URLhaus Database

You are currently viewing the URLhaus database entry for http://fgggrttload04.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:879761
URL: http://fgggrttload04.top/downfiles/file.exe
URL Status:Offline
Host: fgggrttload04.top
Date added:2020-12-01 15:05:11 UTC
Last online:2020-12-04 11:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2020-12-01 15:06:39 UTC to abuse{at}firstbyte[dot]ru)
Takedown time:2 days, 20 hours, 25 minutes Poor (down since 2020-12-04 11:31:52 UTC)
Tags:CoinMiner cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-12-04n/aexe 01daa53b7ed02c52d05f5d2e6eb149f8627a2710cffb76db8660d7abcbf3d0afn/a 
2020-12-04n/aexe c75dff34b5bd8dfb80231d26c438d7a90ddddb488b5f75257b45e262c83be829Virustotal results 34.78% 
2020-12-03n/aexe 6cd0f7d63aed60b74d6a674b2b5def20a6f17e64c2956f2fa43d977c92ac99e5n/a 
2020-12-03n/aexe 93e06c74c2bf72afa35b46a93573ac2f72aeb1624843fe64463c530b355edc7fn/a 
2020-12-03n/aexe 4423139cbf5043925e71fe7e8734483602a901a9d003c8efacf959975c6e4c7dn/a 
2020-12-03n/aexe dfed5355cc51264ce10b2cca0c7b1631c67931021ea3d0eae22e7bfdd4dc8371n/a 
2020-12-03n/aexe ada1c5359c35e6b70c5a2d5533f9d725f86a1e155c8486bfd2941c9b40478ea2n/aCoinMiner
2020-12-03n/aexe b2a73ee5a9848746da4187766c0137788a5b74a0980d376d152414f69c10b779n/a 
2020-12-03n/aexe 36eaf4259bc87d681197d4ded7da1b5ca1e5fb55056cc77002d18ff5525f6027n/a 
2020-12-03n/aexe 69057a29d94d0ae3e51c435df396178b093d057db5addcdb273dcd5aedc6e1efn/aCryptBot
2020-12-02n/aexe 1ddcd6fa1bbbcac7e5ce606f6880e07f83cf366f9035972becc4dae47c62ed4an/a CryptBot
2020-12-02n/aexe 37cb831726dc1877ea59cf5618e4fa224368bbd64a7047dec6fb554a6a17d4c2n/aCoinMiner
2020-12-02n/aexe 07cf6baf41520d0e97f2010bf76c2ed10509fbf599209ae4bc250eb375515114n/aCryptBot
2020-12-02n/aexe b87a93613d0004b0d07eb302e75cd7030cb2a4bf466e92cec234e0abd8e6e727n/aCoinMiner
2020-12-02n/aexe e3df9e60142d41ca9b4b585b10b09c0e94c11111219bc4592a35efa3233eeaa1n/a 
2020-12-01n/aexe 490a21e6c601a106f4182298a0d595413a0fa92aa27fa8f38213c997e0b858ccn/a 
2020-12-01n/aexe b2803a668ae5609cc458ed4dfb12319c9916713fcca2978934b7fced263a78e8n/a 
2020-12-01n/aexe 173f822b40e4ec762c0f94eecc65f044a4a1f25911076b5970f4b04b1e2f98c0Virustotal results 43.66%