URLhaus Database

You are currently viewing the URLhaus database entry for https://nxsgroup.co/wp-content/cache/Scan/6a44fb22/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:588322
URL: https://nxsgroup.co/wp-content/cache/Scan/6a44fb22/
URL Status:Offline
Host: nxsgroup.co
Date added:2020-09-21 18:21:07 UTC
Last online:2020-09-22 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-09-21 18:22:45 UTC to abuse{at}ovh[dot]net)
Takedown time:13 hours, 17 minutes Good (down since 2020-09-22 07:39:59 UTC)
Tags:doc emotet link epoch2 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-09-22DOC_O19N3GL71HOL.docdoc dfc0eeec857c03af491878b0b6e9a4fe2dd417135410856677216baf78681909Virustotal results 48.33%Heodo
2020-09-22BAL_213787808461.docdoc 5113e330fdea6c93e3ef5a610817655f04d59be9bb5fa3a4f4167f8ccbb01d48Virustotal results 50.00%Heodo
2020-09-22UL_YUFD4XNDG1DD6B.docdoc 1e31391e20889b755f6f5c06597b3173f49065e7743274c17e28f5bedb95672cVirustotal results 48.33%Heodo
2020-09-22E984JZT4KS0.docdoc 8d49090e5ad1ca487645e8dad8b6e90d267b4a7f5d4cdf4d9c4441d969f088caVirustotal results 45.76%Heodo
2020-09-22Q_32794156.docdoc 57ba4b4fdcb75beec5d6d63154dfda3510f28ac094da0ca819dd8677ca37a924Virustotal results 42.62%Heodo
2020-09-2237575389.docdoc 2441d3572b85985e60886402e103e4f699b34844f25875813f617c2ac28618daVirustotal results 40.98%Heodo
2020-09-22REP_77QCU8BD1AIRNNWO.docdoc f574d141e50f5f004b6d5b2932ce746ef012404c5bf46933947ad0ce3b397665Virustotal results 40.98%Heodo
2020-09-22PO_09222020EX.docdoc fb096cb018d3c66f22c322028f9e8f1f049e9a9eb3531f9e893c3d2522f35951Virustotal results 36.36%Heodo
2020-09-22P_OT9251617677MS.docdoc 79a4f9be0ba6aece829290e01255b06fad24cd387c1d27bd98ce0ec1dbc0dfe3Virustotal results 32.79%Heodo
2020-09-22XI4494114319MK.docdoc 3ed5e00e046ce19a840746219ff3efcd6fcc4ddd0b608e51203398bfe2360da2Virustotal results 31.67%Heodo
2020-09-22DOC_008973141979461.docdoc 58dca36db6814be3bc7016599693d84cc074f17451bebe7eb98baee99cef0ac9n/aHeodo
2020-09-22DOC_762601770955689.docdoc d937aee7869b57f5784a642a274c6c32b57ed26aaf0594e7adbbf3f980c4ff98n/aHeodo
2020-09-22BAL_94172228281908.docdoc b664feace8781e7ad1ed550dc5f1a66b77b73f75228c1898a1986b67fd543477Virustotal results 33.33%Heodo
2020-09-22DOC_ZEW_090120_VFK_092220.docdoc b9ae26c8fc56943d82223a7d3c26671f4247a42d3d56fc25a455217cb84674b7Virustotal results 32.79%Heodo
2020-09-22PO_09222020EX.docdoc 6696d2b4bda784271bb22b8bf2ee6db7547f366940a5bba7444ec265cbc1b0e1Virustotal results 31.67%Heodo
2020-09-22INV_XORJ2JD4UA26M7FJ.docdoc ccc41f0194e3ea4cd0460cdb76391a4edf6732e895a600acaeb6099a6796c558Virustotal results 32.79%Heodo
2020-09-22DOC_LUGZBPBX8.docdoc 6f9bccda375580566f4824b5dad0662ea49be1f410eb2bd5c38f3561dbac29e4Virustotal results 33.33%Heodo
2020-09-22YP9333276161IQ.docdoc 62f036b925c8b4c5c90b88eaf15e774481a952ac6e1c7596916e10054b82daceVirustotal results 30.00%Heodo
2020-09-21BAL_PO_09222020EX.docdoc 4b79ba0096d15d6a7c759fdf3e094194707f88072e8aeb0d53979a88db734ae2n/aHeodo
2020-09-21BAL_BU5471576691NL.docdoc 1c32c9f78e41111a64f8b70991f12d32e3baaf7def1f2ec157245644d8e4ddf3Virustotal results 31.15% Heodo
2020-09-21M_MKI_090120_PNO_092220.docdoc caefda78ff290b2ad9de3f8ee864f985144a3caeb6e307e034427b5f621184daVirustotal results 31.15%Heodo
2020-09-21S_5159690694601.docdoc 04b6915557c386d4219e56049dca6eeef6f30b41f45fb525d36977e248fbf4ecVirustotal results 31.15%Heodo
2020-09-21DOC_GOKYNTS0FEYFC38E.docdoc 2d560e72a8bbfa60a7f05d58048f8174de084d6ff4a53531d9582e251fc067c5Virustotal results 30.00%Heodo
2020-09-21REP_UKKVRETMTCZO2IXW.docdoc 9f3a5491d61d0e1c05f436639b20d24b38465f96aecdda836f9fe292d1af0b34n/a Heodo
2020-09-21VF5J6BD68.docdoc a90a365b3c7a945f46b9fdd9cefcaf5c9d8bf91969bd48b47d8454bee53e1425n/a Heodo
2020-09-21JW_98641433.docdoc 292a48621b6f7863d1a7d04f25cd2c6ddbcbf5abac1282941d3ba20ae076b776Virustotal results 27.87%Heodo
2020-09-21417970692890.docdoc e6573ea6cfe0bdb4f9b3d43b7b68207d18fb492c9ed35aaf6bee52d0d681a9ddVirustotal results 28.33%Heodo
2020-09-21030558173359359975508.docdoc 20c91a51721e21851a9378758513e3d0ec631985cab6f862b783627792f1f127n/aHeodo
2020-09-21DOC_PO_09212020EX.docdoc 0375b4835fb4def35254dd37af3b71c8c92dbafb8af44ccf8f7ff85e3751ffb7n/a Heodo
2020-09-21INV_PO_09212020EX.docdoc 9ac42de81707bd470c8974966355b1c4ab5b4be1ff55ffc4b0e38a197d1561c9n/aHeodo
2020-09-21PO_09212020EX.docdoc e4bf7ba6d49953f6d305ed245b9ef7be426ea9b211bbd8aee04948809159fda8Virustotal results 27.87% Heodo
2020-09-21M_532656162.docdoc c21d1380aca8b0bf6a959ecef76f038219bb549814f2e6c92c6fc2ec2316632eVirustotal results 28.81% Heodo
2020-09-21REP_32551176.docdoc 23d5d8e9c92d53d3ee2027f177ca8a6a51be1fd82c937219ed25eb2c0720a377Virustotal results 26.67%Heodo