URLhaus Database

You are currently viewing the URLhaus database entry for https://transfer.sh/get/gA07FT/1.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2136942
URL: https://transfer.sh/get/gA07FT/1.exe
URL Status:Offline
Host: transfer.sh
Date added:2022-04-08 06:16:57 UTC
Last online:2022-04-17 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Myrtus0x0
Abuse complaint sent (?): Yes (2022-04-08 06:17:22 UTC to abuse{at}hetzner[dot]com)
Takedown time:9 days, 15 hours, 3 minutes Bad (down since 2022-04-17 21:20:59 UTC)
Tags:CoinMiner exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-04-171.exeexe e79ffdefa60ce02b2086207c89bc2f6ebf559a6bc322ac4dd5598903b5fd7a8dn/a 
2022-04-151.exeexe cfbc5552d3e7b4f66a34795ba35d398e3919c901cbb023da0586b3c986b61344n/a 
2022-04-121.exeexe 1a885f254a8f2c6a5583eb7a266af7d5de505b21cfc1036e85bfa806221cef6dn/a 
2022-04-121.exeexe 4e11d2f34efec4fa3de7da91b6c95cce8c9956fde5c50442ac72987600e58ecan/a 
2022-04-121.exeexe 8498c3b8f040cedfbe21969106a4b29a9f6146843ebdb3451d6de6fe1b784b54n/a 
2022-04-111.exeexe 5035bb188d5ee3541e57f6b0d68970e028fbbc65e0882656921a33debda3f1e2n/a 
2022-04-111.exeexe 8c4d2c0065539384d852255baa3f7398261d662304b03a795b54c1bc8b78fa96n/a 
2022-04-081.exeexe eaf366ae14a7882c3af4408767b9001796ea6aee6ae7a23a7323da7e6ed76408Virustotal results 42.03%CoinMiner