URLhaus Database

You are currently viewing the URLhaus database entry for http://gurvox08.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1476042
URL: http://gurvox08.top/downfiles/file.exe
URL Status:Offline
Host: gurvox08.top
Date added:2021-07-23 13:26:09 UTC
Last online:2021-07-26 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: vxvault
Abuse complaint sent (?): Yes (2021-07-23 13:27:05 UTC to abuse{at}digitalocean[dot]com)
Takedown time:2 days, 20 hours, 0 minutes Poor (down since 2021-07-26 09:27:36 UTC)
Tags:cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-25n/aexe 194c939150cd885553cc6e02f1c8dbe5fb7bf327556245d76d6ea165ec959670Virustotal results 31.34%CryptBot
2021-07-25n/aexe d4036c235fca73a67732d884564991184b7a8ea148784f0cd70fa07adbd8e160n/aCryptBot
2021-07-25n/aexe d6255b4b18e6f07c4708cf6344163dfe3197cf403957bf3085a6a737bb37b038n/aCryptBot
2021-07-25n/aexe 838edfe6cbf7b8fb1f0d3d99535f15ef22b651fa82a9f31a50c3cae435a0af0cVirustotal results 51.43%CryptBot
2021-07-23n/aexe a832cae5c8de458edf6a4604d3e0e19fb74300baaeeb212227330df9e7927088n/aCryptBot
2021-07-23n/aexe 3a48f675be894ad3fa2c9d0f1ea37ccaea20ff71d4381dc4e09804bc455a2d12n/aCryptBot