URLhaus Database

You are currently viewing the URLhaus database entry for http://hofeyz03.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1453979
URL: http://hofeyz03.top/downfiles/file.exe
URL Status:Offline
Host: hofeyz03.top
Date added:2021-07-14 14:26:12 UTC
Last online:2021-07-18 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-07-14 15:24:46 UTC to abuse{at}alibaba-inc[dot]com,intl-abuse{at}list[dot]alibaba-inc[dot]com)
Takedown time:3 days, 14 hours, 5 minutes Bad (down since 2021-07-18 05:30:11 UTC)
Tags:cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-15n/aexe eb4e54c1372f7002b2b49a9918e67f84d65e52f1b12c5b7313420a48d5305e41n/aCryptBot
2021-07-15n/aexe df85a38611751933558ef9e7da81e81025ffc5e5e92cedaf4d97fb0b9f147422n/aCryptBot
2021-07-14n/aexe 7e19416205cfb8e056d4628bdeb635e29cefba04fcb21ee55e7b0077427e4c99n/aCryptBot
2021-07-14n/aexe af8df57ba3941ed8fa89543e4e98f2da5dfe7a0efaaa72aaca4c54ea9f5ccc58n/aCryptbot
2021-07-14n/aexe 949b755ce7ba4afeffe8c261141b77bca5f443761aa062936141ed94b737e848n/aCryptBot