URLhaus Database

You are currently viewing the URLhaus database entry for http://topprogress.top/bestof/gfers.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:949292
URL: http://topprogress.top/bestof/gfers.exe
URL Status:Offline
Host: topprogress.top
Date added:2021-01-05 07:44:06 UTC
Last online:2021-01-11 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-01-05 07:46:03 UTC to admin{at}isphoster[dot]net)
Takedown time:5 days, 23 hours, 54 minutes Bad (down since 2021-01-11 07:40:05 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-11n/aexe eec9f565329a6a6e4129c775a212eda9a3e23001dff996345538de0ea1f6bdfcVirustotal results 33.33%RedLineStealer
2021-01-08n/aexe 0a5faef2bdcce3d5b58e9062bf8f936596a96eaf0b270ed86cac3033cd922537n/aRedLineStealer
2021-01-07n/aexe 36e2d47f3667ec11a9853dbc29f67599970b96f16692a6212757d3b7410de34cn/aRedLineStealer
2021-01-05n/aexe ecebc42356531d726c29149265632f77431e6d597e88372326d19d821952f565n/aRedLineStealer
2021-01-05n/aexe c30d45a309b85b010bc04905b7f43d81926a60c7e8c5f387b659517425ce083bVirustotal results 31.43%RedLineStealer