URLhaus Database

You are currently viewing the URLhaus database entry for http://ufficiolink.top/login.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2066014
URL: http://ufficiolink.top/login.txt
URL Status:Offline
Host: ufficiolink.top
Date added:2022-02-28 08:32:09 UTC
Last online:2022-03-01 05:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2022-02-28 08:33:10 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:20 hours, 59 minutes Good (down since 2022-03-01 05:32:18 UTC)
Tags:geofenced Gozi link inps ISFB link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-01n/aexe 23197fc4ac72c26b7f4214a75643162cbd46bde7d5a39424a3db897c3737ce6an/a Gozi
2022-03-01n/aexe ca27a3ca5e9ae97c209381d3af87f9280570c68a6bff1acb1eaae966a84cdf9en/a Gozi
2022-03-01n/aexe 7e3b2ac80fabbb4b3f1f058eaec703e22313637d2397ac84dbd52372bbc847e7n/a Gozi
2022-02-28n/aexe 15d777f5ae2fb7054d3db94630980e254ebb8ee92d7554d6c90e16b525131fd3n/a Gozi
2022-02-28n/aexe 62d43308e7ebc9affceedec75a361c572402e6107bbc6cf63d84920fbce95f62n/a Gozi
2022-02-28n/aexe fc3a07a2f6a8f82ffa323ff489f7c558cd3fba51d9aa168e53848d88c9140c6en/a Gozi
2022-02-28n/aexe 37958cd863c40abf367cf75e811f4388fba8bc83e00ade95749e982f47be39d3n/a Gozi
2022-02-28n/aexe 5e70d9b93301e27d41e1599a9492b3f3e77859466d33122f94376e61b8ff94edn/a Gozi
2022-02-28n/aexe f420e566e9da55dd057b173006916025b1f3cba20dedf5e1509235c8ce225268Virustotal results 35.71% Gozi
2022-02-28n/aexe c5352dbe290d56ffd51e9b957f51ebd00c6c8a0788c8357cc1dd0cf9ad8880f7n/a Gozi
2022-02-28n/aexe cc11a88c480eadc75119085bb6e54dfcc443844e22b795ceff7a98ddbfc15429Virustotal results 35.71% Gozi
2022-02-28n/aexe fd42d2aa3df0c3875a00618c4c9e74db288dbe66631875b8582971e63ba6684an/aGozi
2022-02-28n/aexe 817fe41d2a881e9a2a12a600638be69ed017898afdfd64ade81b3ff978b17323n/a Gozi
2022-02-28n/aexe e57b6ea5d609740b8328626137a4c6b0254b33bc192d6b54c475fef2a9e3c07aVirustotal results 32.35% Gozi
2022-02-28n/aexe 2fc0767c71c977781d828aee42fdca19b72a38437430c13475bad8d17d0008f5Virustotal results 32.86% Gozi
2022-02-28n/aexe bce53e9e5af3e93c647956fd2fe0662e507513c7a3abee2fbc3bcb2f85432406Virustotal results 33.33%Gozi