URLhaus Database

You are currently viewing the URLhaus database entry for http://liochi08.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1917582
URL: http://liochi08.top/downfiles/file.exe
URL Status:Offline
Host: liochi08.top
Date added:2021-12-24 15:38:04 UTC
Last online:2021-12-25 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-25 19:06:50 UTC to abuse{at}sambuca[dot]ru)
Takedown time:1 day, 3 hours, 35 minutes Poor (down since 2021-12-25 19:15:43 UTC)
Tags:32 cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-12-25n/aexe baad2a0ffe87799a010626dede455fc11abeba9df6c6c8ef2f062d1b83e31c6dn/a CryptBot
2021-12-25n/aexe c5235a63f916e2de15aaa66e0664c1548caa85c4a56c11fb5e328921bab1f459n/aCryptBot
2021-12-25n/aexe da10cd48bec8f7dc23f30ff95e3a0df73826afb51c95ff10c2adec7e4ef9310cn/aCryptBot
2021-12-24n/aexe b888b5ee1d7210d1373764e760dde471897fc7a7b56364a53bba521ee57f402bn/a CryptBot
2021-12-24n/aexe 3cfb768f5c6a00d29071ae8288d0270ed7bb19a56da162d07a49ba2aafbfba4aVirustotal results 47.83%CryptBot