URLhaus Database

You are currently viewing the URLhaus database entry for http://post.medusaranch.com/abonento9.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:365269
URL: http://post.medusaranch.com/abonento9.exe
URL Status:Offline
Host: post.medusaranch.com
Date added:2020-05-20 10:38:11 UTC
Last online:2020-05-22 19:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-05-20 11:08:07 UTC to legal{at}hosthink[dot]net)
Takedown time:2 days, 8 hours, 32 minutes Poor (down since 2020-05-22 19:40:49 UTC)
Tags:geofenced Gozi link ifsb ITA

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-05-21n/aexe e1e9a53623d18bd4cd167b3d081288ab684126a5921a730d05bf53c452da4ac1n/a Gozi
2020-05-21n/aexe 32d09f3af504e854075bc5f89d2cae391e50fdc5a519b19d1fdfa6588522bf3fn/a Gozi
2020-05-21n/aexe dafc60c8c270443f0b22491b527db92ea192d33f8e0c43ab018bc3197832ce46n/aGozi
2020-05-21n/aexe 549cf5a8cb28f6e00880714a5849359a48b1d3350f2d58da1deee10bb1d2b074n/a Gozi
2020-05-21n/aexe e485151da0f291294f813cfc3b363965846023cb2277b01ec863f27b4d98541dn/a Gozi
2020-05-20n/aexe 9f3c5678cc5ebb29e6e13e0382005dceb7f18757eeb73006a1ddc106fba48161n/a Gozi
2020-05-20n/aexe bb0659bc0b458a4edf7a61dcd7ee8321ca434395c96ecfbb1e2e8b58b1a8a354n/a Gozi
2020-05-20n/aexe dcc2030e0fba351cbca6d09d07f5cc2aa20408a40de52c817bb2e908597a6f44n/a Gozi
2020-05-20n/aexe c29378cbc2cf94c0c8e5245b0cccb263b648a2782eb8b3f3871fe1aada22b8fdn/aGozi
2020-05-20n/aexe 91bb5a34bbb920d74958cf94266192c49d0293d175933578edec14aeb301b1c1n/a Gozi
2020-05-20n/aexe 974217feefe1dcaef43190abf21f6b2894d67ce49c8eebd7cefc44b0dc50169fn/aGozi
2020-05-20n/aexe 64e83c8f0cee695c66674a7b244713bf0ad390a77b079d35294f3ac989b937f0Virustotal results 24.66%Gozi