URLhaus Database

You are currently viewing the URLhaus database entry for https://proto-h4ul.withregw.in.net/verification.google which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3800605
URL: https://proto-h4ul.withregw.in.net/verification.google
URL Status:flame Online (spreading malware for 3 days, 17 hours, 51 minutes)
Host: proto-h4ul.withregw.in.net
Date added:2026-03-20 13:11:09 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2026-03-23 09:10:16 UTC to abuse{at}cloudflare[dot]com)
Tags:ACRStealer ClearFake NetSupport link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-24verification.googledll d588b90faf401a690aac3143599681768ff471d5ec53a3810c056ba550e99619n/a 
2026-03-23verification.googledll 73edb1d8637b28113a1ba04fa4aa64d3020a9eaaf8a3024b978b362a4cce6238n/a
2026-03-23verification.googledll 235124913aebf0f1d289c7306f45aa6f6ccb866161cce300b44516974d45c4b9n/a NetSupport
2026-03-23verification.googledll 8e2f63960ffe5e9fddf3e01085991c422625972e24397f81dfc9c39f8fd6f771n/aNetSupport
2026-03-20verification.googledll 2fb7654e31e95421bb32362a6ba8120cdaf78798d531b97e7893788e0c15e1b0n/aACRStealer