URLhaus Database

You are currently viewing the URLhaus database entry for http://tobexa03.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1560380
URL: http://tobexa03.top/downfiles/file.exe
URL Status:Offline
Host: tobexa03.top
Date added:2021-08-24 13:54:05 UTC
Last online:2021-08-26 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-08-24 13:55:02 UTC to audit{at}firstbyte[dot]ru)
Takedown time:1 day, 18 hours, 48 minutes Poor (down since 2021-08-26 08:43:26 UTC)
Tags:32 cryptbot DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-08-26n/aexe 0997ed7bac99475d1b76eda90aa27685ab2313be5f822a64fe413fc4492d4518n/aCryptBot
2021-08-26n/aexe 9c409df92867a210bba9c3de29296c54222a9342e7e992392f75456e4a86e7a5n/aCryptBot
2021-08-25n/aexe ad7a74ddae7cc81d8610ab6bedb94857f38c03b795c4a612fbacc47941286709n/aCryptBot
2021-08-25n/aexe 6b7bb728fed4545f0e4b9d3ab78e8f008d78f635d1a9f118a1b962d466c2118dn/aCryptBot
2021-08-25n/aexe c9cf9521886aaa99c317b33c9fd5a8f82be1fe61d8616bc6ce8a10c4d26b6e21n/aCryptBot
2021-08-25n/aexe ddfd9ad71462f4680d2816f5022bfd385cf9ff9291e52612f39db801fa1278fbn/aCryptBot
2021-08-25n/aexe abc87c7b821bb7bba854958ecd20760e63c9365aff2091edc2b8449040263a67n/aCryptBot
2021-08-25n/aexe b381327323df581dd6a3dadad65a7a23033a2158faae6f6b8e0713bca5221028n/a DanaBot
2021-08-24n/aexe fb6e522546a83e50fb8759d02881ded745926b7746f06f64694a13aedadd2d6en/aCryptBot
2021-08-24n/aexe 7c3b2df673868d8f99e2cea7d58bcf356bd59c1a49340e5a8a285e06a517fb1fVirustotal results 35.29%CryptBot