URLhaus Database

You are currently viewing the URLhaus database entry for http://balkun.com/operazione which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2668295
URL: http://balkun.com/operazione
URL Status:Offline
Host: balkun.com
Date added:2023-06-21 08:22:06 UTC
Last online:2023-06-22 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-06-21 08:23:06 UTC to abuse{at}rentaserv[dot]su)
Takedown time:23 hours, 46 minutes Good (down since 2023-06-22 08:09:42 UTC)
Tags:agenziaentrate geofenced Gozi link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-06-221_202306215864902259.zipzip 1c0b15ed7c50a8a40bb2fe4e98550d05fbb9735a78304b9bbc08c680ff34a611n/a Gozi
2023-06-211_202306213096447302.zipzip ab3aebb147be4a97157da5c7d1ff235a8e27f3b2ac10b5ce354712cc0afd9fd2n/a Gozi
2023-06-211_202306217251591141.zipzip 5021bb12674d4c21022786e9585d8af4603a48c8bd345f056db932dad10a2ddan/a Gozi
2023-06-211_202306213884665054.zipzip d90d7183d25f23cec58f94176a80afd929e94ea33a111f9318de23d6888b3faen/a Gozi
2023-06-211_202306211591278661.zipzip f628b33521cfb55daf491b34961f17b20614d3efd83b3ea475a6156eabb937edn/a Gozi
2023-06-211_202306219853411945.zipzip e187518dd2fd5d4410729199dd45b2d0c8c6e3b8b04260a8caa6589abc5d007cn/a Gozi
2023-06-210_202306218045367911.zipzip 73304800ebb161345bb532e26a299a9e58a145a8cedbfdc300e26081c18bd8b2n/a Gozi