URLhaus Database

You are currently viewing the URLhaus database entry for http://gstat.couturefloor.com/fattura.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:358683
URL: http://gstat.couturefloor.com/fattura.exe
URL Status:Offline
Host: gstat.couturefloor.com
Date added:2020-05-06 06:57:53 UTC
Last online:2020-05-08 08:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Blocked
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-05-06 07:02:02 UTC to admin{at}vpsville[dot]ru)
Takedown time:2 days, 1 hours, 16 minutes Poor (down since 2020-05-08 08:18:49 UTC)
Tags:exe Gozi link ISFB link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-06n/aexe 27922dcf3ce8d7c92cfcead3b8418da0565a63e563517d8023ea16f3df016fe6n/a 
2020-05-06n/aexe 553479f19d8d45079eb8dbd3a22149e34c8772aba2312ae9e015cd8abf9880bfVirustotal results 29.17% 
2020-05-06n/aexe 5c8ac9a40a80ae0316034b5f1256182e01dde632d03b2d521ac92236f08ea36bn/a 
2020-05-06n/aexe d146f9aeac3e73c65de22770af4eb960605853d8388a47f3633d405e17f39807n/a 
2020-05-06n/aexe abe179c0d7408ef395f55edb6e82b9a9d072390cc6923d2e120bfaf3e4a8d729n/a 
2020-05-06n/aexe 3933f7f82a58a64acf39ea703dbc8639e6ff98ea15a38b5cd2f2f40805b21e04n/a 
2020-05-06n/aexe d0ff90145ddce9719e9aea6ef8c83b90c39f55e11b2f897b0a0197e26e97896cVirustotal results 26.39% 
2020-05-06n/aexe 113a9b7ae98ff107ce514cd1c7ae8a0e6fb1b080f5a580fbfd89ab270a238ccfn/a 
2020-05-06n/aexe b02a2fec4d624944d8474eb7e5acbf48d8000bfa0760ecd36c87256991db3c99Virustotal results 27.40% 
2020-05-06n/aexe 471b19ceb64cc9bfc3b1a6fb0f66208c2895c66ac99f0e937559b1cd2f8018c3n/a Gozi
2020-05-06n/aexe a2514c6a09b59be1062c8f7e376bc0a61aeb194808123538dff202ece8367b48n/a Gozi
2020-05-06n/aexe 25f96fe1058217837c7d5792767f033c536c6a2321bf809a80c9a02e45641929n/a 
2020-05-06n/aexe 6f1f13a58deb16f304bc3004e6adf5eec0c12673b4d9125c1addfab367340bfeVirustotal results 26.39%Gozi