URLhaus Database

You are currently viewing the URLhaus database entry for https://balkun.com/operazione which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2668285
URL: https://balkun.com/operazione
URL Status:Offline
Host: balkun.com
Date added:2023-06-21 08:00:12 UTC
Last online:2023-06-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2023-06-21 08:01:05 UTC to abuse{at}rentaserv[dot]su)
Takedown time:1 day, 0 hours, 6 minutes Poor (down since 2023-06-22 08:07:48 UTC)
Tags:agenziaentrate geofenced Gozi link ISFB link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-221_202306218294085473.zipzip 1b7fb6bd131888a988f065d50a7c5258f0a60f10e14828ed557a9157f7b8b212n/a Gozi
2023-06-211_202306218734096304.zipzip a346dc550e718ed1dcf0b3933855182d57d36915bfc8fe788cad38a1419ef839n/a Gozi
2023-06-211_202306219098536385.zipzip 48fc21c63f04589446b2365fd19f896694c189a256cc139a3081e62a1c187c9an/a Gozi
2023-06-211_202306219764164096.zipzip a40cc2ff7fcba950f7a3712e0a16e7fb9569d09edcc0a0d76fb792ae70607a7en/a Gozi
2023-06-211_202306214296496391.zipzip 5587ae9659c1f6e26ff0356a1b9fd8681ffc09f3f23e38621b3061c29d654eb0n/a Gozi
2023-06-211_202306213870721891.zipzip cfe4c4d38d3e56dec4dc67355f333ab3a316a5c2c3f19f39933c87d8ed4b510fn/a Gozi