URLhaus Database

You are currently viewing the URLhaus database entry for http://kypersab36.top/downfiles/file.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:951747
URL: http://kypersab36.top/downfiles/file.exe
URL Status:Offline
Host: kypersab36.top
Date added:2021-01-10 12:29:04 UTC
Last online:2021-01-12 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-01-10 12:30:05 UTC to mak{at}mcntelecom[dot]com)
Takedown time:2 days, 1 hours, 5 minutes Poor (down since 2021-01-12 13:35:56 UTC)
Tags:cryptbot exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-01-11n/aexe c9b0f5d90420edebaa0e60551c6dfdff2ff89bd05cdc4993d20670157f7667a2n/a 
2021-01-11n/aexe 30e374185ded5944c1ff0b2150cdaf2af9decb76a41089351cd21db2c3d1afaen/aCryptBot
2021-01-11n/aexe fccd7d5301e46046f199343583a436d0869f49ae668aeedd41b76d75c403701en/aCryptBot
2021-01-11n/aexe c34a85e738b7c8fa703aaa447cd24d17ff08baae5d4b44b7c2131c5df164b9a3n/aCryptBot
2021-01-10n/aexe b75f742ad569048f45c0898e017dfcc56e1ac7f98c40249a444fc1dad6ebb49cn/aCryptBot
2021-01-10n/aexe ffb27074c9ab066faecbaa1ad2e2824ba16553f0cf56fc658e62bc137db50c63n/aCryptBot
2021-01-10n/aexe 1a3e09c9e55edd4048813fe5a20a87e840cb96039f199a0f6f960f315a61486fn/aCryptBot
2021-01-10n/aexe 723cd9a121f4dbdd70fba3a061d63921ac8c7a20723f9eec00e7664e4b0ce454Virustotal results 30.00%CryptBot