🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

URLhaus Database

You are currently viewing the URLhaus database entry for https://gomaspureglow.com.br/acr/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry



ID:2714234
URL: https://gomaspureglow.com.br/acr/
URL Status:Offline
Host: gomaspureglow.com.br
Date added:2023-09-26 10:46:08 UTC
Last online:2023-09-27 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: 0x48215333
Abuse complaint sent (?): Yes (2023-09-27 10:12:05 UTC to abuse{at}bluehost[dot]com)
Takedown time:8 hours, 38 minutes Good (down since 2023-09-27 18:50:37 UTC)
Tags:DarkGate link xll

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-09-27I.zipzip 72549b57edccef3a16821cd2b6f27587ed35eab6155cb165b69918a6d3450852n/aDarkGate
2023-09-27Nm.zipzip 66b1a14ea50b7977e44d78a36966d5b622a550d187cc03d9eacc3c884de93596n/a 
2023-09-27Mxq.zipzip 13149a118c4568740448f7a7bd0fa86fb6c9107ffaf6d0bbb79f135172324ab0n/a 
2023-09-27A.zipzip 0567be2a3f2edb6263e8e14ab06d718a74d79927183163b844263f164919ea7cVirustotal results 4.76% 
2023-09-27Bwm.zipzip 39edd03b27c8a3e37d429b7d279cafdb0ae92367b3bcb1068ab3eda0a6dc4b71Virustotal results 4.92%