URLhaus Database

You are currently viewing the URLhaus database entry for http://ecologilink.top/notepad.txt which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2083567
URL: http://ecologilink.top/notepad.txt
URL Status:Offline
Host: ecologilink.top
Date added:2022-03-08 07:48:08 UTC
Last online:2022-03-10 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: reecdeep
Abuse complaint sent (?): Yes (2022-03-08 11:17:09 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:2 days, 2 hours, 41 minutes Poor (down since 2022-03-10 10:30:26 UTC)
Tags:exe geofenced Gozi link ISFB link ITA MISE ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-03-09n/aexe 14e041ad11be886018e643ed1cff9abe512e787bec794ab585e75f91e2da119en/aGozi
2022-03-09n/aexe eda3487d5cce3777e504ae88f362c2352de1642fa86200e005ba5a7a3bfbdec0n/a Gozi
2022-03-09n/aexe 54c8911c3fd29d5b1ccf03a983ba0106e0f553db2e72e06251f6fca5a5ad1d81n/a Gozi
2022-03-09n/aexe 0c71e469325880f48ca9ea51a1092a8de66e4076f2123c9ddb1e49c3c6d4d2d2n/a Gozi
2022-03-09n/aexe 7a09413c1069aa57c3f7fa392524beba2946e52c0e7d19a950f949d7795d3be0Virustotal results 31.82% Gozi
2022-03-08n/aexe 9d78bd7565091ca9bd64766f4d83a4da720ec931bacd8c1d715b56be24cacdb9n/a Gozi
2022-03-08n/aexe f1d890163f681d1c94337e6459b9c233180ebe755e94095315f7acf0171e1eean/a Gozi
2022-03-08n/aexe d2996d305d44d4bd2e235e0c7ef48c3bdab626a8852e5d1abccf68e94d233c92n/a Gozi
2022-03-08n/aexe 05d6ed618ae482d788a0228674163236f32b231f00a8b0d1b23ba0bdc481be60n/a Gozi
2022-03-08n/aexe 6c65c6f3674899f9139ead6125de690cbc88d5b6b782ac736bbc9ed68aebc099n/a Gozi
2022-03-08n/aexe bc2bd3c448b2348629da59a454f409ad5b60f2eb21f175e7e49dd04b2703c0ean/a Gozi
2022-03-08n/aexe 02f23031b04660ce5d0a3dbd6862640895e37c649963c02d0b367a17d8422ffeVirustotal results 31.34% Gozi
2022-03-08n/aexe 50ed0329ffb7ae83f7a8042ef7f6bd5af5f308e52f479965358cfe4d646b1847n/a Gozi
2022-03-08n/aexe 4bd004047533752383486ead4f6ce67459d38f816d63d110744f0df009b2d022n/aGozi
2022-03-08n/aexe 4cd40ce08b87a5b1cf9ec2c3d9696076f2d7b698609739823786bcc243b89d25n/a Gozi
2022-03-08n/aexe 9eb0bdb45d505a24290b3fe9adb1ac5c856238e91358fcf7e6af73d9a1b9c244Virustotal results 31.88%Gozi
2022-03-08n/aexe 57d9f65f62b63e02b194c97d66d478f70a75df94abc134d45e02539cbb33d961n/aGozi
2022-03-08n/aexe efd04e8f37b1a511e4c723356220d4c07a27a8e8b5a370ea7a7a6b8a5d98ea6bn/aGozi