URLhaus Database

You are currently viewing the URLhaus database entry for https://vipbeed.com/SERVICES which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2636777
URL: https://vipbeed.com/SERVICES
URL Status:Offline
Host: vipbeed.com
Date added:2023-05-19 02:13:16 UTC
Last online:2023-05-19 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-05-19 02:14:06 UTC to abuse{at}rentaserv[dot]su)
Takedown time:14 hours, 20 minutes Good (down since 2023-05-19 16:34:22 UTC)
Tags:dll geofenced Gozi link ISFB link ITA js ursnif link zip

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-05-191 Total New Invoices - Wednesday May 17 2023.zipzip 0454fa25f33894efeb780ee5b14e212c4b3513ecc57ca4016ee956333c10dbadn/a Gozi
2023-05-191 Total New Invoices - Wednesday May 17 2023.zipzip 23cbb544c8df95b55eb364175ba8d4354e2ee5d59c848c193e3eba77d8b2043fn/a Gozi
2023-05-191 Total New Invoices - Wednesday May 17 2023.zipzip 5d68ce9ef60e452ea71eda65bbeb47f2dee3c45db137df433e36f35abe4efef7Virustotal results 6.67% Gozi
2023-05-191 Total New Invoices - Wednesday May 17 2023.zipzip 4b90dcb094e90f98525547ac2ca94d64448f11228ead22a8ebd0e35618f04c75n/a Gozi