URLhaus Database

You are currently viewing the URLhaus database entry for http://gstat.bluechipstaffing.com/fattura.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:348056
URL: http://gstat.bluechipstaffing.com/fattura.exe
URL Status:Offline
Host: gstat.bluechipstaffing.com
Date added:2020-04-22 07:23:05 UTC
Last online:2020-04-23 07:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-04-22 07:24:02 UTC to abuse{at}ovh[dot]net)
Takedown time:23 hours, 38 minutes Good (down since 2020-04-23 07:02:40 UTC)
Tags:exe Gozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-23n/aexe 68993e2185bf6f6ecb308c4cedfde6c0abaaf80d0862dfa1c675d2705bba064an/a Gozi
2020-04-23n/aexe 920ad1ae22655f9850cdd3d302cd6b52705b10c871aaa12af3e66bf089f71eacn/a Gozi
2020-04-23n/aexe ab7e2e1d3c57f9a379d7b35d65b2574a472f35f8e52fd00c73be9da486a5fd1an/a Gozi
2020-04-22n/aexe 0b93b892b9f03ffd09ade54471b05da183845a26ef7c81a2ca6a789f7fbf821bn/a Gozi
2020-04-22n/aexe b30f5f792e8febb7839e9bf5c77e9aa88f14f10a9c149d7047e37462c2238a7cn/a Gozi
2020-04-22n/aexe 24dad84da20d706f5fd197a4f011d47d9438322110d41b76399e62f163767b38n/a Gozi
2020-04-22n/aexe 1adcc9fc9fa63988743f96c99e20083e7960b16ef0a38c8a20889f5c85947a92n/a Gozi
2020-04-22n/aexe 7e6f65cd14c02b7516ae2d438e8f263107f719d00d7b1ef7c7a38bf4ec47974an/a 
2020-04-22n/aexe b6cae5238debed04df2bbe86fac8f4dd7feaa0c205f582719735f6ca82fba156n/a Gozi
2020-04-22n/aexe cd4e2a8e52f9160e7d25e3a1cf0ee45a1b3c88831cb76e049622bd69170289c5n/aGozi
2020-04-22n/aexe 51710ac663a6fd3bc7f166045d4cb38b1e1796195b4aab057b4133df8db9ef8bn/aGozi
2020-04-22n/aexe acfc2a0c6eaf9209bc6036bd385b70fc6971b51ea9dab0eaefb5ac99b674b658Virustotal results 31.51%Gozi
2020-04-22n/aexe 55c9174f8e46852cecde40c6816bdb6758b033113a6383dc1bcebdf77fd63be4n/aGozi
2020-04-22n/aexe fac11630f88bfc6ce7e3b65fe8a2f50bb1de4722254bf95b3b161528ac9d6e8an/a Gozi
2020-04-22n/aexe bd27fe96b334c81e8b62bda3121306619ca317dad8a971daf0639cb896953006n/aGozi