URLhaus Database

You are currently viewing the URLhaus database entry for http://gstat.dondyablo.com/fattura.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:352683
URL: http://gstat.dondyablo.com/fattura.exe
URL Status:Offline
Host: gstat.dondyablo.com
Date added:2020-04-28 03:09:05 UTC
Last online:2020-05-05 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: p5yb34m
Abuse complaint sent (?): Yes (2020-04-28 03:10:09 UTC to admin{at}memvds[dot]com)
Takedown time:7 days, 18 hours, 12 minutes Bad (down since 2020-05-05 21:22:21 UTC)
Tags:Dreambot link exe Gozi link ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-04-30n/aexe cddf3cc072913f9e5b0a020b12a0d80184b34a82f6ea6f8f7e95475a87de268cn/a Gozi
2020-04-30n/aexe ca05aa620812fc10329f8081fd406dbad3b598a7327b42c2225238028c4bd7e2n/a Gozi
2020-04-29n/aexe 9deb03451234d8e7d174e9b28820772588b5a7c3722b2d25f92663d2a440fb2bn/a Gozi
2020-04-29n/aexe 976987d0a331db7c2bb240d12efe841ba7937fa55929169a84bf795128249been/a Gozi
2020-04-29n/aexe c7302529dfc17cf19775b5e18736238566aae6da83b6addb238169ea3b469127n/a Gozi
2020-04-29n/aexe 6eb52f5195dd1a3192f8863f40fa7e23199a3ae468d7c862121842262b18baa4n/a 
2020-04-29n/aexe bcee3f98f0c43cfaf390cafdfdf6ccba0288da1f322692fc88376cfc989eca27n/a Gozi
2020-04-29n/aexe 298cf52ab3c16a3133b8759ddc9c107b4f50d280db1398cf42b889edf060602en/a Gozi
2020-04-29n/aexe c7535e5745dd17b443a6f9e8317d40986c7be649c184cf8fb4c43f18bc2f63e1n/a Gozi
2020-04-29n/aexe 5c0994794fc629561847821cf4378729cda9197d9f4949d3b2646ecff3cb5259n/a Gozi
2020-04-29n/aexe c8c34200469907eb0e08f4a1fcbb0a2d02320c9b03a03eb78bd33fb153faffc2n/a Gozi
2020-04-28n/aexe ea0342b7236728f3068d81a922d0e81543910b63c287a03bf2045fc8cb34f52en/a Gozi
2020-04-28n/aexe 0f4c2408250e74f90f9702e9121d605dd6ecad8b2c66f4bc024dea134e2b11a1n/a Gozi
2020-04-28n/aexe d6be0f5afea82743ce414b66a395125474de5bcb1c81f6d61bf444db78615ea8n/a Gozi
2020-04-28n/aexe e848c3b50337dcbfe0ed11638394529f435cead68dbdcfdbeba7598ef55b5e11n/a Gozi
2020-04-28n/aexe c1de1b3b2414c72b55a52e43774edbc958a12866c98d78cd3a875735312b3439n/a Gozi
2020-04-28n/aexe 946adbce15a4f35bd87a3928710f148431f696bc9511583c5f63b7e6c9d30771n/a Gozi
2020-04-28n/aexe 509507afe833e7aa2ccd8633cdb272178c3ea26f6742ff57416e4d7079bcaba7n/a Gozi
2020-04-28n/aexe 4f28b77016a56fff0e99688cd6348301dcc98421f3d614161a64c18e2bdff413n/a Gozi
2020-04-28n/aexe 78ab5f5da002769f5104e87bf633930d4218f9c764699427a01384d15e7ed43fn/a Gozi
2020-04-28n/aexe 454100af51eec868d71d2994dc370aad164375d4b640bfddce831ee3fa940b8fn/a Gozi
2020-04-28n/aexe d477ca313a35d4d01159dc676295d33117bb7e061162e6f400ebdd381e56c30en/a Gozi
2020-04-28n/aexe 8db92b0c9d4b4f84dff157537c0b87110ec52e7b0e055f2f7a7e15d459ef2a03n/a Gozi
2020-04-28n/aexe fffbb1abdef029f1ace178c9ef5eae89946518db511c014c8d911459187158abn/a Gozi
2020-04-28n/aexe c80ce621a00bb036a877014452aab62040f9632b256f313e917abe4cc26c0b98n/a Gozi
2020-04-28n/aexe acb1ee7cf3fb321d303a95c9dcfe7ccb0a6bcbbdfa12df91b483827bdecd95d1n/a Gozi
2020-04-28n/aexe 72d1a65a38fce80182cf27c5d40ac135af2831b25d76da3f87c25b0f285ed99cn/a Gozi
2020-04-28n/aexe 0886908df3034115dba91181a242e6a2f537f1b824d7dd863648484776fb4a8dVirustotal results 25.35% Gozi
2020-04-28n/aexe 87a4426c28ae029b6b88b5711e3f2378ad78ab5c970bf5a4f17ec988bb5674c8Virustotal results 25.00% Gozi
2020-04-28n/aexe 8e2a28aad8af599120e8c298c7d82e755c4945b31528a15322b0ae792a6de6c5n/aGozi
2020-04-28n/aexe 4bbe789e75c3c70093e97e042beff6b8c231e8718fc38c85971ba7a30bed7597n/a Gozi
2020-04-28n/aexe 0517ba9bfb6cbc246dbc04db72f99a7abaece00a8ab3be017c29cd485f84989fVirustotal results 13.70% Gozi