URLhaus Database

You are currently viewing the URLhaus database entry for https://www.gestroom.it/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry


ID:3463491
URL: https://www.gestroom.it/
URL Status:Offline
Host: www.gestroom.it
Date added:2025-03-02 20:17:20 UTC
Last online:2026-08-02 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Blocked
DNS4EU :Not blocked
Reporter: NDA0E
Abuse complaint sent (?): Yes (2025-03-02 20:18:49 UTC to abuse{at}staff[dot]aruba[dot]it)
Takedown time:1 year, 5 month, 7 days, 16 hours, 49 minutes Bad (down since 2026-08-02 13:08:37 UTC)
Tags:censys ClickFix FakeCaptcha html

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2026-08-02b97c6d152459a98e178d6928fb23a57c84f7a0ef5a94c98a0072a7ac6651e512.htmlhtml b97c6d152459a98e178d6928fb23a57c84f7a0ef5a94c98a0072a7ac6651e512n/a 
2026-08-01fb30af9c14015ec31a33e80a1cd447e280e18cc613b1f2099993e44beb646fea.htmlhtml fb30af9c14015ec31a33e80a1cd447e280e18cc613b1f2099993e44beb646fean/a 
2026-07-313d75b1f2a9da03af3847a32168bd69309c8585117f91f9027a9adec4b72d5355.htmlhtml 3d75b1f2a9da03af3847a32168bd69309c8585117f91f9027a9adec4b72d5355n/a 
2025-03-02n/ahtml c3baf1eaa63000020bdae8ecec6636b79adaefa6b290480d94959b54666f1ca7Virustotal results 43.75%