URLhaus Database

You are currently viewing the URLhaus database entry for https://gestroom.it/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3463483
URL: https://gestroom.it/
URL Status:flame Online (spreading malware for 1 year, 5 month, 5 days, 7 hours, 19 minutes)
Host: gestroom.it
Date added:2025-03-02 20:17:19 UTC
Threat:Malware download Malware download
URLhaus blocklist:Blocked
Spamhaus DBL :Abused domain (malware)
SURBL :Blocked
Quad9 :Blocked
AdGuard :Not blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-02 20:18:49 UTC to abuse{at}staff[dot]aruba[dot]it)
Tags:censys ClickFix FakeCaptcha html

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-07-31e9a5ff4af29de0cd052170ab089007a371ca83c1a6b2c6c21886aaececffd3f0.htmlhtml e9a5ff4af29de0cd052170ab089007a371ca83c1a6b2c6c21886aaececffd3f0n/a 
2026-07-298c80a834d141a1559e91ff66644d360cf1ab0c4b62a5333b17652f60dffa163e.htmlhtml 8c80a834d141a1559e91ff66644d360cf1ab0c4b62a5333b17652f60dffa163en/a 
2026-07-299786a66f9d9baaa3883bc8f4846de36912ed598fc417698480a612863c451490.htmlhtml 9786a66f9d9baaa3883bc8f4846de36912ed598fc417698480a612863c451490n/a 
2026-07-29eee55e368e06d63a715ab27a2200ba9856e01319d47b7f7175aef5e924ccd3f0.htmlhtml eee55e368e06d63a715ab27a2200ba9856e01319d47b7f7175aef5e924ccd3f0n/a 
2025-03-02n/ahtml c3baf1eaa63000020bdae8ecec6636b79adaefa6b290480d94959b54666f1ca7Virustotal results 43.75%