URLhaus Database

You are currently viewing the URLhaus database entry for http://ufficioline.top/login.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2065899
URL: http://ufficioline.top/login.txt
URL Status:Offline
Host: ufficioline.top
Date added:2022-02-28 07:28:05 UTC
Last online:2022-03-01 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2022-02-28 12:14:06 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:21 hours, 42 minutes Good (down since 2022-03-01 05:11:59 UTC)
Tags:geofenced Gozi link inps ISFB link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-01n/aexe 42fbdb6312c3f44c9cc8d84b851500f78332984b253a5d435ef815a0ea0fce3an/a Gozi
2022-03-01n/aexe ca27a3ca5e9ae97c209381d3af87f9280570c68a6bff1acb1eaae966a84cdf9eVirustotal results 40.00% Gozi
2022-03-01n/aexe 7e3b2ac80fabbb4b3f1f058eaec703e22313637d2397ac84dbd52372bbc847e7n/a Gozi
2022-02-28n/aexe 62d43308e7ebc9affceedec75a361c572402e6107bbc6cf63d84920fbce95f62Virustotal results 38.03% Gozi
2022-02-28n/aexe fc3a07a2f6a8f82ffa323ff489f7c558cd3fba51d9aa168e53848d88c9140c6en/a Gozi
2022-02-28n/aexe 37958cd863c40abf367cf75e811f4388fba8bc83e00ade95749e982f47be39d3n/a Gozi
2022-02-28n/aexe 5e70d9b93301e27d41e1599a9492b3f3e77859466d33122f94376e61b8ff94edn/a Gozi
2022-02-28n/aexe 1b80e0aa6560bd9868c6d7a0dad54f9e66ec13f2c125ea8761f6822d88c39464n/a Gozi
2022-02-28n/aexe f420e566e9da55dd057b173006916025b1f3cba20dedf5e1509235c8ce225268n/a Gozi
2022-02-28n/aexe c5352dbe290d56ffd51e9b957f51ebd00c6c8a0788c8357cc1dd0cf9ad8880f7n/a Gozi
2022-02-28n/aexe cc11a88c480eadc75119085bb6e54dfcc443844e22b795ceff7a98ddbfc15429Virustotal results 35.71% Gozi
2022-02-28n/aexe fd42d2aa3df0c3875a00618c4c9e74db288dbe66631875b8582971e63ba6684an/aGozi
2022-02-28n/aexe 817fe41d2a881e9a2a12a600638be69ed017898afdfd64ade81b3ff978b17323n/a Gozi
2022-02-28n/aexe 2fc0767c71c977781d828aee42fdca19b72a38437430c13475bad8d17d0008f5n/a Gozi
2022-02-28n/aexe 645d6e01fb304d604422c5a2812d107e21c091925fbea750c9c80542c7903399n/a Gozi