URLhaus Database

You are currently viewing the URLhaus database entry for http://209.141.58.111:8080/gwupdater.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:1862765
URL: http://209.141.58.111:8080/gwupdater.exe
URL Status:Offline
Host: 209.141.58.111
Date added:2021-12-07 13:41:04 UTC
Last online:2021-12-29 17:XX:XX UTC
Threat:Malware download Malware download
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2021-12-22 11:37:25 UTC to admin{at}frantech[dot]ca,fdias{at}frantech[dot]ca)
Takedown time:4 months, 27 days, 19 hours, 57 minutes Bad (down since 2022-05-04 09:41:13 UTC)
Tags:32 exe nitol link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2022-01-23gwupdater.exeexe 130cf972bf44124d373d75675db814b23b0a50a9c0ffcff4c2171a06e76fc015n/aNitol
2022-01-23gwupdater.exeexe 153157d1cfd1fdd77cf5b40ce3a36c8022eeb5f255858422f156a4fc06c9bb45n/a Nitol
2021-12-12gwupdater.exeexe 109df6318a320246f7a561fbf3ed4dff149d21c89c8337e6530c068914dfe8e2n/a 
2021-12-08gwupdater.exeexe cbc8f0215f9f14b78f221528abe36567a1b05a2a92dd4b7d5eff4e47c44b3072n/a 
2021-12-07gwupdater.exeexe cb3d42cb0a374cded8d38f8403df22170689a5e196c98186d10495e60a798837Virustotal results 77.94%Nitol