URLhaus Database

You are currently viewing the URLhaus database entry for http://customline.top/forum.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2081572
URL: http://customline.top/forum.txt
URL Status:Offline
Host: customline.top
Date added:2022-03-07 07:59:08 UTC
Last online:2022-03-08 22:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2022-03-07 09:54:07 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:1 day, 14 hours, 35 minutes Poor (down since 2022-03-08 22:35:37 UTC)
Tags:geo geofenced Gozi link ISFB link ITA MISE ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-08n/aexe 08e7899c7946794dd0b738ff2ac0114efd8f2d3a27dfad22a5bd8fc8603748a6n/aGozi
2022-03-08n/aexe eaed7a6aaa019755d04e201ed387c0b0d28a2b6659350c72ea49d9ea0ba04e50Virustotal results 34.33% Gozi
2022-03-08n/aexe 12b463a895e1471038d3bd8918305c631693ae0348e64207444e6f82b8a5d59aVirustotal results 33.33% Gozi
2022-03-08n/aexe 820f89ddf87ac643eb97e9abb4bd38baaade5fc5c9b940f85e0a4d81793e2012n/a Gozi
2022-03-07n/aexe 19be9c4dc2dd22942ad90b3f8679720a3de0996d918fb4cdae16c53824c7d41dn/a Gozi
2022-03-07n/aexe 15435517483aae812307904a7564724a17bd74bc10261ad493cbe63677633aa7n/aGozi
2022-03-07n/aexe af01d12df06f34e81f3772a1b661eef4f9086a73d953ea1c92a8408c4efa2e77n/a Gozi
2022-03-07n/aexe 0e75c1824b648b6fadd5d3055dc7f829922409b3bcce4dbf265d644c41cc8ff4n/a Gozi
2022-03-07n/aexe 586a07986c7d4c61d9ee0084b35488e39007dc77e6ec56917f6006f9f41f0811n/a Gozi
2022-03-07n/aexe 99d58426902459f3a34dcec92c1ea96f2356c80cbb5852d397995eee53cf3625Virustotal results 35.29% Gozi
2022-03-07n/aexe 1837a356bc61c6bed790dd433060fd7d16fb1b3f3484b2fecca2370e9cd42509Virustotal results 32.35% Gozi
2022-03-07n/aexe 1c94ff552101b549d89207a0ed966aa34041ec7f25db6869f13557540b480f9fn/a Gozi
2022-03-07n/aexe 892eb4894a632abe9552c1e512cfffa07dae879d25085a024fd59136a78e0c56n/a Gozi
2022-03-07n/aexe 24e7d068b0c1704d982eb8af15738219b7329937b0e5951f1e1af462641e4748n/a Gozi
2022-03-07n/aexe df2f2f04aba4fac3d06945bf744bb861fe6a1d227b2269b3d40ba7a8d1f3f8b0n/a Gozi
2022-03-07n/aexe 9fcaf7ae5e2b5e2a4e7b34c37b5f6f1a539c07bc258379314b7590582b859147n/aGozi