URLhaus Database

URLhaus tries to identify the malware associated with the payload served by a certain malware URL. In case URLhaus is able to identify the associated malware family, the payload will be tagged accordingly (field signature). The page below gives you an overview on payloads that URLhaus has identified as GOStealer.

Database Entry


Signature:GOStealer
Firstseen:2025-04-22 15:29:12 UTC
Lastseen:2025-06-03 21:04:14 UTC
Unique Payloads:4
URLs:4

Payload


The table below shows all payloads that have been identified as GOStealer.

Firstseen (UTC)SHA256File TypeFile sizeVT
2025-06-03 21:04:149bba769ad5a9076dd020a60431a69a406ea8c5286994bcd8da425d5df060765eExecutable exe2'944'000Virustotal results 41 / 70 (58.57)
2025-06-03 21:04:1460a3e9b585d2296977b7074e4d1ceb6dcad8e66453683f2f1212d75c06730737Executable exe2'944'000n/a
2025-04-24 12:51:078953c494ae38623a62bea5c6705056fd8dce59f88f1d3c2b5da89cfa71f620a9Executable exe8'514'560Virustotal results 45 / 72 (62.50)
2025-04-22 15:29:128953c494ae38623a62bea5c6705056fd8dce59f88f1d3c2b5da89cfa71f620a9Executable exe8'514'560Virustotal results 13 / 72 (18.06)

Number of entries displayed: 4 (max: 1'000)