URLhaus Database

You are currently viewing the URLhaus database entry for http://gstat.hamiltoncustomhomesinc.com/fattura.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:350489
URL: http://gstat.hamiltoncustomhomesinc.com/fattura.exe
URL Status:Offline
Host: gstat.hamiltoncustomhomesinc.com
Date added:2020-04-24 06:37:09 UTC
Last online:2020-04-24 23:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-04-24 06:38:05 UTC to admin{at}vpsville[dot]ru)
Takedown time:16 hours, 32 minutes Good (down since 2020-04-24 23:10:52 UTC)
Tags:exe Gozi link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-24n/aexe 50a6e7077b8be20451d09fc1a487cf9bfb0d22e23c0eec589823670deaee5453n/a Gozi
2020-04-24n/aexe b82a534f51108af22767e1b83cdacf19ccfc8ac898f5f4c6ab07ee1f7c9178c0n/a Gozi
2020-04-24n/aexe 4f9be4851740b6d20406aca8c7f65916e4ec041f839d24e302165fe12b25b973n/a Gozi
2020-04-24n/aexe 3d03e79be7e1bd5bf02508c4599e6d3e4e66103fedb48b9a6ac29deb234cba79n/a Gozi
2020-04-24n/aexe f26ab4b562d8974a0d4c70065a7b7e51dc72918b8ec409670ca2b4d4b8a7d99bn/a Gozi
2020-04-24n/aexe e7543c5dbc2378d3c4b6401f764764986e5c9773383f5837346af7e785528f3dn/aGozi
2020-04-24n/aexe a564910112b33b769485254ae891a16cbb5b91ad5a099408e290658698edc81an/aGozi
2020-04-24n/aexe 263d4bcfcc2e1cd9d3de9bbc585864861dda333cdd2e0158e3c47ff70540aefdn/aGozi
2020-04-24n/aexe 744f341a285a15647220b1dda12600c38b754a5d810f0fc5240a96a9ee44714dn/aGozi
2020-04-24n/aexe 75e3028aa0c2dfb079a4bf42a11bf65c6265d539fa4b6cb600cf144bdfba5df9Virustotal results 37.14%Gozi
2020-04-24n/aexe 5a05c55c863b0ca4ee89a521557e881cd17434f5b485baca0d1603a6ba61d880n/a Gozi
2020-04-24n/aexe d04ce36b2c6a5888bf4c413ed5a1c8d2e16af857957742059e7f4de74d36d854n/aGozi