URLhaus Database

You are currently viewing the URLhaus database entry for https://srvhub.6toralex.surf/sh5hne-c8b9b4-sskjy-znq2k2of-ybay3z/usr294-verif.confirm which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3839950
URL: https://srvhub.6toralex.surf/sh5hne-c8b9b4-sskjy-znq2k2of-ybay3z/usr294-verif.confirm
URL Status:Offline
Host: srvhub.6toralex.surf
Date added:2026-05-05 21:00:08 UTC
Last online:2026-05-06 14:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter:Anonymous
Abuse complaint sent (?): Yes (2026-05-05 21:00:23 UTC to abuse{at}cloudflare[dot]com)
Takedown time:17 hours, 49 minutes Good (down since 2026-05-06 14:49:48 UTC)
Tags:ClearFake

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-05-06usr294-verif.confirmdll f0e08e9e4264f9a56a87d9ccfeca70f0e2a8cb1f868f7d61d677cd28f3f5aa42n/a 
2026-05-06usr294-verif.confirmdll a1c18d5121b7cf9be0c84f6c75d4d82cdcf9166043c71cc710e8653a51cf3a45n/a
2026-05-05usr294-verif.confirmdll 4578983213d268c6b5add3f1dc9f174fd015fa2d55d2ed66149035d1d6401c14n/a
2026-05-05usr294-verif.confirmdll 5f4362084bdc42c0f47723e25f614a87590db6aa1b24450880c324df675a30a9n/a