URLhaus Database

You are currently viewing the URLhaus database entry for http://link.icloudcowboy.com/setup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:390024
URL: http://link.icloudcowboy.com/setup.exe
URL Status:Offline
Host: link.icloudcowboy.com
Date added:2020-06-15 06:37:04 UTC
Last online:2020-06-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-06-15 12:40:03 UTC to info{at}inoventica[dot]ru)
Takedown time:6 days, 19 hours, 58 minutes Bad (down since 2020-06-22 08:38:53 UTC)
Tags:geofenced Gozi link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-21n/aexe 6371f0247fc473f4a62dc80511eb8e67ef1cdcaf97109227d64541f8957402bcn/a 
2020-06-20n/aexe 4a4972c000b3d822d99c77e77c3608f8da72fb3ea73e8a6cc2ca2d1c68f8d0f8n/a 
2020-06-16n/aexe 6a473e38f47d6ec7d3dcdcd4ccd8e1d8d9e388d1b8b169011bf89c273327d5a3n/aGozi
2020-06-16n/aexe 82d62675daaa3a85f419c86bf5221e55e1e26f830fc711dcafc574d567afa634n/a Gozi
2020-06-16n/aexe 2fde4d251ebdd918124280abfc53ab05b42b7b0bf51cd5409dab20f7bd26f657n/a Gozi
2020-06-16n/aexe 9aaf4cf4d3f24b75f82f3200c9c1172f68021845707b524318b78d925f49adc2n/a Gozi
2020-06-15n/aexe 66d93e44b4091c24fc2b319efd9eabe43932ab85e32a08fe87d9428ea0b71aedn/a Gozi
2020-06-15n/aexe 54f3af6816ec5a9454043a657621985670b043da6a1fbee8c462e3ecc3edd39fn/a Gozi
2020-06-15n/aexe d6ad700c9b42767e90bd7e552434f00c5945b82ff5d4185223f64347def4b8b4n/a Gozi
2020-06-15n/aexe 500f87d09dc1e2a1c245247d2d14f5897eddb2857c3abe67aa0600527c4dc9d3n/a Gozi
2020-06-15n/aexe 6faa3110db3a2b6d2d2b377a519fda1e6818284f3c25a1ef379f3e1f6634cea6n/a Gozi
2020-06-15n/aexe 2cd12c96677db4e592b2ec01eccb0ba9a51b061498a36441f422de372d13da4fn/a Gozi
2020-06-15n/aexe 29eba6e40bd67080024f220aea3bfc15b532c4e4d0fdf0c802689496f2744f32n/a Gozi
2020-06-15n/aexe 9f28fb3c7a60d8cf4b320887f25ed84417ec984d7e255910ed8127e23e7b3b9en/a Gozi
2020-06-15n/aexe 9f28fb3c7a60d8cf4b320887f25ed84417ec984d7e255910ed8127e23e7b3b9en/a Gozi
2020-06-15n/aexe b57950321a93e2d2930e926087e1945e3bbfa78a4265bdc4bf888afcf781a27dVirustotal results 27.40% Gozi