URLhaus Database

You are currently viewing the URLhaus database entry for http://exeseria.com/aperto which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2676448
URL: http://exeseria.com/aperto
URL Status:Offline
Host: exeseria.com
Date added:2023-07-04 12:31:11 UTC
Last online:2023-07-04 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2023-07-04 12:32:13 UTC to mail{at}proton66[dot]ru)
Takedown time:3 hours, 43 minutes Good (down since 2023-07-04 16:15:29 UTC)
Tags:brt geofenced Gozi link ISFB link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-07-04Fatt_20230704_6248658748.zipzip cd011ff00865510ae1f4affe3b6815d8405edc9aad2e4d4d4c75125e7d360572n/a Gozi
2023-07-04Fatt_20230704_3983266884.zipzip 9cd2c8168574eeefc6fa0e1b8a757b6ef82f9142a6e43d86a05168653bb2a32bn/a Gozi
2023-07-04Fatt_20230704_8766861713.zipzip 689d9603edc0228d287facf70000f764804e38bc14cacd91603d9d8f9c2adfa9n/a Gozi
2023-07-04Fatt_20230704_2095358769.zipzip 4627ddd3fd354152c5e1b25cd091ffbb951f09d49c39e968bfcf62653012e007n/a Gozi
2023-07-04Fatt_20230704_2911251602.zipzip caa5013876275a07a695742e8f0c232b114ac0bd6669c1d8b694024747c1a64an/a Gozi
2023-07-04Fatt_20230704_2284499744.zipzip 2870a81354d09f2c2e7f10a41465526d3391e513014d200b7b80a9fc999819c1n/a Gozi