URLhaus Database

You are currently viewing the URLhaus database entry for https://www.nilemixitupd.biz.pl/BRONZE/WTYHHGHVCDKNJKJ.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:360038
URL: https://www.nilemixitupd.biz.pl/BRONZE/WTYHHGHVCDKNJKJ.exe
URL Status:Offline
Host: www.nilemixitupd.biz.pl
Date added:2020-05-08 14:08:03 UTC
Last online:2020-05-09 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-05-08 14:10:03 UTC to abuse{at}smarthost[dot]net)
Takedown time:12 hours, 30 minutes Good (down since 2020-05-09 02:40:14 UTC)
Tags:exe GuLoader link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-08n/aexe 409b5df63705aabc1454bfe5a37b511cb6b38e10876fa39fe2609bc05d8ac169n/aGuLoader
2020-05-08n/aexe 39c6542eed54111b41269af0a620177cdd956144f35e97be9f6814d6b653bd25n/aGuLoader
2020-05-08n/aexe f84f6cc2c42c1edaeea5ac534a3a2c68c42e864021affb7ec88e41e5e359f080n/a GuLoader
2020-05-08n/aexe 5b9d8fc341d54a1a3daac1c087b80404bc8195d9ae8d6c2a5ab1aa631b059275n/a GuLoader
2020-05-08n/aexe 9532627f43a3de7b9c4414517f18197a08969adec3c24e1c2f1856e32613d5cdn/aGuLoader
2020-05-08n/aexe 1240a7ff417004b8b3b98ce0d7adc1f959178e730590b45b2cba92c473fc0b89n/aGuLoader
2020-05-08n/aexe 5f642d8b157f2edffe4bdf562b68625062021c6667b52f1b1d87489c4399464dVirustotal results 16.33%GuLoader