URLhaus Database

You are currently viewing the URLhaus database entry for http://91.212.150.4/gonu.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1000963
URL: http://91.212.150.4/gonu.exe
URL Status:Offline
Host: 91.212.150.4
Date added:2021-02-11 12:18:06 UTC
Last online:2021-03-11 12:XX:XX UTC
Threat:Malware download Malware download
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2021-02-11 12:20:17 UTC to alexx[dot]person{at}gmail[dot]com)
Takedown time:27 days, 23 hours, 49 minutes Bad (down since 2021-03-11 12:09:49 UTC)
Tags:CULNADY LTD LTD RemoteManipulator link ServHelper link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2021-03-11n/aexe fdebb3925c5a458141e9cc3ae46c9b439baa328a397131f7f6ac51c0a4b59547n/a 
2021-03-11n/aexe d9ac95bbb83a59b4eba673c76914ff935540426859851863d8c30cf9419abaa9n/a 
2021-03-11n/aexe a298bd0b72bfabf20cb67336346e19d8d43de8fae858a0a3fce6b55a8a8da43fn/a
2021-03-10n/aexe 16ce472ccbff2b6f58a99d9e101bfebbd2cfbb2a1238021cfe7e0e8f1634c954n/a
2021-03-09n/aexe 58e1370fdd747d652f4c8e0dc59188f3dfabb6dfcd3491c6fe4b81c3305d5a46n/aServHelper
2021-03-09n/aexe 4768e6d2b9709724630666d0e683410f9e2387bf32a4646798dbe46a98831654n/a
2021-03-09n/aexe b54ea188ed42d6e598cef2b2687cf2b0e61c73aa4ba664f8eb8552234268519dn/a
2021-03-08n/aexe 870c7c8a33ecded1784c2dab4d8027d3552f670d4138c049ad5b5ce7686b233dn/aServHelper
2021-03-08n/aexe e5a7bf831d2041fa65176ef53c8a2c02b089e17902a2e37e99f2caaa833c1b8an/a ServHelper
2021-03-07n/aexe 0da1ef07bcc55be3524bbfc24bddb0540bacf062bca73436d9a821a3cf88e3a7n/aServHelper
2021-03-06n/aexe ecb7d38e4d76cede2f47b8b31c0008086e16680fcfb2563a8d7f2e3dc871bb47n/a RemoteManipulator
2021-03-04n/aexe 3bb798492d069e8eb98d0850cce29e510f0befa18ad8f349349d35b4e395653en/a RemoteManipulator
2021-03-03n/aexe 7f8875c429f32788547639c9bbe36793b2d565de181dc1ccc07404345ef52253n/aRemoteManipulator
2021-03-01n/aexe da18331d180a3a26596943d23d2aa8e1a2ef1f245d935eb9f3dd800aee77e851n/a RemoteManipulator
2021-02-26n/aexe 2347cc0db179374f808400368b0a66f1c15e02ad28d2b93ccc26d5aafb9777can/aRemoteManipulator
2021-02-26n/aexe eb2fd16a678bea5e7c708e99aa7d19189b1de6c7c6f4fed903b7348a6e128cfdn/a RemoteManipulator
2021-02-25n/aexe 29e3702f28a1dd959ba56805130f040a2414a38e8399599f0b47f632a8eaeedbn/a RemoteManipulator
2021-02-24n/aexe c0a4c6bf6f0ffd6bae65f98f115534eccc2a2de0984c0825318e14c4b4d22cfdn/a RemoteManipulator
2021-02-24n/aexe d10fbb373ed55c7c43718b7257ae790adf19d2a8d30e4bc5688db690ce72fb16n/a RemoteManipulator
2021-02-21n/aexe 4bf8f42f17bf3b4b98ee2c0418bb3f75c0471530342a9884cb7714b96c6c2b2bn/a RemoteManipulator
2021-02-21n/aexe 826fb62aa2659c50864af07f2cd840e15310043a138f8ced0872e7d9a9fcdb4bn/aRemoteManipulator
2021-02-20n/aexe cb243bbb746bd35098184e88a5dc5dc25dc3c008bcc17cab57421b9c26a03ba5n/a RemoteManipulator
2021-02-20n/aexe 11a3e811f2a491a0182240b4765d19601c833eaa1217cf989958bfe0cef03834n/a RemoteManipulator
2021-02-19n/aexe c5ac4c65b75b966fe5257d03ac3333c23ff0a1bb5502b251943c2cecdd55c4ban/a RemoteManipulator
2021-02-19n/aexe c692c2889154ce3fc2338ac5998f66c9a9cd6a9f61950b3c4d71701159c1e7f1n/a RemoteManipulator
2021-02-19n/aexe 88526f56c361dc66a62854ac65236a6a3e214e4b27e3642be12839e2b66ae7d8n/a RemoteManipulator
2021-02-14n/aexe d926fe443c0ceb65e70cd64ac3d18a77d75d039486f1698dbd103c3cda2dff52n/aRemoteManipulator
2021-02-13n/aexe 5312214b15330113f6eab71565e1e3c7d1ee3b59daa6703c271aaf3b192e6809n/aRemoteManipulator
2021-02-13n/aexe f6f7f3647e865740ab06d24f66219a519f2b60572d424deb9273e919222d9376n/a
2021-02-12n/aexe db9b9e528146bd17ee05a0ff4eb73c2064e80a03d387b224d1b76c5a56e7c193n/a 
2021-02-11n/aexe 4bc8c57bc1c743b7607ba2e15670591551241fd3b129c266c5894159e72d1c72Virustotal results 51.43%