URLhaus Database

You are currently viewing the URLhaus database entry for http://fumzgo01.top/downfiles/rewend.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1735789
URL: http://fumzgo01.top/downfiles/rewend.exe
URL Status:Offline
Host: fumzgo01.top
Date added:2021-11-01 11:38:05 UTC
Last online:2021-11-02 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-02 06:12:04 UTC to audit{at}firstbyte[dot]ru)
Takedown time:22 hours, 41 minutes Good (down since 2021-11-02 10:20:16 UTC)
Tags:clipbanker exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-01n/aexe 31320da1bd5a36a6d6856e06cebbcc07459b9e1354982f33926b491c1beb4864n/aClipBanker
2021-11-01n/aexe 6354eb1d6a13a189883ff970a2a3038b91f5dc993ec13550fc085472c8d10595n/aClipBanker
2021-11-01n/aexe ac0bc138f72552b13db4882710a410b16d298b02f195392b05892ce52c13b7bbVirustotal results 47.76%ClipBanker