URLhaus Database

You are currently viewing the URLhaus database entry for http://twizthash.net/32.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3525964
URL: http://twizthash.net/32.exe
URL Status:Offline
Host: twizthash.net
Date added:2025-04-26 13:33:07 UTC
Last online:2025-06-20 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Phishing domain
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abus3reports
Abuse complaint sent (?): Yes (2025-06-18 20:29:09 UTC to erishennya[dot]res{at}gmail[dot]com)
Takedown time:1 month, 25 days, 3 hours, 10 minutes Bad (down since 2025-06-20 16:44:50 UTC)
Tags:phorpiex link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2025-06-1832.exeexe 252171bdaa35d19f872c165e861b03d347a4afb85d7a03d02f8eae09d191038dVirustotal results 77.46% Phorpiex
2025-04-2632.exeexe c0d12405d2a5cd6064e6e498d6f5f7fd48c72b2d02f171f20f898a4d2832968cVirustotal results 81.69%Phorphiex