URLhaus Database

You are currently viewing the URLhaus database entry for http://troygilletc.ug/nw.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:383015
URL: http://troygilletc.ug/nw.exe
URL Status:Offline
Host: troygilletc.ug
Date added:2020-06-08 05:07:07 UTC
Last online:2020-06-20 13:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-06-08 05:08:02 UTC to abuse{at}grandcosmetic2[dot]ru)
Takedown time:12 days, 8 hours, 37 minutes Bad (down since 2020-06-20 13:45:50 UTC)
Tags:exe GuLoader link NetWire link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-14n/aexe 086d35f26bd2fd886e99744960b394d94e74133c40145a3e2bc6b3877b91ec5dn/aNetWire
2020-06-13n/aexe c2185ad8d295866ca4f3bff2c57b3e47e01e18d4a0eab24ad274f35aab2920e8n/a 
2020-06-12n/aexe bccda86ab7ade8c534422630f8df36360aa04c6a74715de71399af613a37355an/aNetWire
2020-06-11n/aexe 4c0201a24bb5ce9ed7b2a24dc35cbfe03ecb8546a14f549811e7d4a1b314f32fn/aNetWire
2020-06-09n/aexe 7705fa87126fed83b26578594380903268c9e2876b07375fdca0198730149e94n/aGuLoader
2020-06-08n/aexe e8f205cb55b6e064b6252572493b15776b339d9118f182d220731077629e8bbfVirustotal results 16.90%GuLoader
2020-06-08n/aexe 7d53275640b52b08bb54259f6bc85edad2dfe30b6b5f9cea9ddc8d7469d97cd8Virustotal results 20.55%NetWire