URLhaus Database

You are currently viewing the URLhaus database entry for http://customlines.top/forum.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2081570
URL: http://customlines.top/forum.txt
URL Status:Offline
Host: customlines.top
Date added:2022-03-07 07:59:07 UTC
Last online:2022-03-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2022-03-07 08:00:09 UTC to abuse{at}cishost[dot]ru)
Takedown time:3 days, 2 hours, 14 minutes Bad (down since 2022-03-10 10:14:37 UTC)
Tags:geo geofenced Gozi link ISFB link ITA MISE ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-08n/aexe 08e7899c7946794dd0b738ff2ac0114efd8f2d3a27dfad22a5bd8fc8603748a6Virustotal results 27.94%Gozi
2022-03-08n/aexe 1bfd7fb4be1c3d25af01f6cfbaf08ed1b8bd61aa08063357e2040991d5af8d24n/a Gozi
2022-03-08n/aexe eaed7a6aaa019755d04e201ed387c0b0d28a2b6659350c72ea49d9ea0ba04e50n/a Gozi
2022-03-08n/aexe 820f89ddf87ac643eb97e9abb4bd38baaade5fc5c9b940f85e0a4d81793e2012n/a Gozi
2022-03-08n/aexe 1fa21fba018c6683bdd0690a97175a5f88046d7d4c1b93c4b1340f5b9cf507a4n/a Gozi
2022-03-07n/aexe eb3f5f63888b85f287fbc37479ca4c518ff8527e334feaeaeabc62f34b37c6afn/a Gozi
2022-03-07n/aexe 0e6991263462b4c49de95f5d10037a077e723749d09a13a9d387ae8ec5c17ed6n/a Gozi
2022-03-07n/aexe 0e75c1824b648b6fadd5d3055dc7f829922409b3bcce4dbf265d644c41cc8ff4n/a Gozi
2022-03-07n/aexe eb42e30d3ee21fcdca4da6e7aa5311f64d1aa7aa8e05c8eee161dee90fda912en/a Gozi
2022-03-07n/aexe 99d58426902459f3a34dcec92c1ea96f2356c80cbb5852d397995eee53cf3625n/a Gozi
2022-03-07n/aexe 1837a356bc61c6bed790dd433060fd7d16fb1b3f3484b2fecca2370e9cd42509Virustotal results 32.35% Gozi
2022-03-07n/aexe 892eb4894a632abe9552c1e512cfffa07dae879d25085a024fd59136a78e0c56n/a Gozi
2022-03-07n/aexe 24e7d068b0c1704d982eb8af15738219b7329937b0e5951f1e1af462641e4748n/a Gozi
2022-03-07n/aexe df2f2f04aba4fac3d06945bf744bb861fe6a1d227b2269b3d40ba7a8d1f3f8b0n/a Gozi
2022-03-07n/aexe feee03d66ec3d9c906d0dca423c2c0fa08bbbf9b5c2e2459515d860374082b31n/a Gozi
2022-03-07n/aexe 9fcaf7ae5e2b5e2a4e7b34c37b5f6f1a539c07bc258379314b7590582b859147n/aGozi