URLhaus Database

You are currently viewing the URLhaus database entry for http://short.extrafandome.com/p6-2.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1393651
URL: http://short.extrafandome.com/p6-2.exe
URL Status:Offline
Host: short.extrafandome.com
Date added:2021-06-24 05:11:04 UTC
Last online:2022-05-27 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2022-05-27 07:48:06 UTC to abuse{at}amazonaws[dot]com)
Takedown time:11 months, 7 days, 3 hours, 43 minutes Bad (down since 2022-05-27 08:55:42 UTC)
Tags:32 cryptbot exe RaccoonStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-14n/aexe 8b9455340782df54173b872faf9c27da68d16667ac40397dfa2ae8221766520bn/a Downloader.Upatre
2021-09-18n/aexe 601c45de707f7993a9101ac0f9eca21bf3e0865cf5cb952272c76975ad05a2b8Virustotal results 70.59% Downloader.Upatre
2021-07-21n/aexe 88a2e91597137f9a64ccf66c89390c533d1a85d09f8310b658f73bf6ad45db2aVirustotal results 38.81%CryptBot
2021-07-20n/aexe ae4ccd912a3f2ad87789956660ee5485bb5fcd0f36c1d0d4f1272e3ae1f668f3Virustotal results 19.12%CryptBot
2021-07-19n/aexe f2046a05e0d3e80544ef276bfc96ad1dd92ced0f97d32c7e7825f9d558ad2b10n/a Cryptbot
2021-07-19n/aexe ffe5b10cd81f4c1484f62863be69ea28732b8e765b12569c5cd11b463bd4d261n/aCryptbot
2021-07-18n/aexe d0c2ffb2664b0757fa896299577579cb6bd7a7e9dd601e11c13efcc7b5879e2dn/aCryptbot
2021-07-18n/aexe 3d3bd7e7f5fabaf2510cf58eb74a9474b44c5d1389538ee7a93826a25531bd56n/aCryptBot
2021-07-17n/aexe b3a99ecc4ab9f73d814f0f64a3aa0c71ee3cf94872f2f8ca3a2a1c5d630c095dn/aCryptBot
2021-07-17n/aexe 3d364150c09d1f0c4a9eab0144fb4754bdcfa96ad1d0bd874308e625c5958b75n/aCryptbot
2021-07-16n/aexe 9cbdf7f433f59f69ed01b5d6928259ad816d83c3680b8d14bbc54f2e8cd7b752n/a
2021-07-16n/aexe 1a70a7de8a393638b80336e9d2b225c2fd199d9d3eed3ad2c007656cc20c2b4an/aCryptbot
2021-07-15n/aexe 0dbfcf05490597b25cd7e6abaf698d821b00301625a85b3f1ee8e75d8a090a49n/aCryptbot
2021-07-15n/aexe 349fcfd6f24473d8b0c9429c0f71459a178125b6d42a48129d357ce99eca94fen/aCryptBot
2021-07-14n/aexe 54f791796231f7899d753f0ba44e7387bf7748dc7a28adbd28f2067c9ab88605n/aCryptbot
2021-07-14n/aexe 4fed7b4a593e61c9f6b4d0003320bb985cc2be10164bc43aa47e39013b920538n/a RaccoonStealer
2021-06-24n/aexe 06cf7c7c1a2d8f8647c977803466fd5b3a39dded0312fb23575eeacfaeaf07d6Virustotal results 45.71%CryptBot