URLhaus Database

You are currently viewing the URLhaus database entry for http://ecologilines.top/notepad.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2083562
URL: http://ecologilines.top/notepad.txt
URL Status:Offline
Host: ecologilines.top
Date added:2022-03-08 07:41:04 UTC
Last online:2022-03-09 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2022-03-08 07:42:08 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:1 day, 14 hours, 7 minutes Poor (down since 2022-03-09 21:49:35 UTC)
Tags:exe geofenced Gozi link ISFB link ITA MISE ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-09n/aexe 14e041ad11be886018e643ed1cff9abe512e787bec794ab585e75f91e2da119eVirustotal results 32.84%Gozi
2022-03-09n/aexe 1f81af8f4546b7987e0f027d5a169ed2f13c531cb2abdb3bf53d178adf0dca4fn/a Gozi
2022-03-09n/aexe 0c71e469325880f48ca9ea51a1092a8de66e4076f2123c9ddb1e49c3c6d4d2d2n/a Gozi
2022-03-09n/aexe 7a09413c1069aa57c3f7fa392524beba2946e52c0e7d19a950f949d7795d3be0n/a Gozi
2022-03-08n/aexe f1d890163f681d1c94337e6459b9c233180ebe755e94095315f7acf0171e1eeaVirustotal results 30.30% Gozi
2022-03-08n/aexe d2996d305d44d4bd2e235e0c7ef48c3bdab626a8852e5d1abccf68e94d233c92Virustotal results 29.85% Gozi
2022-03-08n/aexe e74e14b36e71787b1be4c18218322ae0b78d643ce5ee7170ed5d3c0b828679d3n/a Gozi
2022-03-08n/aexe b8d2240b48152cdb8a65ca9c147cead454d1f341f308dae3dddc41d2f7adf215n/a Gozi
2022-03-08n/aexe 6c65c6f3674899f9139ead6125de690cbc88d5b6b782ac736bbc9ed68aebc099n/a Gozi
2022-03-08n/aexe bc2bd3c448b2348629da59a454f409ad5b60f2eb21f175e7e49dd04b2703c0ean/a Gozi
2022-03-08n/aexe 02f23031b04660ce5d0a3dbd6862640895e37c649963c02d0b367a17d8422ffeVirustotal results 31.34% Gozi
2022-03-08n/aexe 50ed0329ffb7ae83f7a8042ef7f6bd5af5f308e52f479965358cfe4d646b1847n/a Gozi
2022-03-08n/aexe 4bd004047533752383486ead4f6ce67459d38f816d63d110744f0df009b2d022n/aGozi
2022-03-08n/aexe 4cd40ce08b87a5b1cf9ec2c3d9696076f2d7b698609739823786bcc243b89d25n/a Gozi
2022-03-08n/aexe da620c65032d49a148b428dab566fed2a1a9af6fb0f53ffc4ea75ae54a2cd6a9n/aGozi
2022-03-08n/aexe 57d9f65f62b63e02b194c97d66d478f70a75df94abc134d45e02539cbb33d961n/aGozi
2022-03-08n/aexe efd04e8f37b1a511e4c723356220d4c07a27a8e8b5a370ea7a7a6b8a5d98ea6bn/aGozi