URLhaus Database

You are currently viewing the URLhaus database entry for https://di5pat-ring.prowinserv.in.net/verification.google which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3803215
URL: https://di5pat-ring.prowinserv.in.net/verification.google
URL Status:flame Online (spreading malware for 20 hours, 45 minutes)
Host: di5pat-ring.prowinserv.in.net
Date added:2026-03-23 09:04:26 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2026-03-23 09:07:02 UTC to abuse{at}cloudflare[dot]com)
Tags:ClearFake NetSupport link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-03-24verification.googledll e5a668cf37445f83831a886d32fda284697ff98bd8b9e4c71e43fd1b64c1f7een/a 
2026-03-24verification.googledll d588b90faf401a690aac3143599681768ff471d5ec53a3810c056ba550e99619n/a 
2026-03-23verification.googledll 73edb1d8637b28113a1ba04fa4aa64d3020a9eaaf8a3024b978b362a4cce6238n/a
2026-03-23verification.googledll dc9587d7c62518c935f190bda2925bed1401f48ee24dda76a3a91eaa3a974daen/a 
2026-03-23verification.googledll 8e2f63960ffe5e9fddf3e01085991c422625972e24397f81dfc9c39f8fd6f771n/aNetSupport