Heodo
2020-01-30invoice-LK5267_0444019.docdoc 9440498706f2d925d78ed85c677ee615fe3fdf05c7188cf59cadf543e59e0c32Virustotal results 32.81% Heodo
2020-01-30invoice-43_4769269.docdoc e88c11fe26e7cad165df54049eeb12ea47f3cbb684fb6f8a5235d4a379e646ddVirustotal results 31.75% Heodo
2020-01-30Invoice UYH0921_274800.docdoc fdb94ed08de0a00729ab30f9ad646da06ce54d879eec2ea1b5526d8820dc12d3n/a 
2020-01-30INVOICE-CKKU47_1522386.docdoc 5452b9448c3310adaa86f6020c32d6ae4727fce5049f613ad9242e2f35e94effVirustotal results 31.67% Heodo