URLhaus Database

You are currently viewing the URLhaus database entry for http://fakecontact.top/bestof/gfers.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:983276
URL: http://fakecontact.top/bestof/gfers.exe
URL Status:Offline
Host: fakecontact.top
Date added:2021-01-29 16:30:07 UTC
Last online:2021-02-05 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-01-29 16:32:02 UTC to google-cloud-compliance{at}google[dot]com)
Takedown time:7 days, 4 hours, 40 minutes Bad (down since 2021-02-05 21:12:35 UTC)
Tags:exe RedLineStealer link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-05n/aexe 1e19d49cb015cb4d7e892c62020689becff9a9a721a6a8191f00c846a87db0b9n/a RedLineStealer
2021-02-04n/aexe c4b04c108c2308b1bb0558cf3de4fc2b1357a8c112d7bc38c228874000b8a4bdn/aRedLineStealer
2021-02-03n/aexe fd90532ae98860320f8c3a02045912a0e38bfc3c9b2772ca2683a769f668cd1dn/a RedLineStealer
2021-02-02n/aexe 75c351553ed5f1ce8e0dd3ad0d97f98050dacf934fe15e3f7e9c1b7c9a3aa45an/aRedLineStealer
2021-02-01n/aexe bec5357c8a455639460f76de7bac4220c225a1770cfb5448de3c8885a22a8ba4n/aRedLineStealer
2021-02-01n/aexe 9dfa1f5136c588a4433ec532ed12ebc5ee703439462b69af9a36854980fadef3Virustotal results 49.30% RedLineStealer
2021-01-29n/aexe 2fb53f979d17779c590040e61d10a5fcfbc39a49b22268bb51c0a49745687d8fn/a RedLineStealer
2021-01-29n/aexe a587c3f101f95fced4c0096f4d7617aa6448f00cedba55478b439b825a491335n/aRedLineStealer
2021-01-29n/aexe 47162ef38e515cecd61c767bc97b7588a985c65d56f858bd8b85789bbdd66d80n/aRedLineStealer