URLhaus Database

You are currently viewing the URLhaus database entry for http://gurtuq11.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1480172
URL: http://gurtuq11.top/downfiles/file.exe
URL Status:Offline
Host: gurtuq11.top
Date added:2021-07-25 09:20:11 UTC
Last online:2021-07-28 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-07-25 09:21:07 UTC to abuse{at}linode[dot]com)
Takedown time:2 days, 16 hours, 58 minutes Poor (down since 2021-07-28 02:19:45 UTC)
Tags:32 cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-07-27n/aexe daf8edec541d1943ba497842d5347d2fb98f3428f1f62aecb3f136027c97df51n/aCryptBot
2021-07-27n/aexe 59a3a6df6f6a006fb14ed1b221e398b5d8ebb983e0ef9543369c0f5c7de34da8n/aCryptBot
2021-07-27n/aexe 9960a4ad4563e70c0605116e37e733081d02fa02af27563d836d5fe71966b459n/aCryptBot
2021-07-26n/aexe 07efd513a02e8c30296f7b73488d9a74796849787df14af028266cd79c89d51fn/aCryptBot
2021-07-26n/aexe a4c1611cb53460b6e745cc05101f83a834d66d78462fff9b190cff9727784700n/aCryptBot
2021-07-26n/aexe 28877275c2c938f24cd0bf43f2c0cef090c58b7a85a988b2f6dff4970660b07dn/aCryptBot
2021-07-26n/aexe 50f41c07db1d0d625cd0746a78dc15a1193f4fd0f80e6a4df40315f24efe2110n/aCryptBot
2021-07-25n/aexe 194c939150cd885553cc6e02f1c8dbe5fb7bf327556245d76d6ea165ec959670Virustotal results 31.34%CryptBot
2021-07-25n/aexe d4036c235fca73a67732d884564991184b7a8ea148784f0cd70fa07adbd8e160n/aCryptBot
2021-07-25n/aexe d6255b4b18e6f07c4708cf6344163dfe3197cf403957bf3085a6a737bb37b038Virustotal results 43.48%CryptBot