URLhaus Database

You are currently viewing the URLhaus database entry for http://gstat.chromaimagen.com/fattura.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:362567
URL: http://gstat.chromaimagen.com/fattura.exe
URL Status:Offline
Host: gstat.chromaimagen.com
Date added:2020-05-14 06:57:08 UTC
Last online:2020-05-17 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-05-14 07:02:02 UTC to abuse{at}cishost[dot]ru)
Takedown time:3 days, 14 hours, 46 minutes Bad (down since 2020-05-17 21:48:47 UTC)
Tags:geofenced Gozi link ISFB link ITA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-15n/aexe 071f60474179e84dacc015e59f030537f2561694f42350277c83e8239d9a35c6n/a Gozi
2020-05-15n/aexe e542af5b9251b2eab8cad824ff85761fb71368f035e2e792c1af7b3e81247934n/a Gozi
2020-05-14n/aexe 9a6a6176befca266486fffff725bb197f20831542aeaed040ad877fca0015971n/a Gozi
2020-05-14n/aexe f9b796753e32725891b33d41a3bf8ff03e6a4b8a842ff9314f73c46dfc624f92n/a Gozi
2020-05-14n/aexe 49de5718b29a8af969e9486724150f060961a4491284ebca87d8b405da9a2a0an/a Gozi
2020-05-14n/aexe 837becd51bb1bdb0e2b182704f727f9f7270737e4c0284df9739ddba3948aa83n/aGozi
2020-05-14n/aexe b17fd10164f0c3bad1ddce3b97f8d2d09b96340e5899459560dbc0b8af5e3726n/a Gozi
2020-05-14n/aexe 10cdbff6553f81e875f2d4cf4b8f4b0a5dd45f2104726820c73dc4a30b47779cn/a Gozi
2020-05-14n/aexe 03e1933216dbc2fc754ecf4bb90e6d505ca9faa3d9b2ee9ac8a32cd29c7463den/a Gozi
2020-05-14n/aexe 4c9cf4c0050b62f67b69c17eef264a6f784d7e977cd146aa69529194115dd6b7n/a Gozi
2020-05-14n/aexe cde87d0e3d781ce86f62256f3fdf619b0b238f98e6aa776671a626ab87128f0dn/a Gozi
2020-05-14n/aexe 4cff13aa8674be31cd94951cbc5bb9c02a6fb39d37802f2c555652709e463b34n/a Gozi
2020-05-14n/aexe 5e2f705aca77ac3ab2bf2b2b08a2adc515f2785ed865827eaf1e0283382bf0ben/aGozi