URLhaus Database

Every malware URL on URLhaus is associated with a host. A host can be either an domain name or an IP address (in case the malware URL is hosted on an IP address and doesn't use a domain name).

Database Entry


Host: gstat.dondyablo.com
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Control D HaGeZi :Not blocked
Firstseen:2020-04-28 03:09:02 UTC
Total malware sites :1
A record(s) observed :6

IP addresses


The table below shows all IP address observed for this particular host (in case the host is a domain name, all A records will be listed - including all historical ones). Please note that the output is limited to 10 entires.

Firstseen (UTC)IP addressHostnameSBLASNCountryActive?
2020-04-28 15:52:47 193.111.155.30193.111.155.30.deltahost-ptrNot listedAS42159 DELTAHOST-AS- NLyes
2020-04-28 14:49:40 195.22.152.76tungys1.example.comNot listedAS47196 Garant-Park-Internet- RUyes
2020-04-28 07:16:21 81.177.26.200Not listedAS8342 RTCOMM-AS- RUno
2020-04-28 03:09:04 82.146.49.85eugexl1.fvds.ruNot listedAS29182 RU-JSCIOT- RUno

Malware URLs


The table below shows all malware URLs that are associated with this particular host.

Dateadded (UTC)URLStatusTagsReporter
2020-04-28 03:09:05http://gstat.dondyablo.com/fattura.exeOfflineDreambot ext exe Gozi ext ursnif ext p5yb34m

The table below shows recent payloads delivery by this host.

Firstseen (UTC)SHA256 hashFile typeBazaarSignature
2020-04-30 04:08:36cddf3cc072913f9e5b0a020b12a0d80184b34a82f6ea6f8f7e95475a87de268cexe Gozi
2020-04-30 03:27:43ca05aa620812fc10329f8081fd406dbad3b598a7327b42c2225238028c4bd7e2exe Gozi
2020-04-29 23:00:409deb03451234d8e7d174e9b28820772588b5a7c3722b2d25f92663d2a440fb2bexe Gozi
2020-04-29 19:57:46976987d0a331db7c2bb240d12efe841ba7937fa55929169a84bf795128249beeexe Gozi
2020-04-29 18:02:19c7302529dfc17cf19775b5e18736238566aae6da83b6addb238169ea3b469127exe Gozi
2020-04-29 15:24:396eb52f5195dd1a3192f8863f40fa7e23199a3ae468d7c862121842262b18baa4exe  
2020-04-29 14:21:52bcee3f98f0c43cfaf390cafdfdf6ccba0288da1f322692fc88376cfc989eca27exe Gozi
2020-04-29 12:34:51298cf52ab3c16a3133b8759ddc9c107b4f50d280db1398cf42b889edf060602eexe Gozi
2020-04-29 09:14:33c7535e5745dd17b443a6f9e8317d40986c7be649c184cf8fb4c43f18bc2f63e1exe Gozi
2020-04-29 07:48:275c0994794fc629561847821cf4378729cda9197d9f4949d3b2646ecff3cb5259exe Gozi
2020-04-29 06:00:48c8c34200469907eb0e08f4a1fcbb0a2d02320c9b03a03eb78bd33fb153faffc2exe Gozi
2020-04-28 23:45:20ea0342b7236728f3068d81a922d0e81543910b63c287a03bf2045fc8cb34f52eexe Gozi
2020-04-28 22:38:180f4c2408250e74f90f9702e9121d605dd6ecad8b2c66f4bc024dea134e2b11a1exe Gozi
2020-04-28 21:51:10d6be0f5afea82743ce414b66a395125474de5bcb1c81f6d61bf444db78615ea8exe Gozi
2020-04-28 21:10:22e848c3b50337dcbfe0ed11638394529f435cead68dbdcfdbeba7598ef55b5e11exe Gozi
2020-04-28 20:28:43c1de1b3b2414c72b55a52e43774edbc958a12866c98d78cd3a875735312b3439exe Gozi
2020-04-28 19:23:22946adbce15a4f35bd87a3928710f148431f696bc9511583c5f63b7e6c9d30771exe Gozi
2020-04-28 19:00:56509507afe833e7aa2ccd8633cdb272178c3ea26f6742ff57416e4d7079bcaba7exe Gozi
2020-04-28 18:21:144f28b77016a56fff0e99688cd6348301dcc98421f3d614161a64c18e2bdff413exe Gozi
2020-04-28 17:29:4478ab5f5da002769f5104e87bf633930d4218f9c764699427a01384d15e7ed43fexe Gozi
2020-04-28 15:14:52454100af51eec868d71d2994dc370aad164375d4b640bfddce831ee3fa940b8fexe Gozi
2020-04-28 14:23:13d477ca313a35d4d01159dc676295d33117bb7e061162e6f400ebdd381e56c30eexe Gozi
2020-04-28 12:23:208db92b0c9d4b4f84dff157537c0b87110ec52e7b0e055f2f7a7e15d459ef2a03exe Gozi
2020-04-28 11:45:55fffbb1abdef029f1ace178c9ef5eae89946518db511c014c8d911459187158abexe Gozi
2020-04-28 09:38:20c80ce621a00bb036a877014452aab62040f9632b256f313e917abe4cc26c0b98exe Gozi
2020-04-28 09:00:17acb1ee7cf3fb321d303a95c9dcfe7ccb0a6bcbbdfa12df91b483827bdecd95d1exe Gozi
2020-04-28 08:30:1072d1a65a38fce80182cf27c5d40ac135af2831b25d76da3f87c25b0f285ed99cexe Gozi
2020-04-28 08:13:160886908df3034115dba91181a242e6a2f537f1b824d7dd863648484776fb4a8dexe Gozi
2020-04-28 07:26:3187a4426c28ae029b6b88b5711e3f2378ad78ab5c970bf5a4f17ec988bb5674c8exe Gozi
2020-04-28 06:16:098e2a28aad8af599120e8c298c7d82e755c4945b31528a15322b0ae792a6de6c5exeGozi
2020-04-28 06:03:254bbe789e75c3c70093e97e042beff6b8c231e8718fc38c85971ba7a30bed7597exe Gozi
2020-04-28 03:09:040517ba9bfb6cbc246dbc04db72f99a7abaece00a8ab3be017c29cd485f84989fexe Gozi