URLhaus Database

You are currently viewing the URLhaus database entry for https://gons22cl.top/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2731907
URL: https://gons22cl.top/build.exe
URL Status:Offline
Host: gons22cl.top
Date added:2023-11-18 16:40:10 UTC
Last online:2023-11-18 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-18 16:50:07 UTC to abuse{at}cloudflare[dot]com)
Takedown time:1 day, 11 hours, 12 minutes Poor (down since 2023-11-20 03:53:20 UTC)
Tags:dropped-by-PrivateLoader Stealc Vidar link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-19n/aexe 44f7e32d9d153692bf8e985566a42e118711c5c7c458354d9d2b8da8d3ecb34dVirustotal results 40.28%Stealc
2023-11-19n/aexe 2b64b187c3f36ebcfeb40e5f975d923167d4e981cae7f4e2861611d1e1ae036dVirustotal results 40.28%Vidar
2023-11-19n/aexe bc182c1ad875034766bf6f30db48ccd680a19757d51c21624d40c29f8609eb9fVirustotal results 40.28%Tosee
2023-11-19n/aexe a50880d6cbbc39560c99a3999e2b1fd0df3f0d5855a0f638a27489747a7f8877n/aVidar
2023-11-18n/aexe 72363354fdb8847c45c1dc44e2a87a20da0fa04d52c2afddd24f8050a260b99bVirustotal results 50.00%Vidar