URLhaus Database

You are currently viewing the URLhaus database entry for http://diatxo06.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1640753
URL: http://diatxo06.top/downfiles/file.exe
URL Status:Offline
Host: diatxo06.top
Date added:2021-09-23 10:15:06 UTC
Last online:2021-09-25 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-09-23 10:16:03 UTC to abuse{at}mtw[dot]ru)
Takedown time:1 day, 21 hours, 17 minutes Poor (down since 2021-09-25 07:33:38 UTC)
Tags:32 cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-09-24n/aexe dc31cab14ad2fafec96a07792728490e406c9375f73d6ba24a863afea94d84fan/a CryptBot
2021-09-24n/aexe 7d228085018d1f8ffdd1765cbc892a3c6886d81a156e25d053737597a6566112n/aCryptBot
2021-09-24n/aexe d8ce50fa9a07e1f21bf60490cd8b8002dd2eebd6e02ebc3f95a6be8664d7a407Virustotal results 31.34% CryptBot
2021-09-23n/aexe eb9aba41f979b8da5bd42d7e7d248daaa23014db0ad5593bbf4967327cd651aeVirustotal results 37.31%CryptBot
2021-09-23n/aexe 20c3236616a266a4175355373d2d89742f9a4eae73f2c44b1a8e83a215fde9f1n/aCryptBot
2021-09-23n/aexe 6563baa395257badd656572083aa05dc277e6516f079da5c0eddf0b6bbee4ffcVirustotal results 33.33%CryptBot