URLhaus Database

You are currently viewing the URLhaus database entry for http://xetryc11.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1786450
URL: http://xetryc11.top/downfiles/file.exe
URL Status:Offline
Host: xetryc11.top
Date added:2021-11-14 19:32:14 UTC
Last online:2021-11-15 17:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-11-15 15:35:05 UTC to audit{at}firstbyte[dot]pro)
Takedown time:1 day, 12 hours, 29 minutes Poor (down since 2021-11-16 08:02:54 UTC)
Tags:32 cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-11-16n/aexe 969455946cc052e86853b51035e7271bdb15cde3e4e7cc684f5fd34fb3b6c896n/a 
2021-11-15n/aexe f3317a224bd0281ade1bec86ca72f8f6f178155d2263d0d9ae6c4b24c49b4a9an/a CryptBot
2021-11-15n/aexe 76912d7b284d7666d3c5aca9e3ae4ff5fc8fbff7956171f42cff7413ec635053n/a 
2021-11-15n/aexe 59193209add2aa657db4343d23ddc12453746a3cdf63117db522f3976bd88cc0n/aCryptBot
2021-11-14n/aexe 6319b895e7a61947bfa702bf9f092d585f76a983666bbceb8d6dcbabe50e330dVirustotal results 44.12%CryptBot