URLhaus Database

You are currently viewing the URLhaus database entry for http://ufficiolines.top/login.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2065988
URL: http://ufficiolines.top/login.txt
URL Status:Offline
Host: ufficiolines.top
Date added:2022-02-28 08:19:05 UTC
Last online:2022-03-01 06:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2022-02-28 08:20:11 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:22 hours, 1 minutes Good (down since 2022-03-01 06:21:32 UTC)
Tags:geofenced Gozi link inps ISFB link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-01n/aexe e77a57a76ec227bbb2b7e5b29ebcaac5a0c0f24779984353b7bfed395e97cf6fn/a Gozi
2022-03-01n/aexe ca27a3ca5e9ae97c209381d3af87f9280570c68a6bff1acb1eaae966a84cdf9en/a Gozi
2022-03-01n/aexe 7e3b2ac80fabbb4b3f1f058eaec703e22313637d2397ac84dbd52372bbc847e7n/a Gozi
2022-02-28n/aexe 80ce53e5dfb8260fe911f020621d7d887f9ba9c23b2b2805665016bd4383b1edn/a Gozi
2022-02-28n/aexe 62d43308e7ebc9affceedec75a361c572402e6107bbc6cf63d84920fbce95f62Virustotal results 38.03% Gozi
2022-02-28n/aexe fc3a07a2f6a8f82ffa323ff489f7c558cd3fba51d9aa168e53848d88c9140c6en/a Gozi
2022-02-28n/aexe 37958cd863c40abf367cf75e811f4388fba8bc83e00ade95749e982f47be39d3n/a Gozi
2022-02-28n/aexe 5e70d9b93301e27d41e1599a9492b3f3e77859466d33122f94376e61b8ff94edn/a Gozi
2022-02-28n/aexe f420e566e9da55dd057b173006916025b1f3cba20dedf5e1509235c8ce225268Virustotal results 35.71% Gozi
2022-02-28n/aexe 54cadf62508d5b2151283b0b804cc29481df6948b2ee88867ffe13698326e8b9n/a Gozi
2022-02-28n/aexe cc11a88c480eadc75119085bb6e54dfcc443844e22b795ceff7a98ddbfc15429Virustotal results 35.71% Gozi
2022-02-28n/aexe fd42d2aa3df0c3875a00618c4c9e74db288dbe66631875b8582971e63ba6684an/aGozi
2022-02-28n/aexe 8a1667ced8247d1642ea3794e0dca340c4be3f44a5d465a47632b1946c36268en/a Gozi
2022-02-28n/aexe 817fe41d2a881e9a2a12a600638be69ed017898afdfd64ade81b3ff978b17323n/a Gozi
2022-02-28n/aexe e57b6ea5d609740b8328626137a4c6b0254b33bc192d6b54c475fef2a9e3c07an/a Gozi
2022-02-28n/aexe bce53e9e5af3e93c647956fd2fe0662e507513c7a3abee2fbc3bcb2f85432406Virustotal results 33.33%Gozi
2022-02-28n/aexe 645d6e01fb304d604422c5a2812d107e21c091925fbea750c9c80542c7903399Virustotal results 37.14% Gozi