URLhaus Database

You are currently viewing the URLhaus database entry for http://zukavp08.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1650387
URL: http://zukavp08.top/downfiles/file.exe
URL Status:Offline
Host: zukavp08.top
Date added:2021-10-01 12:29:04 UTC
Last online:2021-10-03 09:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-10-01 12:30:03 UTC to info{at}iqhost[dot]ru)
Takedown time:1 day, 20 hours, 36 minutes Poor (down since 2021-10-03 09:06:45 UTC)
Tags:32 cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-10-02n/aexe 2d090e48369efcdbebf9df5aed96857cd442509bb5f59e171f2b1b3cf1a56361n/aCryptBot
2021-10-02n/aexe 70d01c6918c07b4cd0daa9b2c688fbd7e0e2e6f77831c9bd351be29a7991e1d3n/aCryptBot
2021-10-02n/aexe 337b9f5f13ee874ebe70fd5468725b638eb7b62c4f8c91a6e2a7deab8f5edbb6n/aCryptBot
2021-10-02n/aexe 043b6e6b1c0dcd7fa27211fd8e19a35cc9db8e11d02b880086478d2b7569e5dfn/a CryptBot
2021-10-01n/aexe 2408472718bae19c334ae7afb2b2457eacb43ca178b0e472e2428454f31d2cd8n/a CryptBot
2021-10-01n/aexe e7e206cee63cf56f1818aa706ba3e7beb42daded2e40ed3c82caf0eee52e120dn/aCryptBot
2021-10-01n/aexe 90145ecdcdb80f34c3246bc485a714535af298d7bd195e79bd2174fda5a714ecVirustotal results 32.84%CryptBot