URLhaus Database

You are currently viewing the URLhaus database entry for http://akwer03.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1085767
URL: http://akwer03.top/downfiles/file.exe
URL Status:Offline
Host: akwer03.top
Date added:2021-03-23 09:19:04 UTC
Last online:2021-03-25 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2021-03-23 09:20:02 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:2 days, 3 hours, 48 minutes Poor (down since 2021-03-25 13:08:06 UTC)
Tags:cryptbot DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-25n/aexe 85703e12da9b03c01beeca428bab091b0f790d26f789bdc0beee75cab764f3d2n/a DanaBot
2021-03-25n/aexe 6c219118acdf6e43d54298e2a7c268c0877a4f31c207cd29d2e038a858cea9fen/aCryptBot
2021-03-24n/aexe ad56615795d2071a9019547765ea589c937b5cc351a59dfa53eefedf774dc38an/a DanaBot
2021-03-24n/aexe 724a392320703670f6bccc152942ec483ceb9f97317add3507fbb9ce4db10509n/a DanaBot
2021-03-24n/aexe 10c0f1080840ab3cf7fd69f80a6b821a6f95cb7b57a7e43dfb757e9df598c18an/aDanaBot
2021-03-23n/aexe 7b55f92633f9e8b7aad9234dd19148549c4b068f8199bb2ea4cfa6ef3175e569n/aCryptBot
2021-03-23n/aexe 6d18b40031a6b4522327bd525225dd5146422d6156ca6a90ecefceb63b8a1f26Virustotal results 31.43% CryptBot
2021-03-23n/aexe b0e796694c790548cf9553a6ed536b21e8471064c4ae887304137ffcafbe257fVirustotal results 38.24%CryptBot