URLhaus Database

You are currently viewing the URLhaus database entry for https://gons20cl.top/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2731344
URL: https://gons20cl.top/build.exe
URL Status:Offline
Host: gons20cl.top
Date added:2023-11-16 15:21:06 UTC
Last online:2023-11-16 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-16 18:09:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:3 days, 13 hours, 1 minutes Bad (down since 2023-11-20 04:23:30 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Smoke Loader link Stealc Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-20n/aexe 0546f5dc01b3c39752e2d7b08dcb5062c151c3c2e7b2877f64a5c404c78c27b6Virustotal results 44.44% 
2023-11-19n/aexe 44f7e32d9d153692bf8e985566a42e118711c5c7c458354d9d2b8da8d3ecb34dn/aStealc
2023-11-19n/aexe 2b64b187c3f36ebcfeb40e5f975d923167d4e981cae7f4e2861611d1e1ae036dVirustotal results 40.28%Vidar
2023-11-19n/aexe bc182c1ad875034766bf6f30db48ccd680a19757d51c21624d40c29f8609eb9fn/aTosee
2023-11-19n/aexe a50880d6cbbc39560c99a3999e2b1fd0df3f0d5855a0f638a27489747a7f8877Virustotal results 40.28%Vidar
2023-11-18n/aexe 72363354fdb8847c45c1dc44e2a87a20da0fa04d52c2afddd24f8050a260b99bVirustotal results 38.89%Vidar
2023-11-18n/aexe 82c275cb45227b5f3b3d6b222a1e1b4a52f37d0de58655fd8daaa71efc4e0d1bn/aSmoke Loader
2023-11-18n/aexe 1df3ca3f121e7606f16c05fbec1f2d97925002242cf534118f522664ba689a52n/aVidar
2023-11-17n/aexe 0e093049b2e7265ce11c541b4f4d9125d44f668fb51ed397c51545c6b46f0fa1n/aVidar
2023-11-17n/aexe f7adca4cc02137f6abb62b551d2e3859f058ccddfc3626c1126cc73aee9b8fb4n/a MarsStealer
2023-11-17n/aexe 5e14a56ec2a51eafe98e9bdf632000b71c28d89ca3f73d03121445c8bead4042Virustotal results 43.06%Smoke Loader
2023-11-16n/aexe b04caf3e505f0d1a6ed6348f82d5ff27de4a8ff134154c13b20c0409912bb12cVirustotal results 45.07%Stealc