URLhaus Database

You are currently viewing the URLhaus database entry for http://gstat.securityguardlisting.com/setup.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:403149
URL: http://gstat.securityguardlisting.com/setup.exe
URL Status:Offline
Host: gstat.securityguardlisting.com
Date added:2020-06-29 06:45:06 UTC
Last online:2020-06-29 21:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: JAMESWT_MHT
Abuse complaint sent (?): Yes (2020-06-29 06:58:02 UTC to noc{at}spacenet[dot]ru,secure{at}spacenet[dot]ru)
Takedown time:14 hours, 24 minutes Good (down since 2020-06-29 21:22:54 UTC)
Tags:geofenced Gozi link ISFB link ITA ursnif link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-06-29n/aexe a7593bf31c35cfe506f19633175cb6e025dfdbbfd39fb792156502fe33b11b12n/a Gozi
2020-06-29n/aexe caab488d7ceaf20f99521bff6dfaf9dc53d6148bab088ba15b031fc69b87772dn/a Gozi
2020-06-29n/aexe 34451f9d7751fbbd510951c459f9f626f7c61604da674e6d344a5787ace323d4n/a Gozi
2020-06-29n/aexe 36838238ae8e92246e324823e5bb7ce7f9f4e8856bcc3036e2c5a28a74e433een/a Gozi
2020-06-29n/aexe ab3f7f5b81faff08479b6e7fdd572fd163f31ca73c2919873fe7691091d7701en/a Gozi
2020-06-29n/aexe 5dd5a4849252ca774d60e8c68560dedfc7941c1c996e22513afaec9c662061a4Virustotal results 26.03%Gozi
2020-06-29n/aexe 1f5872b81920463f1a5424b86e34d7a1a66e8fa7e68153ccd14f36ada3a1e43cVirustotal results 27.40%Gozi
2020-06-29n/aexe 3fe5fdbdc141727dc6b70a7c8e2c7700a0eef1ee6236d7a5cb62b15c75ab9f26n/aGozi
2020-06-29n/aexe 1f1f38914a548cd04bb1793d17e50cf8e7b7e0ac027217d5f0aaa6ede159a259n/aGozi
2020-06-29n/aexe 56cb618af797072fc01cc1d24ac0d11574979a69e34b6ef6cd51023ea724c07dn/a Gozi