URLhaus Database

You are currently viewing the URLhaus database entry for http://cotraresr04.top/downfiles/lv.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:998482
URL: http://cotraresr04.top/downfiles/lv.exe
URL Status:Offline
Host: cotraresr04.top
Date added:2021-02-10 08:16:14 UTC
Last online:2021-02-12 04:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2021-02-10 08:18:05 UTC to anti-spam{at}list[dot]alibaba-inc[dot]com)
Takedown time:1 day, 20 hours, 25 minutes Poor (down since 2021-02-12 04:43:17 UTC)
Tags:DanaBot link exe

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-02-12n/aexe eea7b6d98c2f0ae7a10c5565bfca286cc96ba9c9e3ddc65670b323b0087edebcn/a DanaBot
2021-02-11n/aexe a78bc685aa18e6dc62798efda47ebe4a0a6ea5193682cf68d09fb14c727ae5ban/a DanaBot
2021-02-11n/aexe c846fb5099000a51968f3ff0aec93ad09569efea0825cb1c47f57582bea818d7n/a DanaBot
2021-02-11n/aexe 75223973ad04247918d1e7f3145f29872eba7c30583788fe71ae61233da4df71n/a
2021-02-11n/aexe 6d5a0cabd7fe5be134e8c2e1e509af2ffcdfc7e2f4009a94880fcca080874d9dn/a
2021-02-11n/aexe c6fabe2e224e7c72496f3fbd3241ee6aeef85ee68611c1b0e518cb420cfa2459n/a
2021-02-10n/aexe 49771de8bcea44c22d54d1eebc9f05ff0d33f66355fbf9dd77e7e891cd062bccn/aDanaBot
2021-02-10n/aexe 8e76055823664f0cabcd8fdd17ccdef01f0dcc584346b59d8c0dfbfefa547ab2n/aDanaBot