URLhaus Database

You are currently viewing the URLhaus database entry for https://gons23cl.top/build.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:2732065
URL: https://gons23cl.top/build.exe
URL Status:Offline
Host: gons23cl.top
Date added:2023-11-19 16:56:07 UTC
Last online:2023-11-19 18:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Status unknown
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: andretavare5
Abuse complaint sent (?): Yes (2023-11-19 16:57:06 UTC to abuse{at}cloudflare[dot]com)
Takedown time:13 hours, 39 minutes Good (down since 2023-11-20 06:36:18 UTC)
Tags:dropped-by-PrivateLoader MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2023-11-20n/aexe ab0970c349e1e6576684cd3a41f01e9db604e975a3394d345a0f8997a8e6fb70n/a MarsStealer
2023-11-20n/aexe 0546f5dc01b3c39752e2d7b08dcb5062c151c3c2e7b2877f64a5c404c78c27b6n/a 
2023-11-19n/aexe 44f7e32d9d153692bf8e985566a42e118711c5c7c458354d9d2b8da8d3ecb34dVirustotal results 40.28%Stealc