URLhaus Database

You are currently viewing the URLhaus database entry for https://gosp.davidmolins.com/chrome_130.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:3272967
URL: https://gosp.davidmolins.com/chrome_130.exe
URL Status:Offline
Host: gosp.davidmolins.com
Date added:2024-11-03 04:09:06 UTC
Last online:2024-11-04 10:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: zbetcheckin
Abuse complaint sent (?): Yes (2024-11-03 04:10:17 UTC to abuse{at}arsys[dot]es)
Takedown time:1 day, 6 hours, 8 minutes Poor (down since 2024-11-04 10:19:00 UTC)
Tags:32 exe MarsStealer Stealc

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2024-11-04n/aexe 3805f2b6eb73752f99910178fe7e1492126b9be62476255c4dd2fda68b2f8d11Virustotal results 43.66%Stealc
2024-11-03n/aexe 42da2fffa02da4fcd1a1ae6d4e070b9cfeec392ea045312caf9032aeed3c58b5n/a MarsStealer
2024-11-03n/aexe 359a61c84208516ab566e6f413ce19932c80b5ed07753d541c44ba54af3a24fen/aStealc
2024-11-03n/aexe 4a4880d1b307a8e5aa3b518bcf0e9470b793a8d5b98b068bd2404b1b0d952edeVirustotal results 41.67%Stealc
2024-11-03n/aexe ae7c55423a0fba87ed316817cb423b5fd562e88b0b978c3a6f8860142c3e6d7eVirustotal results 40.28%Stealc