URLhaus Database

You are currently viewing the URLhaus database entry for http://elotom06.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1605278
URL: http://elotom06.top/downfiles/file.exe
URL Status:Offline
Host: elotom06.top
Date added:2021-09-09 13:14:05 UTC
Last online:2021-09-12 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-09 13:15:02 UTC to abuse{at}pinvds[dot]com)
Takedown time:2 days, 18 hours, 6 minutes Poor (down since 2021-09-12 07:21:29 UTC)
Tags:32 cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-11n/aexe 6ebf8ce8d1c0147cbd6cff787cb552c3ddf2478123067fb5c699d82da5590811Virustotal results 48.53%CryptBot
2021-09-10n/aexe 6bcc91824c4c496d12b58dcd82591ad61d76caa662a271bc18aa718f0f56995fn/a 
2021-09-10n/aexe 8a05316f91b11d8dc3258b7fdcebea6d5b89de8142cb535dfc33082dad1e9470n/aCryptBot
2021-09-10n/aexe 8abb5662a9406e7f0ac677244f1403e0517507dc516d36b208df7b66b53a0cdcn/aCryptBot
2021-09-09n/aexe 9e1d4eeff067d03371c7464e2fe9879deed0633968fc745ec88458ebb198f3f0Virustotal results 40.58%CryptBot
2021-09-09n/aexe 9c183327a52687e89969b39d6e099f239161ce9876af0f8da666eb5e55c238c3Virustotal results 32.84%CryptBot