URLhaus Database

You are currently viewing the URLhaus database entry for http://winfyn10.top/downfiles/lv.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1497244
URL: http://winfyn10.top/downfiles/lv.exe
URL Status:Offline
Host: winfyn10.top
Date added:2021-08-01 09:17:08 UTC
Last online:2021-08-03 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-01 09:18:03 UTC to abuse{at}cloudassets[dot]ru)
Takedown time:1 day, 19 hours, 38 minutes Poor (down since 2021-08-03 04:56:07 UTC)
Tags:32 DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-01n/aexe d33336905c29588a28620ae7bca11c90214a928d36fbde3afa3890ff7b2fb3c8n/a DanaBot
2021-08-01n/aexe 48e20a43a55f81f5adb33616e72190509c7647216daf69c0095d1270fe66381an/a DanaBot
2021-08-01n/aexe 11a3ec7e77a518bf03da7384646898e4708e9ad77ecca7e4a32dfd0c484e8259n/a DanaBot
2021-08-01n/aexe d61176ad7367c227cd55914c24fb5584d01b17cef989648c8274665b630ea9aaVirustotal results 23.21%DanaBot