URLhaus Database

You are currently viewing the URLhaus database entry for http://gurqew05.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1470678
URL: http://gurqew05.top/downfiles/file.exe
URL Status:Offline
Host: gurqew05.top
Date added:2021-07-21 11:11:07 UTC
Last online:2021-07-25 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: 0x746f6d6669
Abuse complaint sent (?): Yes (2021-07-21 11:12:02 UTC to abuse{at}cloudwm[dot]com)
Takedown time:3 days, 17 hours, 56 minutes Bad (down since 2021-07-25 05:08:58 UTC)
Tags:cryptbot DanaBot link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-23n/aexe 3a48f675be894ad3fa2c9d0f1ea37ccaea20ff71d4381dc4e09804bc455a2d12n/aCryptBot
2021-07-23n/aexe 955c3dabe6486e6e66a2796c175aeef0830c8047eae3501c3c9823985d11bf43Virustotal results 31.88%CryptBot
2021-07-23n/aexe d4045dd568eec50b80e7e3679050e24cea71480500f85eb6c3a0f382716f8b0cn/aCryptBot
2021-07-22n/aexe 7224633aec5f96349eea1bc38ae40d5cbc1d5ed120aee617efca5ba7facafa26n/aCryptBot
2021-07-22n/aexe 3140427b921ff6b832fa2c68ddc8ba328d57fa9c20ca6b917abf920c0dabf416n/aCryptBot
2021-07-22n/aexe 4a7279e1bb036c150488d9c828fc82921e798a2f1516baf7f032b1fb398f062an/aCryptBot
2021-07-22n/aexe cfd8b67f3e21558c90c0a84d4f1f74b4691901c8e898308ce4162095b6b597fan/aCryptBot
2021-07-21n/aexe 28e1b969367acd5919e60d1a59aa7d1cfd473f2728bb41f8075cdc969c404a24n/a DanaBot
2021-07-21n/aexe 819f04aad6e5928860bc28b2c02bd3661d8a5e91baa2b37dc069e90d9da9ecaan/aCryptBot